4 ms·
The real question is why use 512 bit RSA when you can use 2048+?
by stonewareslord 5y ago
The real question is why use 512 bit RSA when you can use 2048+?
- mastax 5y agoSo it can fit on a reasonably sized QR code probably.
- est31 5y agoKey size determines number of bytes the signature takes up, which is one of the determinants of the complexity of a QR code. I suppose if you don't know what you are doing, and want to reduce QR code complexity, you lower the key size. To turn up speculation to 100, this might also be a third world issue, because here in the west we have high quality smartphones with good cameras, but the smartphone cameras there might not be as good, so they might be challenged reading QR codes. 8 years ago I built a thing that had customized links accessible via QR codes, but my buddy's cheap phone couldn't read them due to issues with the camera resolution. A lot has happened in 8 years in terms of progress, but they still put crappy cameras into cheaper phones, and this might still pose a problem for reading complex QR codes.
- dundarious 5y agoTake a look at QR image in the post. I haven't seen a QR code in the first world that carries more data, especially not a printed one. It's doubtful they're optimizing for poor cameras or printers any more than is done in the first world, and to be clear, in the first world we still have to optimize for poor cameras and printers. Decreasing the message size while improving security would obviously be ideal and most likely quite achievable, but there are plenty of wealthy municipalities in the US who don't exactly cover themselves in honor in similar situations. While I'm not at all saying it's illegitimate to speculate on wealth disparities as a cause, in this case I think it's lazy to call this a "third world issue", even with speculation up to 100.
- tgsovlerkhgsel 5y agoThe EU covid certificates that I've seen have way more data (this one has 3x3 alignment markers, the certificates I've seen in production have 4x4).
- nowahe 5y agoHave you ever looked at the size of the standardize EU QR code[0] ? At just a glance it looks at least 2-3x denser than the one presented in the article. Also, on the specification published by the EU[1], they seem to advise for a 25-60cm size, and also warn about using <300dpi printers. When I was vaccinated, I was given an A4 sheet with those QR codes on it, and I really wouldn't want to scan those with a crappy camera. [0]: https://gir.st/blog/greenpass.html https://gir.st/blog/greenpass.html [1]: https://ec.europa.eu/health/sites/default/files/ehealth/docs/digital-green-certificates_v1_en.pdf https://ec.europa.eu/health/sites/default/files/ehealth/docs... § 4.2.2
- Beldin 5y agoFrom there [1]: Primary Algorithm: The primary algorithm is Elliptic Curve Digital Signature Algorithm (ECDSA) as defined in (ISO/IEC 14888–3:2006) section 2.3, using the P–256 parameters as defined in appendix D (D.1.2.3) of (FIPS PUB 186–4) in combination the SHA–256 hash algorithm as defined in (ISO/IEC 10118–3:2004) function 4. This corresponds to the COSE algorithm parameter ES256. Secondary Algorithm: The secondary algorithm is RSASSA-PSS as defined in (RFC 8230) with a modulus of 2048 bits in combination with the SHA–256 hash algorithm as defined in (ISO/IEC 10118–3:2004) function 4. So not exactly 512 bit RSA.
- godmode2019 5y agohttps://nzcp.covid19.health.nz/#examples https://nzcp.covid19.health.nz/#examples Here is the nz version
- Spooky23 5y agoMy guess is Vietnam’s spec was to achieve the same level of integrity as a paper document (ie. Minimal) and optimize for cheap/poor quality cameras. Longer keylengths make it difficult to deliver sufficient payload in a QR. not sure about EU, but the SMART health passes that are the emerging standard use ES256 signatures. The lack of global leadership for interoperable standards early on made this more difficult. You had the EU, Israel, US states and others who were ahead of the curve, but that approach had limits that were reached. Now in the US we also have the issue of dealing with states with wacky political stances. States like California, New York and Louisiana, combined with private sector leaders like Walmart and Epic made SMART the defacto US standard, and other countries are recognizing them.
- deleted 5y ago[deleted]
- waynecochran 5y agoRSA 512-bits key was proven breakable years ago Even so, I am amazed they were able to break it so quickly and cheaply.