Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Here are his comments about this announcement:

http://www.schneier.com/blog/archives/2012/10/keccak_is_sha-...



Note that Schneier hedges in a very similar matter about AES, suggesting in _Practical Cryptography_ that XSL attacks made him dubious of AES's long-term security --- or at least, that if you're "paranoid about your data", that you should use Serpent instead of AES/Rijndael.


Does Schneier really recommend Serpent to avoid XSL-type attacks? As far as I remember, XSL also applied to Serpent.


Not directly, but his specific concern with AES is XSL, and he suggests Serpent for more security-conscious users.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: