Hello,here's some additional text that explains the "hedge" strategy. Perhaps it's worth adding to the draft. Comments welcome.
DavidThe main motivation for AES-192 and AES-256 is to provide alternative ciphers to AES-128 that can be adopted in event that unforeseen advances in cryptanalysis significantly erode the security level of AES-128. The main purpose of this specification is to provide algorithm agility to SRTP, to allow that protocol to easily adopt the alternative ciphers if the need arises in the future. It MUST NOT be interpreted as discouraging the use of AES-128. Implementers MAY support the alternative ciphers in advance of any need to replace AES-128, in order to facilitate a potential future 'hot swap' replacement, but those implementations MUST be prepared to interoperate with implementations that do not support the alternative ciphers.
Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.