Nexus wrote:
Meh, use AES 256-bit to encrypt data before sending it anywhere. That's probably the best encryption out there. It's what the U.S Government uses to protect highly classified stuff.
But I thought they could demand passwords for ALL encrypted files regardless of cipher used.
NO, what the us government requires is that AES 256 be used in addition to at least three more levels.
Physical security/human trustworthness of anyone who knows such secrets
Physical security of all electronic systems that handle the AES-256 keys.
An additional human level of security (one more level of compartmentalisation) for those who manage the keys.
The academic theoretical vulnerabilities have always existed.
hence the first rule of Cryptography :never invent your own