I am a great fan of Bruce Schneier (and Twofish actually) – but isn it too soon jump on the bandwagon?
1) “Report on the AES Candidates” by Vaudenay et al. Points out that S-Boxes should “no longer be called key-dependant”. Also says “consists of a collection of patches” & “we do not think this design comes from deep investigation”. Of course, this paper is written by the authors of another AES candidate. 2) “An observation on the Key Schedule of Twofish” by Mirza & Murphy (RHBNC), points out several deficiencies with the key schedule. Implications unknown, but it does directly contradict implicit claims in the original Twofish paper. None of the candidates escaped criticism from a “cryptographic security” point of view, but if one wanted to objectively select an AES candidate by any combination of the above criteria, would we logically select Twofish at the moment?