@cryptomancer@fediverse.cryptomancer.de
Post #4239941
2026-07-30 06:56 UTC
From what I understand, they attacked a 7 round version of #AES and not the standardised 10 rounds for AES-128, no? If so, would the attack scale to the 14 rounds of AES-256?
CC: @SteveBellovin@infosec.exchange @CryptoOrrDun@ioc.exchange
Replies (1)
-
@SteveBellovin@infosec.exchange 2026-07-30 12:08
@cryptomancer @CryptoOrrDun@ioc.exchange Yes, 7 rounds, and no, it doesn't scale even to 10 rounds, let alone 14. Attacking weakened versions of ciphers is a standard analytic technique—and sometimes a variant of the attack on a weakened version will scale up and sometimes it won't. (A fair number of years ago, there was a decent attack on a weakened version of Skipjack, an NSA-designed cipher. I showed that to someone I knew who had NSA contacts. His reply: "You call it worrisome; I call it good engineering." To my knowledge, no one has ever been able to scale it up to the full cipher.)