[TLS] Re: Aes cipher

Orr Dunkelman <[email protected]> Wed, 29 Jul 2026 12:05:32 +0300
Newsgroups gmane.ietf.tls
Message-ID <CAA+_yBY6a0isDP3f33U9oCDHZ=ZMybBxG7RHudZGxxFeMg6=Kw@mail.gmail.com>
--===============8750758080898380845==
Content-Type: multipart/alternative; boundary="000000000000da3fc90657bc4221"

--000000000000da3fc90657bc4221
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I hope I am allowed to suggest my 2 cents on the matter. While I don't have
a long track record of participation in TLS discussions and votes, and thus
I am probably unworthy of suggesting my ideas, I am mentioned in the
acknowledgements of the relevant manuscript, and I have interacted with the
Anthropic team about this result. If the esteemed moderators, working under
their new rules that allow them to be a bit more draconian with moderation,
find these 2 cents too much of an interference with the TLS mailing list,
please just let me know, and I will unsubscribe from the list and avoid
bothering you all.

The main result in this paper is improving the Derbez, Foque, Jean attack
from EUROCRYPT 2013, which is an improvement of our attack from CRYPTO
2010, which is an improvement of the Demirci-Selcuk attack, which is the
improvement of the Gilbert-Minier collision attack against 7-round attack
(it is worth mentioning that Gilbert is also the mastermind behind the
backdoor introduced in the GEA algorithm in the times governments were the
ones controlling ETSI, and according to some misconceptions in this mailing
list, handled ETSI flawlessly).

To save everybody's time, the [DFJ13] attack is on 7-round AES. The new
result is also on 7-round AES, "eroding" the security margin of 7-round AES
by about 8 bits of security (I will refrain from discussing the exact
number of bits, the paper claims x200 to x800, whereas the algorithmic gain
is limited by x256). This brings down the cost of attacking 7-round AES to
2^88 (given a lot of data and memory).

While this is the first improvement in attacking 7-round AES in the last
decade, if you were not worried by the series of papers that reduced the
security of 5-round AES from 2^32 to 2^16, or the somewhat improved attacks
on 6-round AES, then you should not really worry now ro start a procedure
for changing 10-round AES (for 128-bit key) for something else, when there
are no attacks on 8-round AES-128.

Cheers,

On Wed, Jul 29, 2026 at 11:43=E2=80=AFAM Loganaden Velvindron <loganaden@gm=
ail.com>
wrote:

> After reading
> https://www.anthropic.com/research/discovering-cryptographic-weaknesses,
>
> I would like to know whether we should look at having more diversity for
> tls 1.3 ciphers ?
>
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

--000000000000da3fc90657bc4221
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>I hope I am allowed to suggest my 2 cents on the matt=
er. While I don&#39;t have a long track record of participation in TLS disc=
ussions and votes, and thus I am probably unworthy of suggesting my ideas, =
I am mentioned in the acknowledgements of the relevant manuscript, and I ha=
ve interacted=C2=A0with the Anthropic team about this result. If the esteem=
ed moderators, working under their new rules that allow them to be a bit mo=
re draconian with moderation, find these 2 cents too much of an interferenc=
e with the TLS mailing list, please just let me know, and I will unsubscrib=
e from the list and avoid bothering you all.</div><div><br></div><div>The m=
ain result in this paper is improving the Derbez, Foque, Jean attack from E=
UROCRYPT 2013, which is an improvement of our attack from CRYPTO 2010, whic=
h is an improvement of the Demirci-Selcuk attack, which is the improvement =
of the Gilbert-Minier collision attack against 7-round attack (it is worth =
mentioning that Gilbert is also the mastermind behind the backdoor introduc=
ed in the GEA algorithm in the times governments were the ones controlling =
ETSI, and according to some misconceptions in this mailing list, handled ET=
SI flawlessly).</div><div><br></div><div>To save everybody&#39;s time, the =
[DFJ13] attack is on 7-round AES. The new result is also on 7-round AES, &q=
uot;eroding&quot; the security margin of 7-round AES by about 8 bits of sec=
urity (I will refrain from discussing the exact number of bits, the paper c=
laims x200 to x800, whereas the algorithmic gain is limited by x256). This =
brings down the cost of attacking 7-round AES to 2^88 (given a lot of data =
and memory).</div><div><br></div><div>While this is the first improvement i=
n attacking 7-round AES in the last decade, if you were not worried by the =
series of papers that reduced the security of 5-round AES from 2^32 to 2^16=
, or the somewhat improved attacks on 6-round AES, then you should not real=
ly worry now ro start a procedure for changing 10-round AES (for 128-bit ke=
y) for something else, when there are no attacks on 8-round AES-128.</div><=
div><br></div><div>Cheers,</div></div><br><div class=3D"gmail_quote gmail_q=
uote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Jul 29, 2026 =
at 11:43=E2=80=AFAM Loganaden Velvindron &lt;<a href=3D"mailto:loganaden@gm=
ail.com">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"g=
mail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204=
,204,204);padding-left:1ex"><div dir=3D"auto">After reading=C2=A0<a href=3D=
"https://www.anthropic.com/research/discovering-cryptographic-weaknesses" r=
el=3D"noreferrer" target=3D"_blank">https://www.anthropic.com/research/disc=
overing-cryptographic-weaknesses</a>,=C2=A0=C2=A0<div dir=3D"auto"><br></di=
v><div dir=3D"auto">I would like to know whether we should look at having m=
ore diversity for tls 1.3 ciphers ?</div><div dir=3D"auto"><br></div><div d=
ir=3D"auto"><br></div></div>
_______________________________________________<br>
TLS mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">tls@i=
etf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" targe=
t=3D"_blank">[email protected]</a><br>
</blockquote></div>

--000000000000da3fc90657bc4221--


--===============8750758080898380845==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK

--===============8750758080898380845==--