When commercial organizations look for encryption or security products, they frequently know very little about anything to do with computer security - the approach can be summarized as something like "We want to do Internet commerce because that's where the money and the suckers are. Give us a large order of security, and a side order of encryption, to go". A typical response to the specification for an encryption product runs along the lines of "What are all these algorithms? IDEA, what's that? Safer? Blowfish? What are all these encryption modes, ECB, CFB, CBC? Why do we need this secure key exchange thing, what's wrong with just faxing them a new key every day, or sending it in email?" (this really happened!).
Click Here to download this article