3 ms·
Does anyone know how this interacts with the AES-256 break from a while back? Something to do with, they didn't use enough rounds so the security is really only
by zrm 5y ago
Does anyone know how this interacts with the AES-256 break from a while back? Something to do with, they didn't use enough rounds so the security is really only about equivalent to AES-128. And then nobody cared because having the security of AES-128 isn't a practical break.
Unless we get quantum computers. Then what happens with AES-256?
- ncmncm 5y agoAs I recall it was about the key schedule. But, same outcome. Some people, idiotically, use 256 bit AES anyway, because it reassures less literate customers. Sort of like the patdowns at airports: security theater.
- hxtk 5y agoI haven't heard anything about not using enough rounds, so it's possible that my information is just out of date. My understanding is that AES-128 was chosen to be resistant against classical attacks, and AES-256 was chosen to achieve the same level of security as AES-128 against attacks that incorporate quantum computers and Grover's algorithm.