Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 23 Jun 1997 22:38:03 -0400 (EDT)
From:      Ben Black <black@zen.cypher.net>
To:        Ollivier Robert <roberto@keltia.freenix.fr>
Cc:        hackers@FreeBSD.ORG
Subject:   Re: RSA5 Encryption Cracked..
Message-ID:  <Pine.LNX.3.91.970623223638.28982B-100000@zen.cypher.net>
In-Reply-To: <19970623204723.39016@keltia.freenix.fr>

next in thread | previous in thread | raw e-mail | index | archive | help
"very immune"?  it isn't immune, it is resistant.  yes, NSA was aware of 
differential cryptanalysis when the cipher was designed, but they 
couldn't eliminate the problem, just reduce it.  and that's what they did.

as for NIST writing the paper, they are.  after all, they are the 
standards arm of the government.  but the algorithm is from NSA.

On Mon, 23 Jun 1997, Ollivier Robert wrote:

> According to Ben Black:
> > i think you mean differential cryptanalysis which under certain 
> > circumstances can reduce the effective keyspace.  it is not broadly 
> > applicable and is rather constrained.  3DES (triple DES) will be an 
> > actual gov't standard shortly.
> 
> Anyway, DES is very immune to differential analysis. When it was designed,
> many people thought the NSA was installing a back door when they made IBM
> change the design of the S-Boxes. With the classic 16-round DES, you need
> 2**47 of chosen-plaintext...
> 
> Years after, we learned that the NSA and IBM were aware of differential
> analysis 10 years before it was "discovered" by Shamir and
> that why DES was modified.
> 
> All in one, DES is a very good cipher. Showing its age now but still good.
> 
> > NSA is also releasing a new gov't encryption standard (i forget the name, 
> > starts with A...AES?)
> 
> I don't think it is coming from the NSA. NIST is writing a paper on what
> the next government approved cipher should be. I have the URL of the draft
> at work. It says it should accept key sizes of 128/128, 192/192 and 256/256
> bits.
> 
> See the discussion in sci.crypt.
> -- 
> Ollivier ROBERT -=- FreeBSD: There are no limits -=- roberto@keltia.freenix.fr
> FreeBSD keltia.freenix.fr 3.0-CURRENT #20: Fri Jun 13 00:16:13 CEST 1997
> 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.3.91.970623223638.28982B-100000>