3 ms·
I really like that they were not only upfront about this, but appear to have gotten ahead of it. Good on them. Also, RSA-4069? That's pretty damn hefty, is the
by Vexs 10y ago
I really like that they were not only upfront about this, but appear to have gotten ahead of it. Good on them.
Also, RSA-4069? That's pretty damn hefty, is there even a point to using that?
- sdsfasd 10y agoIts to try to mitigate against a (generally state) adversary saving the session and waiting 10 years or more and then breaking the now weak encryption (ie rsa-2046 is projected to be "usable" until 2030 by NIST) This is one of the reasons why the NSA (and other intelligence agencies around the world) have these huge data centers that essentially just store everything they collect. So that later they can retroactively go through and get a back story.
- goodplay 10y ago> RSA-4069? That's pretty damn hefty This surprised me for a different reason: I was under the impression that effective security bit size does not scale linearly with bit lengths in RSA, and that key size would need to be 16,000-bits long for a comfortable safety margin (a size not practical and not supported by RSA). Are there any practical reasons why one shouldn't use epileptic-curve based crypto?
- kobayashi 10y ago>epileptic *elliptic
- theandrewbailey 10y ago> Are there any practical reasons why one shouldn't use epileptic-curve based crypto? Because it doesn't exist yet? Sounds like it would be all over the place and secure. \s Isn't RSA more widely used? It could also be that the NSA is discouraging EC-based crypto[0]; though whether this is due to "We can't crack this" to "As a guideline to other agencies OMG THIS SHIT IS SO BROKEN" is anyone's guess. [0] by alleged concerns over quantum computing https://threatpost.com/nsas-divorce-from-ecc-causing-crypto-hand-wringing/115150/ https://threatpost.com/nsas-divorce-from-ecc-causing-crypto-...