I linked to Schneier's summary because I can't find a non-paywalled version of the new paper, but here's a paper by some of the same authors on the same topic, from an earlier phase of their research: http://www.krypt.cs.uni-sb.de/teaching/WS08/Seminar/reports/...