On 02/20/2013 07:11 PM, Laila Vrazda wrote: > Very well, theoretically AES-256 is less secure than AES-192.
The current best attack on AES-256 maxes out at 11 rounds; the full AES-256 has 14 rounds. Nobody's ever demonstrated that full AES-256 is easier to break than AES-192; and even if they had, it would still be a nonissue. "Theoretically, a reduced-round AES-256 is less secure than a reduced-round AES-192" would be more accurate, and as the sentence gets more accurate it seems to become less relevant. Besides, cryptosystems very rarely fail as the result of cryptologic flaws. It's so rare I'm having a hard time thinking of any off the top of my head; WEP fell to an implementation defect in RC4, SSL had problems with side channels, there are a lot of systems that have fallen to timing attacks, and so on. But I'm scratching my head here trying to think of the last time a system fell to cryptanalysis. The DVD Content Scrambling System, maybe?
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Gnupg-users mailing list [email protected] http://lists.gnupg.org/mailman/listinfo/gnupg-users
