2 ms·
Sure, AES-256 or ChaCha20 is probably an even better choice. I just mean to say that even a 192-bit key is comfortably out of reach of Grover-assisted brute-fo
by less_less 4y ago
Sure, AES-256 or ChaCha20 is probably an even better choice. I just mean to say that even a 192-bit key is comfortably out of reach of Grover-assisted brute-force for the foreseeable future, which would not be true if Grover effectively halved the key size.
I'm not aware of problems with the AES block size and key size not matching... is there some cryptanalysis in that direction? On the contrary, I'd thought that AES-256 had a slightly shakier key schedule than AES-128 or -192, though due to the longer key it is still stronger than AES-192 vs known attacks.
- Vecr 4y agoI'm actually not sure, I would need to look at it again. As you said, AES-128 is probably the most sound in a theoretical sense, but AES-256 stronger against brute force and that makes up for the theoretical problems. AES-192 is a weird middle option that's less strong against brute force than AES-256, and is also theoretically less sound that AES-128.