Re: 3DES key-length for data authentication
jaymo@hiwaay.net wrote:
> For the time & memory requirements this is academic, but why do you
I think it's infeasible, in the case of SSH tunneling for example, to
mount a CPA. This may be only because I have yet to see a convincing
example of such an attack -- the difficulty in a VPN (or the like) is
that even if an adversary can inject plaintext via some mechanism, it's
unclear how to identify which bits in the output stream correspond to
which plaintext bits. All the scenarios I've seen can be reduced to
the adversary already having the key.
Received on Mon Dec 16 12:28:42 2002
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:02:52 EDT
|