ietf-openpgp
[Top] [All Lists]

Re: Next Steps

2007-11-06 16:07:56

I would be very cautious about using RC4. Every year it seems to get
weaker. In the past year alone there have been four new attacks on it
published on the eprint.iacr.org servers: 2007/305, 2007/261, 2007/208,
and 2007/070. I would not be at all enthusiastic about putting it into
OpenPGP.

I wonder if there is some better-vetted cipher which would be faster
than AES, that might be usable. I'd also look into whether there might
be an AES implementation that is better optimized for ARM (or whatever
the processor is).

Hal Finney
PGP Corporation

<Prev in Thread] Current Thread [Next in Thread>