Security Implications of Using the Data Encryption Standard
RFC 4772, “Security Implications of Using the Data Encryption Standard”, is an Informational document published in December 2006 by S. Kelly. The canonical text is published by the RFC Editor.
Abstract
The Data Encryption Standard (DES) is susceptible to brute-force attacks, which are well within the reach of a modestly financed adversary. As a result, DES has been deprecated, and replaced by the Advanced Encryption Standard (AES). Nonetheless, many applications continue to rely on DES for security, and designers and implementers continue to support it in new applications. While this is not always inappropriate, it frequently is. This note discusses DES security implications in detail, so that designers and implementers have all the information they need to make judicious decisions regarding its use. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4772 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4773 Administration of the IANA Special Purpose IPv6 Address Block
- RFC 4774 Specifying Alternate Semantics for the Explicit Congestion Notification Field
- RFC 4769 IANA Registration for an Enumservice Containing Public Switched Telephone Network Signaling Information
- RFC 4775 Procedures for Protocol Extensions and Variations
- RFC 4768 Desired Enhancements to Generic Security Services Application Program Interface Version 3 Naming
- RFC 4776 Dynamic Host Configuration Protocol Option for Civic Addresses Configuration Information
- RFC 4777 IBM's iSeries Telnet Enhancements
- RFC 4763 Extensible Authentication Protocol Method for Shared-secret Authentication and Key Establishment