It might be worth pointing out that the Boomerang attack by Alex Biryukov and Dmitry Khovratovich requires four keys. Some of the older related key attacks required $2^{35}$ keys, which makes the attack much harder in practice. But forcing a target to rekey four times is quite realistic.
↧