[3846] in cryptography@c2.net mail archive
Re: On living with the 56-bit key length restriction
daemon@ATHENA.MIT.EDU (Antonomasia)
Thu Dec 24 15:52:53 1998
Date: Thu, 24 Dec 1998 00:08:27 GMT
From: Antonomasia <ant@notatla.demon.co.uk>
To: coderpunks@toad.com, cryptography@c2.net
Jim Gillogly <jim@acm.org>
> If you use a good modern cipher for each step of the 30-bit cascade and
> include no identifying information in each step, there should be no
> other shortcut. "Good" for this purpose means it produces a distribution
> of bytes indistinguishable from uniform random to someone who doesn't
> know the key.
Does this mean that padding the final block is out and ciphertext
stealing is in ?
--
##############################################################
# Antonomasia ant@notatla.demon.co.uk #
# See http://www.notatla.demon.co.uk/ #
##############################################################