[Cryptography] Strength of 3DES?

Richard Outerbridge outer at interlog.com
Tue Aug 30 04:54:00 EDT 2016


The strength of 3DES is commonly cited as 112 bits,
apart from a DESX-like construction that might bump
that up to 176 to 240 bits, with fixed pre & post
whitening 64-bit constants.

Don’t get me going on possible DESX modes of operation.

But there have been persistent rumours that the actual
strength of 3DES is 108 bits.  Anyone have a citable
source for that claim?  Even allowing one bit for the
self-similar reflection property?
__outer



More information about the cryptography mailing list