3 ms·
Sincere question: how do you define "how secure it is" except "how long it will remain secure (under attack)"? Edit: You're also completely eliding that secur
by SomeStupidPoint 9y ago
Sincere question: how do you define "how secure it is" except "how long it will remain secure (under attack)"?
Edit:
You're also completely eliding that security is probabilistic -- they might just guess our key on the first try. We can only discuss it as the expected amount of computation to figure out our key on average. That expected amount has a gradient along keysize.
- olliej 9y agoA protocol is secure if, and only if, the fastest attack is an attack on the key itself. All of the recent crypto breaks (that not cause by prior key size restrictions req'd by gov agencies) have been protocol flaws, e.g. flaws in the protocol allowed you to derive the key without having to just explore the entire key space. Anything other than deriving the plaintext of encrypted data alone would mean the protocol was insecure. That said, I am coming to agree with you in terms of trying to explain to people who don't write crypto code that saying key size is gradient of security is probably the most sensible thing. I still disagree with you on the actual statement :D
- zodiac 9y agoHe meant "how long before technology advances, due to Moore's Law or whatever, to the point where it's really cheap to brute force the key space". Not "how long it takes from the moment you attack it to the moment you break it"