Re: NSA and crypto

Paul Rubin wrote:
The information theoretic argument is sound, it's just that if it
makes any practical difference, then AES is so insecure that we're all
in big trouble.

And, to continue the thought, under those premises, even compressing
before you AES encrypt will still be insecure as well (because no
compressor is perfect; any compression algorithm will leave enough
redundancy in the plaintext that you will quickly reach the unicity
distance). So if you believe that all security must rest on purely
information-theoretic foundations, then neither AES encryption on its own,
nor compression followed by AES encryption, is adequate.

