I'm willing to look foolish ... :-)
Can anyone answer the following questions in a quantifiable manner ?
Just what is the improvement of EDE over one-pass ?
Just what is the imporvement of encrypted IV's over plaintext ?
(Remember, you need to quantify your answers)
Since you get one message key per message and since an exhaustive search
looking at a million keys per-second on a known plaintext first block could
take up to 2 thousand years, does any of this matter ?
(Please don't explain about probability and possibility, I know these numbers)
If you need more security than this shouldn't you be using something else ?
If "they" really need to know what is in your message don't you think "they"
would employ other methods to obtain the information ?
Enough ! I am waiting for the first implementation of PEM to become publically
available. Enhancements can come later at OIW meetings held at pleasant
locations
after there is some data on performance and use, etc.
John