Quoting Michel Arboi <mikhail nessus.org>:
> On Thu Apr 05 2007 at 17:27, Sullo wrote:
>
>>> Where does 3DES fit? Is the 112-bit key Low or
Medium?
>
>> For simplicity, I'd say < 128 == weak...
>
> 3DES is definitely not weak. AFAIK, nobody can break
that.
I would agree.
I've been comparing with Foundstone's SSLDigger, which lists
Weak as
< 128, Strong as 128-256, and Excellent > 256. One of
our contracted
assessments used this & I was trying to figure out why
no "weak"
ciphers were reported in Nessus when I tried to confirm...
hence my
statement about using 128 a the water mark for
"weak" -- I'm not sure
I care that much whether Nessus reports it as low or weak,
now that
the 56 bit ones are not just reported as "export
strength"
--
http://www.cirt.net/
| http://www.osvdb.org/
_______________________________________________
Plugins-writers mailing list
Plugins-writers list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers
a>
|