* Eli Biham and Lars Knudsen. It's not particularly quick, but is
* stunningly secure. The best differential and linear attacks are
* speculated to require %$2^{256}$% texts (it's a 128-bit block cipher).
* Eli Biham and Lars Knudsen. It's not particularly quick, but is
* stunningly secure. The best differential and linear attacks are
* speculated to require %$2^{256}$% texts (it's a 128-bit block cipher).