Kristian Gjøsteen wrote:
> Sebastian G. <seppi@seppig.de> wrote:
>> Kristian Gjøsteen wrote:
>>
>>> rossum <rossum48@coldmail.com> wrote:
>>>> I was hoping for something more specific about some sort of attack on
>>>> Twofish.
>>> No. No attacks are known on Twofish.
>> Mr. Schneier may not want to acknowledge them, but I think the
>> distinguishing attack with 2^52 chosen plaintexts and 2^70 steps is pretty
>> serious.
>
> The last time you claimed Twofish broken, the reference you provided
> said no such thing. Is this merely a figment of your imagination or
> another misreading/mischaracterisation of an honest scientific work? http://www.schneier.com/twofish-analysis-shiho.pdf
> PS. I'm still waiting for a reference to the claim that AES-256 with 16
> rounds is vulnerable to differential cryptanalysis.
I didn't claim it vulnerable; the attack is just a space-time-tradeoff. And
sorry, I had a lot of work recently.