Changing preferences

Robert J. Hansen rjh at
Wed Sep 24 16:19:27 CEST 2008

Kevin Hilton wrote:
> would seem that Serpent and 3DES have a lot in common -- slowness, but
> security.

Arguably true.

> How a cipher like cast5, but not Serpent could be
> included, other than for historical reasons, is beyond me.

Purely historical reasons.  Also, the SERPENT design team, much like the
Twofish design team, is strongly pushing abandoning the AES also-rans
and using AES.

A lot of people think CAST5's selection as PGP 5's encryption algorithm
was a mistake, given the ready availability of 3DES.  CAST5 is also not
very well known or well liked outside of OpenPGP.  Schneier, for
instance, has said "I give a big 'yuck!' to the design process."  (Some
people think this is because CAST5 is very similar to Blowfish and
Schneier is feeling protective of his own algorithm, however.)

More information about the Gnupg-users mailing list