Daniel J. Bernstein: Break a dozen secret keys, get a million more for free
29.11.2015
Batch attacks are often much more cost-effective than single-target attacks. For many years NIST has officially claimed that AES-128 has "comparable strength" to 256-bit ECC, namely 128 "bits of security". Ten years ago Bernstein disputed this claim.