In message <[EMAIL PROTECTED]>, "John S. Denker" writes:

>
>So let's not guess about what quantum algorithms exist.
>It is possible to construct such algorithms, but it 
>requires highly specialized skills.
>

Last time I asked Peter Shor about it, he said that the best known 
quantum algorithms for exhaustive key search for classical ciphers was 
O(sqrt(key size)).  (To me, that's the real reason that AES needs the 
option for 256-bit keys...)

                --Steve Bellovin, http://www.research.att.com/~smb (me)
                http://www.wilyhacker.com ("Firewalls" book)



---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]

Reply via email to