, How practical can be the plaintext recovery attack on CTR ? ? Mostly used with AES, famous 128-bit block cipher, as part of GCM. 90% of Firefox HTTPS traffic uses AES-GCM

, ? Requires 128 × 2 64 bits = 256 exbibytes over one session ? 2016 global IP traffic is 82.3 exbibytes per month

, ? SSHv2 includes CTR with 3DES, a 64-bit block cipher. ? Requires 64 × 2 32 bits = 32 GiB ? Quickly attainable with modern internet speed