<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Blog &#187; Criptografie</title>
	<atom:link href="http://www.insecure.ro/category/criptografie/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.insecure.ro</link>
	<description>It's all about Security - Security Blog -</description>
	<lastBuildDate>Mon, 24 May 2010 08:30:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>AES Vulnerabil?!</title>
		<link>http://www.insecure.ro/news/aes-vulnerabil/</link>
		<comments>http://www.insecure.ro/news/aes-vulnerabil/#comments</comments>
		<pubDate>Sat, 18 Jul 2009 09:48:36 +0000</pubDate>
		<dc:creator>inSecure</dc:creator>
				<category><![CDATA[Criptografie]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[aes bruteforce]]></category>
		<category><![CDATA[cracking AES]]></category>

		<guid isPermaLink="false">http://www.insecure.ro/?p=168</guid>
		<description><![CDATA[Se zice a aparut un nou atac asupra AES, ce are performante mai bune decat cel &#8216;brute force&#8217;: &#8220;Abstract. In this paper we present two related-key attacks on the full AES. For AES-256 we show the first key recovery attack that works for all the keys and has complexity 2^119, while the recent attack by [...]]]></description>
			<content:encoded><![CDATA[<p>Se zice a aparut un nou atac asupra AES, ce are performante mai bune decat cel &#8216;brute force&#8217;:</p>
<p><em>&#8220;Abstract. In this paper we present two related-key attacks on the full AES. For AES-256 we show the first key recovery attack that works for all the keys and has complexity 2^119, while the recent attack by Biryukov-Khovratovich-Nikolic works for a weak key class and has higher complexity. The second attack is the first cryptanalysis of the full AES-192. Both our attacks are boomerang attacks, which are based on the recent idea of finding local collisions in block ciphers and enhanced with the boomerang switching techniques to gain free rounds in the middle.&#8221;<br />
<span id="more-168"></span><br />
In an e-mail, the authors wrote: &#8220;We also expect that a careful analysis may reduce the complexities. As a preliminary result, we think that the complexity of the attack on AES-256 can be lowered from 2^119 to about 2^110.5 data and time. We believe that these results may shed a new light on the design of the key-schedules of block ciphers, but they pose no immediate threat for the real world applications that use AES.&#8221;</p>
<p>Agreed. While this attack is better than brute force &#8212; and some cryptographers will describe the algorithm as &#8220;broken&#8221; because of it &#8212; it is still far, far beyond our capabilities of computation. The attack is, and probably forever will be, theoretical. But remember: attacks always get better, they never get worse. Others will continue to improve on these numbers. While there&#8217;s no reason to panic, no reason to stop using AES, no reason to insist that NIST choose another encryption standard, this will certainly be a problem for some of the AES-based SHA-3 candidate hash functions.</em></p>
<p>Daca nici AES nu mai este &#8216;sigur&#8217; ce ne mai ramane?!<br />
Presupun ca este aceiasi valva ca la md5, cica si el fusese &#8216;spart&#8217;<a href="http://blogs.technet.com/srd/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx">[link]</a>, dar inca mai este folosit la scara larga, deoarece este foarte greu de &#8216;spart&#8217;.<br />
Mai multe detalii despre vulnerabilitatea in AES <a href="https://cryptolux.org/mediawiki/uploads/1/1a/Aes-192-256.pdf">aici. </a><br />
<a href='http://secure.hostgator.com/cgi-bin/affiliates/clickthru.cgi?id=NullCode' target='_blank'><img src='http://www.hostgator.com/affiliates/banners/HG468x60-1.gif' /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.insecure.ro/news/aes-vulnerabil/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
