At 03:10 PM 5/31/2003 +0200, Bodo Moeller wrote:
Of course arguably 128 bits are by far enough so that you don't really
have to worry about anything of this -- unless you think that quantum
attacks might become realistic.
Just when you thought this thread was dead... <g>
Here NSA's current view of the matter (from the recent "CNSS Policy No. 15,
FS-1"
document: http://csrc.nist.gov/cryptval/CNSS15FS.pdf):
"(6) The design and strength of all key lengths of the AES algorithm (i.e.,
128, 192
and 256) are sufficient to protect classified information up to the SECRET
level.
TOP SECRET information will require use of either the 192 or 256 key lengths."
-mjm