Re: [TLS] Proposed text for IDEA/DES document
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Proposed text for IDEA/DES document
On Wed, Feb 06, 2008 at 12:38:44PM +0200, Pasi.Eronen at nokia.com wrote:
> Len Sassaman wrote:
>> On Tue, 5 Feb 2008 Pasi.Eronen at nokia.com wrote:
>>> IDEA has a 128-bit key, and thus is not vulnerable to exhaustive
>>> key search. However, IDEA has not seen widespread use,
>>> and has not
>> IDEA has been widely used, particularly in disk and email
>> encryption programs.
Indeed.
> I stand corrected -- maybe that could be rephrased to "IDEA cipher
> suites for TLS have not seen widespread use"?
Yes, makes sense.
[...]
>> IDEA's problem is its patent, nothing more.
IDEA's problem also is the 64-bit block length.
With networks getting faster, it is increasingly easier to get
uncomfortably close to the number of blocks where you can no longer
expect full security (around 2^32 blocks, i.e. 32 GB, for CBC
encryption; with a non-neglible probability to have a security failure
well below this limit).
_______________________________________________
TLS mailing list
TLS at ietf.org
http://www.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.