On 02/20/2013 07:11 PM, Laila Vrazda wrote:
> Very well, theoretically AES-256 is less secure than AES-192.

The current best attack on AES-256 maxes out at 11 rounds; the full
AES-256 has 14 rounds.  Nobody's ever demonstrated that full AES-256 is
easier to break than AES-192; and even if they had, it would still be a
nonissue.  "Theoretically, a reduced-round AES-256 is less secure than a
reduced-round AES-192" would be more accurate, and as the sentence gets
more accurate it seems to become less relevant.

Besides, cryptosystems very rarely fail as the result of cryptologic
flaws.  It's so rare I'm having a hard time thinking of any off the top
of my head; WEP fell to an implementation defect in RC4, SSL had
problems with side channels, there are a lot of systems that have fallen
to timing attacks, and so on.  But I'm scratching my head here trying to
think of the last time a system fell to cryptanalysis.  The DVD Content
Scrambling System, maybe?



Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Gnupg-users mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to