4 ms·
CSS is only 40 bits, which is ridiculously easy to crack. 56-bit DES keys are pretty unsafe these days, so you want at least 128 bits if you're talking private
by redcap 10y ago
CSS is only 40 bits, which is ridiculously easy to crack. 56-bit DES keys are pretty unsafe these days, so you want at least 128 bits if you're talking private keys.
If it's using 2048-bit RSA, that's perhaps equivalent to a 256-bit private key.
So entirely different ballpark to CSS.
- aaronmdjones 10y agoWrong. 2048-bit RSA has an effective security level of approximately 112 bits, just like 3-DES. If you want 256 bits of security, you go all the way up to 15360-bit RSA. That's why Elliptic Curve systems are so attractive: they involve operations that are more costly per-bit, but the required key sizes to meet a security level are much less. Ofcourse, Elliptic Curve Cryptography as specified by NIST has its own downsides (e.g. the 3 most common curves, prime256v1, secp384r1, and secp521r1 (128 bits, 192 bits, and 256 bits of security respectively) have constants that were chosen arbitrarily by NSA with no explanation).
- rthomas6 10y agoThough when the NSA has done things like this in the past, we've found their choices prevented implementation weaknesses that weren't found (by anyone else) for several more years.
- Bartweiss 10y agoCan you follow up on that? I've never heard that story and I'm really curious. On the narrower point, though, it's been shown that Dual_EC_DRBG is broken, and that the NSA values compromised the implementation instead of strengthening it.
- hatsunearu 10y agoS boxes in DES were originally nonexistent/vulnerable to differential cryptanalysis when IBM first made Lucifer.
- jschwartzi 10y agoWhen has this happened? I'm curious about things that could cast the NSA in a positive light.
- danielvf 10y agoThe DES standard's S-Boxes were changed by the NSA in the 1970s. It was long thought that this was to weaken them. However in the 1990's differential cryptanalysis was publicly discovered, and the NSA's changes to the S-boxes were found to have hardend DES agaist differential cryptanalysis.
- PeCaN 10y agoNow here's something fascinating. According to https://en.wikipedia.org/wiki/Differential_cryptanalysis#History¹ https://en.wikipedia.org/wiki/Differential_cryptanalysis#His..., IBM discovered differential cryptanalysis in the 1970s when designing DES. They opted to keep it a secret, given its general applicability against ciphers. It is unclear whether IBM shared it with the NSA or the NSA discovered it independently, but there's strong evidence that both IBM and the NSA were aware of differential cryptanalysis well before the public discovery in the 90s. ¹ This has what looks like a good citation but requires a subscription to access the relevant paper (sigh).
- dsr_ 10y agoIt really doesn't matter how many bits, or what cipher they used. The DRM problem is fundamentally broken: 1. Hand the ciphertext to the opponent. 2. Hand the decryption algorithm to the opponent, embedded in a software or hardware device. 3. Hand the key to the opponent, possibly embedded in the hardware. 4. Ask your opponent to decrypt the ciphertext, view the plaintext, and then kindly not copy the plaintext in any other way.