AES is approved by the NSA for top secret information
Correction: AES192 and AES256 are approved by the NSA as a component in an approved implementation. AES128 is specifically NOT permitted for use with top secret information.
They're not that far ahead any more.
Schneier is probably right; the NSA is probably a few years ahead technologically instead of two decades ahead. However, they still have a very large budget.
Rijndael was selected in 2001 after a 5-year selection process. I assume AES128 was never allowed from the beginning; the alternative would leak too much information. We still think AES128 must be brute forced. So what's the chance that today they're over a decade ahead?
Comments
AES is approved by the NSA for top secret information
Correction: AES192 and AES256 are approved by the NSA as a component in an approved implementation. AES128 is specifically NOT permitted for use with top secret information.
They're not that far ahead any more.
Schneier is probably right; the NSA is probably a few years ahead technologically instead of two decades ahead. However, they still have a very large budget.
Rijndael was selected in 2001 after a 5-year selection process. I assume AES128 was never allowed from the beginning; the alternative would leak too much information. We still think AES128 must be brute forced. So what's the chance that today they're over a decade ahead?