[TLS] Re: Aes cipher
Orr Dunkelman <[email protected]> Wed, 29 Jul 2026 12:05:32 +0300
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <CAA+_yBY6a0isDP3f33U9oCDHZ=ZMybBxG7RHudZGxxFeMg6=Kw@mail.gmail.com> |
--===============8750758080898380845== Content-Type: multipart/alternative; boundary="000000000000da3fc90657bc4221" --000000000000da3fc90657bc4221 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I hope I am allowed to suggest my 2 cents on the matter. While I don't have a long track record of participation in TLS discussions and votes, and thus I am probably unworthy of suggesting my ideas, I am mentioned in the acknowledgements of the relevant manuscript, and I have interacted with the Anthropic team about this result. If the esteemed moderators, working under their new rules that allow them to be a bit more draconian with moderation, find these 2 cents too much of an interference with the TLS mailing list, please just let me know, and I will unsubscribe from the list and avoid bothering you all. The main result in this paper is improving the Derbez, Foque, Jean attack from EUROCRYPT 2013, which is an improvement of our attack from CRYPTO 2010, which is an improvement of the Demirci-Selcuk attack, which is the improvement of the Gilbert-Minier collision attack against 7-round attack (it is worth mentioning that Gilbert is also the mastermind behind the backdoor introduced in the GEA algorithm in the times governments were the ones controlling ETSI, and according to some misconceptions in this mailing list, handled ETSI flawlessly). To save everybody's time, the [DFJ13] attack is on 7-round AES. The new result is also on 7-round AES, "eroding" the security margin of 7-round AES by about 8 bits of security (I will refrain from discussing the exact number of bits, the paper claims x200 to x800, whereas the algorithmic gain is limited by x256). This brings down the cost of attacking 7-round AES to 2^88 (given a lot of data and memory). While this is the first improvement in attacking 7-round AES in the last decade, if you were not worried by the series of papers that reduced the security of 5-round AES from 2^32 to 2^16, or the somewhat improved attacks on 6-round AES, then you should not really worry now ro start a procedure for changing 10-round AES (for 128-bit key) for something else, when there are no attacks on 8-round AES-128. Cheers, On Wed, Jul 29, 2026 at 11:43=E2=80=AFAM Loganaden Velvindron <loganaden@gm= ail.com> wrote: > After reading > https://www.anthropic.com/research/discovering-cryptographic-weaknesses, > > I would like to know whether we should look at having more diversity for > tls 1.3 ciphers ? > > > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] > --000000000000da3fc90657bc4221 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>I hope I am allowed to suggest my 2 cents on the matt= er. While I don't have a long track record of participation in TLS disc= ussions and votes, and thus I am probably unworthy of suggesting my ideas, = I am mentioned in the acknowledgements of the relevant manuscript, and I ha= ve interacted=C2=A0with the Anthropic team about this result. If the esteem= ed moderators, working under their new rules that allow them to be a bit mo= re draconian with moderation, find these 2 cents too much of an interferenc= e with the TLS mailing list, please just let me know, and I will unsubscrib= e from the list and avoid bothering you all.</div><div><br></div><div>The m= ain result in this paper is improving the Derbez, Foque, Jean attack from E= UROCRYPT 2013, which is an improvement of our attack from CRYPTO 2010, whic= h is an improvement of the Demirci-Selcuk attack, which is the improvement = of the Gilbert-Minier collision attack against 7-round attack (it is worth = mentioning that Gilbert is also the mastermind behind the backdoor introduc= ed in the GEA algorithm in the times governments were the ones controlling = ETSI, and according to some misconceptions in this mailing list, handled ET= SI flawlessly).</div><div><br></div><div>To save everybody's time, the = [DFJ13] attack is on 7-round AES. The new result is also on 7-round AES, &q= uot;eroding" the security margin of 7-round AES by about 8 bits of sec= urity (I will refrain from discussing the exact number of bits, the paper c= laims x200 to x800, whereas the algorithmic gain is limited by x256). This = brings down the cost of attacking 7-round AES to 2^88 (given a lot of data = and memory).</div><div><br></div><div>While this is the first improvement i= n attacking 7-round AES in the last decade, if you were not worried by the = series of papers that reduced the security of 5-round AES from 2^32 to 2^16= , or the somewhat improved attacks on 6-round AES, then you should not real= ly worry now ro start a procedure for changing 10-round AES (for 128-bit ke= y) for something else, when there are no attacks on 8-round AES-128.</div><= div><br></div><div>Cheers,</div></div><br><div class=3D"gmail_quote gmail_q= uote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Jul 29, 2026 = at 11:43=E2=80=AFAM Loganaden Velvindron <<a href=3D"mailto:loganaden@gm= ail.com">[email protected]</a>> wrote:<br></div><blockquote class=3D"g= mail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204= ,204,204);padding-left:1ex"><div dir=3D"auto">After reading=C2=A0<a href=3D= "https://www.anthropic.com/research/discovering-cryptographic-weaknesses" r= el=3D"noreferrer" target=3D"_blank">https://www.anthropic.com/research/disc= overing-cryptographic-weaknesses</a>,=C2=A0=C2=A0<div dir=3D"auto"><br></di= v><div dir=3D"auto">I would like to know whether we should look at having m= ore diversity for tls 1.3 ciphers ?</div><div dir=3D"auto"><br></div><div d= ir=3D"auto"><br></div></div> _______________________________________________<br> TLS mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">tls@i= etf.org</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" targe= t=3D"_blank">[email protected]</a><br> </blockquote></div> --000000000000da3fc90657bc4221-- --===============8750758080898380845== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0 bHMtbGVhdmVAaWV0Zi5vcmcK --===============8750758080898380845==--