Also, I have a vague memory of people who believe that block ciphers with X bit keys only provide X/2 bits of security. I can't site papers now, but maybe you or someone else can substantiate or refute this. I've always thought that this was the reason AES were standardized with both 128 and 256 bit sizes. /Simon