4 ms·
In a world where we measure webpage size in megabytes, why do people consider key size to be so important? I can see TLS caring due to latency, but gpg? I could
by oconnore 9y ago
In a world where we measure webpage size in megabytes, why do people consider key size to be so important? I can see TLS caring due to latency, but gpg? I could attach a McEliece quantum 8MB key to every email I ever send, so your "large" RSA keys aren't a big deal.
Edit: oh, smart cards...
- epistasis 9y agoAlso, are operations linear in key size? This source says for k bits in a key, operations with the private key are cubic in key length, and key generation is O(k^4): http://x5.net/faqs/crypto/q9.html http://x5.net/faqs/crypto/q9.html but seems to be from the 90s. Maybe faster algorithms are merited now...
- vbezhenar 9y agoThey are significantly slower. But for GPG it doesn't matter, as long as time is reasonable. It uses RSA to encrypt short key which then encrypts the entire message using something like AES. But it would matter for website served over HTTPS.
- tscs37 9y agoProtocols. You really don't want to sign every TLS packet with a 8MB signature or in this case, send 8MB key material over TLS before properly opening the session. Even if you are the 1% with gigabit connections, that is going to induce some decent latency into the system. It's simply wasteful.
- diafygi 9y agoHeh. The way web bloat is going, I can totally see a framework "optimizing" this by showing the user a spinner over HTTP while an ajax request does the first tls handshake, then redirects the user to the https version of the site.
- stephenr 9y agoThat defeats the purpose of https - the code/response that dictates the redirect can be intercepted and redirect the user to a malicious site.
- stephenr 9y ago> In a world where we measure horribly built webpage size in megabytes Fixed that for you.