[Cryptography] Which big-name ciphers have been broken in living memory?

Bear bear at sonic.net
Mon Aug 25 14:16:17 EDT 2014


On Mon, 2014-08-25 at 05:22 +1200, Peter Gutmann wrote:
> Werner Koch <wk at gnupg.org> writes:

> (Oh, and I filed a request to move to AES as the default in 2011, subject "Why
> does GPG still default to the 15-year-old CAST5 for everything?", so people
> have asked for this to be fixed).

Is there any evidence that CAST5 is in any way inadequate?

People are upset with use of an "Antique" algorithm?  Why?  

I would be upset with the use of an "Insecure" algorithm or 
an "Untested" algorithm.  Into neither of which classes 
CAST5 falls. 

So, I say the burden of evidence falls on those requesting a 
change here.  What is wrong with CAST5 that people want to get
rid of it?

				Bear





More information about the cryptography mailing list