Re: 1619: LRW collision probabilities
Laszlo wrote:
> [...]
>> just replace the *shall* with a *should* in the part that talks about not
>> using the same key for too much data?
>
> This was my proposal, with adding the security tradeoff expressions to the
> Appendix.
In this case let me go on the record as supporting this proposal.
I would only put the simplistic upper-bound in the appendix, though, so
as not to make it too complicated. Also, I would note that in most cases
what you need to count is the number of block encryptions and not just
the size of the storage.
-- Shai
p.s. It seems that there is a fair number of us that will be present
in Crypto next week. Can we schedule a face-to-face meeting over there
instead of the one that was canceled today?