A note to people using AES

Friday, 12 November 2010 01:31:46 UTC

The United States State Department does not recommend AES for encrypting classified information.

If you don't know what AES is, you might know PGP, HTTPS, or password-protected ZIP, which all use AES in their core.

Exact details are muddy, unsurprisingly, since the sentence itself is referring to a specific implementation of AES, so it's hard to tell if it's just the implementation that's broken, or AES itself. Beware, and keep an eye on it.

Comments