Re: [TLS] Proposed text for IDEA/DES document
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Proposed text for IDEA/DES document



On Wed, Feb 06, 2008 at 12:38:44PM +0200, Pasi.Eronen at nokia.com wrote:
> Len Sassaman wrote:
>> On Tue, 5 Feb 2008 Pasi.Eronen at nokia.com wrote:

>>>    IDEA has a 128-bit key, and thus is not vulnerable to exhaustive
>>>    key search. However, IDEA has not seen widespread use, 
>>>    and has not

>> IDEA has been widely used, particularly in disk and email 
>> encryption programs.

Indeed.


> I stand corrected -- maybe that could be rephrased to "IDEA cipher
> suites for TLS have not seen widespread use"?

Yes, makes sense.


[...]
>> IDEA's problem is its patent, nothing more.

IDEA's problem also is the 64-bit block length.

With networks getting faster, it is increasingly easier to get
uncomfortably close to the number of blocks where you can no longer
expect full security (around 2^32 blocks, i.e. 32 GB, for CBC
encryption; with a non-neglible probability to have a security failure
well below this limit).

_______________________________________________
TLS mailing list
TLS at ietf.org
http://www.ietf.org/mailman/listinfo/tls



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.