Re: Validation flaw addressed in version 2.14

Thomas Brooke <[email protected]>
Newsgroups gmane.comp.security.passwordsafe.devel
Message-ID <[email protected]>
On 11/26/05, Rony Shapiro <[email protected]> wrote:
> ...
> - I'm currently leaning towards Twofish as the more "natural" evolution,
> since it is directly derived from Blowfish (main difference being larger
> block size), and has no known attacks as of now. Any particular reason to
> prefer AES (aside from "marketing")?
> ...

One reason may be the availability of external AES implementations.

PalmOS has an AES library available, which could be used in lieu of an
internal implementation within passwordsafe.  Possibly easier, and
potentially faster.

Hardware accelerators are more likely to provide AES than Twofish. 
Should someone want to take advantage of them.

Most desktop OS's already have crypto libraries/APIs.  Linux supports
both AES and Twofish.  Windows at least supports AES, and may support
Twofish, but I haven't investigated.

Food for thought.

-- Thom.


-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_idv37&alloc_id865&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.