3 ms·
I always wondered, since the NSA has intimate knowledge of the inner workings of AES, then can we presume they know its weaknesses, or have compromised it in so
by blindm 6y ago
I always wondered, since the NSA has intimate knowledge of the inner workings of AES, then can we presume they know its weaknesses, or have compromised it in some way? Excuse my naive question, I'm not a crypto nerd.
- andrewnicolalde 6y agoWe have no real way of knowing. AES is considered secure because, as far as is publicly known, it has sufficiently withstood attacks performed by many, many skilled cryptanalysts. As far as I am aware there is no reason to believe that AES provides anything less than its stated level of security. But again that isn’t to say it’s impossible.
- dlubarov 6y agoAES has been a major target of cryptanalysis, and it has held up pretty well. Publicly known key recovery attacks are only slightly faster than brute force, like [1]. There are some efficient related-key attacks, which might be a concern in certain applications, but not if keys are chosen randomly. It's always possible that the NSA has found better attacks, but I don't think there's anything particularly suspicious about AES compared to other primitives. (For an example of a highly suspicious primitive, see Dual_EC_DRBG.) [1] https://eprint.iacr.org/2011/449 https://eprint.iacr.org/2011/449