Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>>It is possible that there is still some magic in there to let the NSA magically defeat DES, but we still haven't found it.

Actually the NSA s-boxes are weak against linear crypto analysis. http://reference.kfupm.edu.sa/content/l/i/linear_cryptanalys...

If I remember Schneider's applied cryptography correctly, the NSA s-boxes were among the worst 7% possible.

I wonder what we would be saying about the NSA if we (publicly) discovered linear crypto-analysys before differential. However, I suspect the vulnerabilty to linear analysys is the result of how structured they made it to resist differential.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: