Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Its nearly impossible to predict when someone would find vulnerabilities (or if they have already in secret, Bletchley Park anyone) in crypto primitives and the problem gets compounded we try to use untested crypto primitives such as those highlighted in this article.

AES has been around since 2001 and researchers haven't gotten past 7 of the 10 rounds so that significantly improves my confidence in its ability to not crumble under the most simple cryptanalysis.

Here's an interesting video by the author of one of the attacks on the inner round of SHA-3 explaining why public analysis is exceptionally important. https://www.youtube.com/watch?v=uT4hrWkbBxM

My point is that though gaining popularity may be good because more researchers may find vulnerabilities but until these primitives are proven its probably not a good idea to use then in any real world application.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: