Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

>...reduced the allowed limit of data encrypted with a single key to 2^20 blocks = 8MB.

Is that is from here?

* https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-De...

I can't find any indication that this has transitioned from the proposal stage to an actual recommendation. But at any rate, this proposal is based on sweet32[1] which was a oracle attack which required 785 GB of traffic to demonstrate. Off the top of my head, recommendations for things like email (and file encryption), which are not vunerable to that sort of oracle attack, suggest a maximum for 64 bit block length ciphers of something like 4 GB. Email tends to be a maximum of 50 MB. That would be after base64 encoding.

[1] https://sweet32.info/



Yes, it became part of the standard in rev 2. 3DES will be completely forbidden for federal use after the end of the year. Sweet32 was a demo, attacks get better. And there are other generic attacks against overuse of 64-bit blockciphers. Outside of a few usecases in constrained environments there’s no good reason to use a 64-bit blockcipher anymore (and there are better choices than DES/IDEA for those cases).

https://csrc.nist.gov/news/2023/nist-to-withdraw-sp-800-67-r...


OK, but how does any of this refute my contention that 3DES is secure for PGP over email?


Just to be clear, you are asking how all this evidence refutes your totally unsupported assertion that 3DES is “perfectly secure” against the NSA? When even the NSA, who co-designed DES in the first place, forbid its continued use?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: