next AE cipher COLM?

Bernhard Reiter bernhard at
Fri May 18 09:19:32 CEST 2018

> Although, if you found a weakness in GCM mode - by all means, please share
> it with the wider audience.

Christian Forler and Rüdiger Weis report on problems with GCM
around 28:00 in their 2017 CCC talk here:
where their cite three papers.

--   +49 541 33 508 3-3
Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: This is a digitally signed message part.
URL: <>

More information about the Gnupg-devel mailing list