ietf-openpgp
[Top] [All Lists]

Re: AES-256 vs AES-128

2003-06-24 13:55:21

At 03:10 PM 5/31/2003 +0200, Bodo Moeller wrote:

Of course arguably 128 bits are by far enough so that you don't really
have to worry about anything of this -- unless you think that quantum
attacks might become realistic.

Just when you thought this thread was dead... <g>

Here NSA's current view of the matter (from the recent "CNSS Policy No. 15, FS-1"
document: http://csrc.nist.gov/cryptval/CNSS15FS.pdf):

"(6) The design and strength of all key lengths of the AES algorithm (i.e., 128, 192 and 256) are sufficient to protect classified information up to the SECRET level.
TOP SECRET information will require use of either the 192 or 256 key lengths."

-mjm


<Prev in Thread] Current Thread [Next in Thread>