[TLS] Re: [Ssh] A new AI-discovered attack on 7-round AE S (commentaries by Orr Dunkelman and D. J. Bernstein)

Bas Westerbaan <[email protected]> Thu, 30 Jul 2026 14:31:05 +0200
Newsgroups gmane.ietf.tls
Message-ID <CAMjbhoXY0MkeQpxXgVocN-ZmfayoP7gnmRKEvXwZyyeDhHnJuA@mail.gmail.com>
--===============5699706413379928801==
Content-Type: multipart/alternative; boundary="0000000000009174a90657d33feb"

--0000000000009174a90657d33feb
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Another way to illustrate this point: there are many quantum labs across
the world that have a CRQC on their roadmap that is able to break RSA-2048
using Shor's algorithm in the next couple of years. Whether they meet their
deadlines is of course a point of contention. The story couldn't be
different with Grover: there is not a single lab that has even dared to
speculate on when they're able to break AES-128. Any estimates on the
viability of Grover assumes big leaps in quantum progress, and still
concludes it's not viable.

So, Shor near, Grover very far
<https://youtu.be/E9IuXEwpU7U?si=3D0hciHrLtdykI0unE&t=3D113>.

Best,

 Bas

On Thu, Jul 30, 2026 at 2:22=E2=80=AFPM Roger Grimes <roger=3D
[email protected]> wrote:

> The short version of why AES-128 is not threatened in the immediate futur=
e
> is:
>
>    - Grover=E2=80=99s algorithm does not parallelize well
>    - To break an AES-128 bit key would take a nonillion (number followed
>    by 30 zeros) quantum gates
>    - Each quantum gate operation today takes in the microseconds
>    - Adding the two figures together means it would take hundreds of
>    millions of years for Grover=E2=80=99s to break AES-128
>
>
>
> So, new thinking is that you don=E2=80=99t have to immediately rush to up=
grade
> your AES-128 keys to something longer. But if gate operations get into th=
e
> low nanoseconds (which seems likely in the future) or if someone figures
> out a way to parallel-attack a symmetric key better than Grover=E2=80=99s
> algorithm, then the immediate threat would be back.
>
>
>
> *From:* Soatok Dreamseeker <[email protected]>
> *Sent:* Wednesday, July 29, 2026 7:11 PM
> *To:* Ken Kubota <[email protected]>
> *Cc:* [email protected]; [email protected]
> *Subject:* [TLS] Re: [Ssh] A new AI-discovered attack on 7-round AES
> (commentaries by Orr Dunkelman and D. J. Bernstein)
>
>
>
> With Grover's algorithm in quantum computing that in the future might
> halve the effective security, theoretically symmetric key lengths of 512
> bits could be necessary.
>
>
>
> I do not think Grover's is a meaningful risk to any system in the
> foreseeable future. See https://words.filippo.io/128-bits/ for a longer
> treatment on the topic.
>
>
>
>
>
> On Wed, Jul 29, 2026 at 2:10=E2=80=AFPM Ken Kubota <[email protected]> wr=
ote:
>
> The catastrophic failure of NIST PQC finalists is not a new phenomenon.
> The situation is basically a mess.
> Consequently, hybrid solutions remain the only viable option, while any
> non-hybrid (or "solo") approach represents a significant security risk.
>
> What is new here is the emergence of a paradigm in which numerous new
> cryptographic researchers appear via AI models that also generate novel
> attacks, as evidenced in first-rate research papers.
>
> Perhaps the accelerated pace of cryptographic research enabled by AI
> (e.g., where the scientific progress of next year might correspond to a
> decade's worth of past advancements) will mitigate the quantum threat,
> either by having AI identify weak PQC algorithms or by creating new,
> stronger ones.
>
> Kind regards,
>
> Ken Kubota
>
> ____________________________________________________
>
> Ken Kubota
> https://doi.org/10.4444/100
>
>
>
> > Am 29.07.2026 um 15:08 schrieb Jan Schermer <[email protected]>:
> >
> > Isn't this a red herring? You completely missed the part where they
> attacked HAWK (PQC finalist), _THAT_ is what illustrates the point. Nobod=
y
> cares about 7-round AES.
> >
> > Jan
> >
> >
> >> On 29. 7. 2026, at 14:58, Ken Kubota <[email protected]> wrote:
> >>
> >> On both Orr Dunkelman's [1] (TLS list) and D. J. Bernstein's commentar=
y
> [2] (SSH list) regarding the new AI-generated attack on 7-round AES [3, 4=
,
> 5]:
> >>
> >>
> >> "While this is the first improvement in attacking 7-round AES in the
> last
> >> decade, if you were not worried by the series of papers that reduced t=
he
> >> security of 5-round AES from 2^32 to 2^16, or the somewhat improved
> attacks
> >> on 6-round AES, then you should not really worry now [t]o start a
> procedure
> >> for changing 10-round AES (for 128-bit key) for something else, when
> there
> >> are no attacks on 8-round AES-128." [1]
> >>
> >> This overlooks the very point that Anthropic researchers emphasize
> themselves:
> >>
> >> "And in the case of AES, our attack extends a long line of work that
> had previously succeeded at attacking reduced-round variants. But we shou=
ld
> not assume that language model capabilities will plateau at this level. I=
n
> just one year, language models have gone from being unable to perform
> cryptanalysis of even the most basic ciphers to being capable of finding
> flaws in cryptographic designs that have escaped discovery despite years =
of
> human expert review." [3]
> >> "But as we develop increasingly powerful cryptanalytic results, it
> would be prudent to consider how researchers should react if a language
> model were to discover vulnerabilities in cryptosystems where attacks do
> have an immediate real-world impact." [3]
> >>
> >> The point is not the new attack on 7-round AES, but the very fact that
> the new attack was AI-generated, and the speed of such developments might
> increase.
> >> While this is probably the first such groundbreaking research result
> created by AI, in half a year there might be 10 such papers, and in anoth=
er
> half a year 100 papers, etc., in other words, a qualitatively _new
> paradigm_ of scientific progress, which is not addressed by focusing on t=
he
> number of rounds.
> >>
> >> Brian Berletic predicted AI development with _exponentially_ growing
> speed already about half a year ago:
> >>
> >> "There are people that don't even want to acknowledge that AI is a rea=
l
> thing that exists and is speeding forward. And it's not just speeding
> forward in a linear way. It is exponentially increasing. You can see it.
> Before it was leaps and bounds year to year. Now it is leaps and bounds
> month to month even sometimes week to week." [6]
> >>
> >>
> >> "Given this risk, it's particularly dangerous if we allow the pursuit =
of
> >> every last bit of performance to strip cryptography down to the bare
> >> minimum that resists attack demos. It's much safer to include defense =
in
> >> depth: for example, 256-bit cipher keys, many more cipher rounds than =
we
> >> know how to break (the classic recommendation from Anderson, Biham, an=
d
> >> Knudsen is twice as many rounds), and continuing to sign with ECC when
> >> we add PQ signatures." [2]
> >>
> >> While
> >> - twice as many rounds
> >> - hybrid approach (e.g., double encryption)
> >> are obvious conclusions,
> >> "256-bit cipher keys" should be replaced by "256 bits of security" for
> long-term security.
> >>
> >> With Grover's algorithm in quantum computing that in the future might
> halve the effective security, theoretically symmetric key lengths of 512
> bits could be necessary.
> >>
> >> For long-term security, a security margin should be added that takes
> into account scientific progress (e.g., new attacks), technological
> progress (e.g., quantum computing, artificial intelligence), the
> interaction between both (possibly exponentially increasing scientific
> progress due to AI) as well as potential weaknesses in the original
> algorithm.
> >>
> >> Considering that secret (nation-state) quantum attacks may already
> happen in 2029 [7, 8], for a pragmatic ad-hoc hybrid solution focusing on
> asymmetric methods might be sufficient (German BSI: "it is advisable to u=
se
> a key length of 256 bits for the symmetric encryption methods" [9]).
> >>
> >> For developing new algorithms, however, 512-bit keys should be
> envisioned for the symmetric encryption methods.
> >>
> >> The historical analogy lies in the NSA and Curve 25519.
> >> The NSA in 2005 decided to internally use 256 bits of security for
> long-term security [10] (e.g., Curve P-521 [11]).
> >> In my opinion, this was the correct decision, and a wise decision.
> >>
> >> While Curve 25519 has done a good job, I always regretted it only
> offered 128 bits of security.
> >> This level of 128 bits of security was deprecated by the NSA more than
> a decade ago [12].
> >>
> >> One should keep in mind that long-term security means more than holdin=
g
> a few decades.
> >> The pediatric records of a seven-year-old child shouldn't be available
> on the internet if the person is 37, 47, or 57 years old, with full name,
> birthday, maybe even place of birth (which would allow identity theft), b=
ut
> also diagnoses that may still be relevant then.
> >>
> >>
> >> Kind regards,
> >>
> >> Ken Kubota
> >>
> >> ____________________________________________________
> >>
> >> Ken Kubota
> >> https://doi.org/10.4444/100
> >>
> >>
> >>
> >> [1]
> https://mailarchive.ietf.org/arch/msg/tls/QusthRp6zRAxCvImiLLQ0SQLtME/
> >>
> >> [2]
> https://mailarchive.ietf.org/arch/msg/ssh/HGT2mTKC7vi9lHPdpBtQEwt57SQ/
> >>
> >> [3]
> https://www.anthropic.com/research/discovering-cryptographic-weaknesses
> >>
> >> [4] https://anthropic.com/document/aes_mobius_bridge.pdf
> >>
> >> [5] https://anthropic.com/document/aes_mobius_bridge_cot.pdf
> >>
> >> [6] https://youtu.be/tbjsagsiWls?t=3D2582
> >>
> >> [7]
> https://cr.yp.to/talks/2023.06.15/slides-djb-20230615-pqrisk-4x3.pdf, p. =
6
> >>
> >> [8] https://youtu.be/qPhoJQtvgUo?t=3D740
> >>
> >> [9]
> https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuid=
elines/TG02102/BSI-TR-02102-1.pdf?__blob=3DpublicationFile&v=3D14,
> p. 40
> >> "The development of fault-tolerant quantum computers has a much less
> severe impact on the
> >> security of symmetric mechanisms than on the security of asymmetric
> mechanisms. The use of
> >> Grover=E2=80=99s algorithm [61] could theoretically accelerate the sea=
rch of
> the key space of symmetric
> >> mechanisms quadratically. Whether an acceleration compared to a classi=
c
> exhaustive search of the
> >> key space can also be achieved in practice is the subject of current
> research, see e.g. [76]. Never-
> >> theless, especially for applications with high or long-term protection
> requirements or long-living
> >> systems it is advisable to use a key length of 256 bits for the
> symmetric encryption methods
> >> recommended below."
> >>
> >> [10]
> https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/
> >>
> >> [11]
> https://mailarchive.ietf.org/arch/msg/ssh/ONXLAO9CR9w6tUhwE3ag9CB14tE/
> >>
> >> [12]
> https://mailarchive.ietf.org/arch/msg/ssh/47mIx2MIjUYpn45EBysgmCHy5_4/
> >>
> >> _______________________________________________
> >> Ssh mailing list -- [email protected]
> >> To unsubscribe send an email to [email protected]
> >
> > _______________________________________________
> > Ssh mailing list -- [email protected]
> > To unsubscribe send an email to [email protected]
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

--0000000000009174a90657d33feb
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Another way to illustrate this point: there are many quant=
um labs across the=C2=A0world that have a CRQC on their roadmap that is abl=
e to break RSA-2048 using Shor&#39;s algorithm in the next couple of years.=
 Whether they meet their deadlines is of course a point of contention. The =
story couldn&#39;t be different with Grover: there is not a single lab that=
 has even dared to speculate on when they&#39;re able=C2=A0to break AES-128=
. Any estimates on the viability of Grover assumes big leaps in quantum pro=
gress, and still concludes it&#39;s not viable.<div><br></div><div>So, Shor=
 near, Grover very <a href=3D"https://youtu.be/E9IuXEwpU7U?si=3D0hciHrLtdyk=
I0unE&amp;t=3D113">far</a>.</div><div><br></div><div>Best,</div><div><br></=
div><div>=C2=A0Bas</div></div><br><div class=3D"gmail_quote gmail_quote_con=
tainer"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Jul 30, 2026 at 2:22=
=E2=80=AFPM Roger Grimes &lt;roger=3D<a href=3D"mailto:40banneretcs.com@dma=
rc.ietf.org">[email protected]</a>&gt; wrote:<br></div><block=
quote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1=
px solid rgb(204,204,204);padding-left:1ex"><div class=3D"msg17795041685167=
81413">





<div lang=3D"EN-US" style=3D"overflow-wrap: break-word;">
<div class=3D"m_1779504168516781413WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">The short version of =
why AES-128 is not threatened in the immediate future is:<u></u><u></u></sp=
an></p>
<ul style=3D"margin-top:0in" type=3D"disc">
<li class=3D"m_1779504168516781413MsoListParagraph" style=3D"margin-left:0i=
n"><span style=3D"font-size:11pt">Grover=E2=80=99s algorithm does not paral=
lelize well<u></u><u></u></span></li><li class=3D"m_1779504168516781413MsoL=
istParagraph" style=3D"margin-left:0in"><span style=3D"font-size:11pt">To b=
reak an AES-128 bit key would take a nonillion (number followed by 30 zeros=
) quantum gates<u></u><u></u></span></li><li class=3D"m_1779504168516781413=
MsoListParagraph" style=3D"margin-left:0in"><span style=3D"font-size:11pt">=
Each quantum gate operation today takes in the microseconds<u></u><u></u></=
span></li><li class=3D"m_1779504168516781413MsoListParagraph" style=3D"marg=
in-left:0in"><span style=3D"font-size:11pt">Adding the two figures together=
 means it would take hundreds of millions of years for Grover=E2=80=99s to =
break AES-128<u></u><u></u></span></li></ul>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">So, new thinking is t=
hat you don=E2=80=99t have to immediately rush to upgrade your AES-128 keys=
 to something longer. But if gate operations get into the low nanoseconds (=
which seems likely in the future) or if someone
 figures out a way to parallel-attack a symmetric key better than Grover=E2=
=80=99s algorithm, then the immediate threat would be back.
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><=
/span></p>
<div style=3D"border-width:1pt medium medium;border-style:solid none none;b=
order-color:rgb(225,225,225) currentcolor currentcolor;padding:3pt 0in 0in"=
>
<p class=3D"MsoNormal"><b><span style=3D"font-size:11pt;font-family:Calibri=
,sans-serif">From:</span></b><span style=3D"font-size:11pt;font-family:Cali=
bri,sans-serif"> Soatok Dreamseeker &lt;<a href=3D"mailto:soatok.dhole@gmai=
l.com" target=3D"_blank">[email protected]</a>&gt;
<br>
<b>Sent:</b> Wednesday, July 29, 2026 7:11 PM<br>
<b>To:</b> Ken Kubota &lt;<a href=3D"mailto:[email protected]" target=3D"_b=
lank">[email protected]</a>&gt;<br>
<b>Cc:</b> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</=
a>; <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br>
<b>Subject:</b> [TLS] Re: [Ssh] A new AI-discovered attack on 7-round AES (=
commentaries by Orr Dunkelman and D. J. Bernstein)<u></u><u></u></span></p>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal">With Grover&#39;s algorithm in quantum computing tha=
t in the future might halve the effective security, theoretically symmetric=
 key lengths of 512 bits could be necessary.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<p class=3D"MsoNormal">I do not think Grover&#39;s is a meaningful risk to =
any system in the foreseeable future. See=C2=A0<a href=3D"https://words.fil=
ippo.io/128-bits/" target=3D"_blank">https://words.filippo.io/128-bits/</a>=
 for a longer treatment on the topic.<u></u><u></u></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<p class=3D"MsoNormal">On Wed, Jul 29, 2026 at 2:10<span style=3D"font-fami=
ly:Arial,sans-serif">=E2=80=AF</span>PM Ken Kubota &lt;<a href=3D"mailto:ie=
[email protected]" target=3D"_blank">[email protected]</a>&gt; wrote:<u></u><=
u></u></p>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal">The catastrophic failure of NIST PQC finalists is no=
t a new phenomenon.
<br>
The situation is basically a mess.<br>
Consequently, hybrid solutions remain the only viable option, while any non=
-hybrid (or &quot;solo&quot;) approach represents a significant security ri=
sk.<br>
<br>
What is new here is the emergence of a paradigm in which numerous new crypt=
ographic researchers appear via AI models that also generate novel attacks,=
 as evidenced in first-rate research papers.<br>
<br>
Perhaps the accelerated pace of cryptographic research enabled by AI (e.g.,=
 where the scientific progress of next year might correspond to a decade&#3=
9;s worth of past advancements) will mitigate the quantum threat, either by=
 having AI identify weak PQC algorithms
 or by creating new, stronger ones.<br>
<br>
Kind regards,<br>
<br>
Ken Kubota<br>
<br>
____________________________________________________<br>
<br>
Ken Kubota<br>
<a href=3D"https://doi.org/10.4444/100" target=3D"_blank">https://doi.org/1=
0.4444/100</a><br>
<br>
<br>
<br>
&gt; Am 29.07.2026 um 15:08 schrieb Jan Schermer &lt;<a href=3D"mailto:jan@=
schermer.cz" target=3D"_blank">[email protected]</a>&gt;:<br>
&gt; <br>
&gt; Isn&#39;t this a red herring? You completely missed the part where the=
y attacked HAWK (PQC finalist), _THAT_ is what illustrates the point. Nobod=
y cares about 7-round AES.<br>
&gt; <br>
&gt; Jan<br>
&gt; <br>
&gt; <br>
&gt;&gt; On 29. 7. 2026, at 14:58, Ken Kubota &lt;<a href=3D"mailto:ietf@ke=
nkubota.de" target=3D"_blank">[email protected]</a>&gt; wrote:<br>
&gt;&gt; <br>
&gt;&gt; On both Orr Dunkelman&#39;s [1] (TLS list) and D. J. Bernstein&#39=
;s commentary [2] (SSH list) regarding the new AI-generated attack on 7-rou=
nd AES [3, 4, 5]:<br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; &quot;While this is the first improvement in attacking 7-round AES=
 in the last<br>
&gt;&gt; decade, if you were not worried by the series of papers that reduc=
ed the<br>
&gt;&gt; security of 5-round AES from 2^32 to 2^16, or the somewhat improve=
d attacks<br>
&gt;&gt; on 6-round AES, then you should not really worry now [t]o start a =
procedure<br>
&gt;&gt; for changing 10-round AES (for 128-bit key) for something else, wh=
en there<br>
&gt;&gt; are no attacks on 8-round AES-128.&quot; [1]<br>
&gt;&gt; <br>
&gt;&gt; This overlooks the very point that Anthropic researchers emphasize=
 themselves:<br>
&gt;&gt; <br>
&gt;&gt; &quot;And in the case of AES, our attack extends a long line of wo=
rk that had previously succeeded at attacking reduced-round variants. But w=
e should not assume that language model capabilities will plateau at this l=
evel. In just one year, language models have
 gone from being unable to perform cryptanalysis of even the most basic cip=
hers to being capable of finding flaws in cryptographic designs that have e=
scaped discovery despite years of human expert review.&quot; [3]<br>
&gt;&gt; &quot;But as we develop increasingly powerful cryptanalytic result=
s, it would be prudent to consider how researchers should react if a langua=
ge model were to discover vulnerabilities in cryptosystems where attacks do=
 have an immediate real-world impact.&quot; [3]<br>
&gt;&gt; <br>
&gt;&gt; The point is not the new attack on 7-round AES, but the very fact =
that the new attack was AI-generated, and the speed of such developments mi=
ght increase.<br>
&gt;&gt; While this is probably the first such groundbreaking research resu=
lt created by AI, in half a year there might be 10 such papers, and in anot=
her half a year 100 papers, etc., in other words, a qualitatively _new para=
digm_ of scientific progress, which is
 not addressed by focusing on the number of rounds.<br>
&gt;&gt; <br>
&gt;&gt; Brian Berletic predicted AI development with _exponentially_ growi=
ng speed already about half a year ago:<br>
&gt;&gt; <br>
&gt;&gt; &quot;There are people that don&#39;t even want to acknowledge tha=
t AI is a real thing that exists and is speeding forward. And it&#39;s not =
just speeding forward in a linear way. It is exponentially increasing. You =
can see it. Before it was leaps and bounds year to
 year. Now it is leaps and bounds month to month even sometimes week to wee=
k.&quot; [6]<br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; &quot;Given this risk, it&#39;s particularly dangerous if we allow=
 the pursuit of<br>
&gt;&gt; every last bit of performance to strip cryptography down to the ba=
re<br>
&gt;&gt; minimum that resists attack demos. It&#39;s much safer to include =
defense in<br>
&gt;&gt; depth: for example, 256-bit cipher keys, many more cipher rounds t=
han we<br>
&gt;&gt; know how to break (the classic recommendation from Anderson, Biham=
, and<br>
&gt;&gt; Knudsen is twice as many rounds), and continuing to sign with ECC =
when<br>
&gt;&gt; we add PQ signatures.&quot; [2]<br>
&gt;&gt; <br>
&gt;&gt; While<br>
&gt;&gt; - twice as many rounds<br>
&gt;&gt; - hybrid approach (e.g., double encryption)<br>
&gt;&gt; are obvious conclusions,<br>
&gt;&gt; &quot;256-bit cipher keys&quot; should be replaced by &quot;256 bi=
ts of security&quot; for long-term security.<br>
&gt;&gt; <br>
&gt;&gt; With Grover&#39;s algorithm in quantum computing that in the futur=
e might halve the effective security, theoretically symmetric key lengths o=
f 512 bits could be necessary.<br>
&gt;&gt; <br>
&gt;&gt; For long-term security, a security margin should be added that tak=
es into account scientific progress (e.g., new attacks), technological prog=
ress (e.g., quantum computing, artificial intelligence), the interaction be=
tween both (possibly exponentially increasing
 scientific progress due to AI) as well as potential weaknesses in the orig=
inal algorithm.<br>
&gt;&gt; <br>
&gt;&gt; Considering that secret (nation-state) quantum attacks may already=
 happen in 2029 [7, 8], for a pragmatic ad-hoc hybrid solution focusing on =
asymmetric methods might be sufficient (German BSI: &quot;it is advisable t=
o use a key length of 256 bits for the symmetric
 encryption methods&quot; [9]).<br>
&gt;&gt; <br>
&gt;&gt; For developing new algorithms, however, 512-bit keys should be env=
isioned for the symmetric encryption methods.<br>
&gt;&gt; <br>
&gt;&gt; The historical analogy lies in the NSA and Curve 25519.<br>
&gt;&gt; The NSA in 2005 decided to internally use 256 bits of security for=
 long-term security [10] (e.g., Curve P-521 [11]).<br>
&gt;&gt; In my opinion, this was the correct decision, and a wise decision.=
<br>
&gt;&gt; <br>
&gt;&gt; While Curve 25519 has done a good job, I always regretted it only =
offered 128 bits of security.<br>
&gt;&gt; This level of 128 bits of security was deprecated by the NSA more =
than a decade ago [12].<br>
&gt;&gt; <br>
&gt;&gt; One should keep in mind that long-term security means more than ho=
lding a few decades.<br>
&gt;&gt; The pediatric records of a seven-year-old child shouldn&#39;t be a=
vailable on the internet if the person is 37, 47, or 57 years old, with ful=
l name, birthday, maybe even place of birth (which would allow identity the=
ft), but also diagnoses that may still be
 relevant then.<br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; Kind regards,<br>
&gt;&gt; <br>
&gt;&gt; Ken Kubota<br>
&gt;&gt; <br>
&gt;&gt; ____________________________________________________<br>
&gt;&gt; <br>
&gt;&gt; Ken Kubota<br>
&gt;&gt; <a href=3D"https://doi.org/10.4444/100" target=3D"_blank">https://=
doi.org/10.4444/100</a><br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; [1] <a href=3D"https://mailarchive.ietf.org/arch/msg/tls/QusthRp6z=
RAxCvImiLLQ0SQLtME/" target=3D"_blank">
https://mailarchive.ietf.org/arch/msg/tls/QusthRp6zRAxCvImiLLQ0SQLtME/</a><=
br>
&gt;&gt; <br>
&gt;&gt; [2] <a href=3D"https://mailarchive.ietf.org/arch/msg/ssh/HGT2mTKC7=
vi9lHPdpBtQEwt57SQ/" target=3D"_blank">
https://mailarchive.ietf.org/arch/msg/ssh/HGT2mTKC7vi9lHPdpBtQEwt57SQ/</a><=
br>
&gt;&gt; <br>
&gt;&gt; [3] <a href=3D"https://www.anthropic.com/research/discovering-cryp=
tographic-weaknesses" target=3D"_blank">
https://www.anthropic.com/research/discovering-cryptographic-weaknesses</a>=
<br>
&gt;&gt; <br>
&gt;&gt; [4] <a href=3D"https://anthropic.com/document/aes_mobius_bridge.pd=
f" target=3D"_blank">
https://anthropic.com/document/aes_mobius_bridge.pdf</a><br>
&gt;&gt; <br>
&gt;&gt; [5] <a href=3D"https://anthropic.com/document/aes_mobius_bridge_co=
t.pdf" target=3D"_blank">
https://anthropic.com/document/aes_mobius_bridge_cot.pdf</a><br>
&gt;&gt; <br>
&gt;&gt; [6] <a href=3D"https://youtu.be/tbjsagsiWls?t=3D2582" target=3D"_b=
lank">https://youtu.be/tbjsagsiWls?t=3D2582</a><br>
&gt;&gt; <br>
&gt;&gt; [7] <a href=3D"https://cr.yp.to/talks/2023.06.15/slides-djb-202306=
15-pqrisk-4x3.pdf" target=3D"_blank">
https://cr.yp.to/talks/2023.06.15/slides-djb-20230615-pqrisk-4x3.pdf</a>, p=
. 6<br>
&gt;&gt; <br>
&gt;&gt; [8] <a href=3D"https://youtu.be/qPhoJQtvgUo?t=3D740" target=3D"_bl=
ank">https://youtu.be/qPhoJQtvgUo?t=3D740</a><br>
&gt;&gt; <br>
&gt;&gt; [9] <a href=3D"https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI=
/Publications/TechGuidelines/TG02102/BSI-TR-02102-1.pdf?__blob=3Dpublicatio=
nFile&amp;v=3D14" target=3D"_blank">
https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidel=
ines/TG02102/BSI-TR-02102-1.pdf?__blob=3DpublicationFile&amp;v=3D14</a>, p.=
 40<br>
&gt;&gt; &quot;The development of fault-tolerant quantum computers has a mu=
ch less severe impact on the<br>
&gt;&gt; security of symmetric mechanisms than on the security of asymmetri=
c mechanisms. The use of<br>
&gt;&gt; Grover=E2=80=99s algorithm [61] could theoretically accelerate the=
 search of the key space of symmetric<br>
&gt;&gt; mechanisms quadratically. Whether an acceleration compared to a cl=
assic exhaustive search of the<br>
&gt;&gt; key space can also be achieved in practice is the subject of curre=
nt research, see e.g. [76]. Never-<br>
&gt;&gt; theless, especially for applications with high or long-term protec=
tion requirements or long-living<br>
&gt;&gt; systems it is advisable to use a key length of 256 bits for the sy=
mmetric encryption methods<br>
&gt;&gt; recommended below.&quot;<br>
&gt;&gt; <br>
&gt;&gt; [10] <a href=3D"https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr=
6vgdjivHGj1mxCun3Rs/" target=3D"_blank">
https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/</a><=
br>
&gt;&gt; <br>
&gt;&gt; [11] <a href=3D"https://mailarchive.ietf.org/arch/msg/ssh/ONXLAO9C=
R9w6tUhwE3ag9CB14tE/" target=3D"_blank">
https://mailarchive.ietf.org/arch/msg/ssh/ONXLAO9CR9w6tUhwE3ag9CB14tE/</a><=
br>
&gt;&gt; <br>
&gt;&gt; [12] <a href=3D"https://mailarchive.ietf.org/arch/msg/ssh/47mIx2MI=
jUYpn45EBysgmCHy5_4/" target=3D"_blank">
https://mailarchive.ietf.org/arch/msg/ssh/47mIx2MIjUYpn45EBysgmCHy5_4/</a><=
br>
&gt;&gt; <br>
&gt;&gt; _______________________________________________<br>
&gt;&gt; Ssh mailing list -- <a href=3D"mailto:[email protected]" target=3D"_bla=
nk">[email protected]</a><br>
&gt;&gt; To unsubscribe send an email to <a href=3D"mailto:[email protected]=
rg" target=3D"_blank">
[email protected]</a><br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; Ssh mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">=
[email protected]</a><br>
&gt; To unsubscribe send an email to <a href=3D"mailto:[email protected]" =
target=3D"_blank">
[email protected]</a><br>
<br>
_______________________________________________<br>
TLS mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">tls@i=
etf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" targe=
t=3D"_blank">
[email protected]</a><u></u><u></u></p>
</blockquote>
</div>
</div>

_______________________________________________<br>
TLS mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">tls@i=
etf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" targe=
t=3D"_blank">[email protected]</a><br>
</div></blockquote></div>

--0000000000009174a90657d33feb--


--===============5699706413379928801==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK

--===============5699706413379928801==--