4 ms·
My computer contains the prime factorization of probably several dozen (if not more) large integers, and I refuse to share them with anyone! (Because they are
by connorboyle 25d ago
My computer contains the prime factorization of probably several dozen (if not more) large integers, and I refuse to share them with anyone!
(Because they are my private RSA keys)
- mitxela 25d agoWhy are you still using RSA?
- catlifeonmars 25d agoWhere else are you going to keep your large primes?
- gpugreg 25d agoIt is easier to trust what you can understand.
- bohrbohra 24d agoWait what ? Does nobody use RSA anymore ?
- deleted 24d ago[deleted]
- pferde 24d agoYes, last night we all voted and decided to move to its successor RSB instead.
- SAI_Peregrinus 24d agoECC allows greater security for key exchange (because it is so cheap to generate keys we can have "ephemeral" exchanges and forward-secrecy). It isn't significantly better for signatures in most cases.
- mitxela 24d agoECC is much faster (like 1000x) and with much smaller keys (like 10x) that are just random numbers so generating them is also free.
- LtWorf 24d agoI'm convinced that all the quantum talk is the NSA propaganda to convince us to drop RSA and move to some secure post quantum algorithm that they can easily break.
- mitxela 24d agoThe NSA did indeed try that, and some federal honeypots adopted quantum-only crypto, but everyone else is using hybrid - you need to break both sides.
- aleph_minus_one 22d ago> I'm convinced that all the quantum talk is the NSA propaganda to convince us to drop RSA and move to some secure post quantum algorithm that they can easily break. It is rather consensus that by now, - too many potential weaknesses for RSA are known (in particular in how it is used in standardized cryptosystems [1]), - it is a bad idea if too many "free parameters" of the cryptosystem are decided by the practical implementation (in RSA: the decision which primes to use to generate the key pair) instead of these parameters being part of the standard Thus the advice to drop RSA is in my opinion sound. But otherwise: many people indeed have the suspicion that the panic that a sufficiently powerful quantum computer might get developed in the next year is indeed used to push novel "post quantum algorithms" which - have not been analyzed as thoroughly as older algorithms, and thus might contain weaknesses, - were covertly developed by some three letter agency, and contain backdoors. In other words: your suspicion might not be unfounded - this just does not imply that RSA does not have its risks and should thus arguably indeed be abandoned. --- [1] Just to give one example: in the past, RSA was often used together with the padding scheme PKCS#1 v1.5, see [2] [2] https://en.wikipedia.org/w/index.php?title=PKCS_1&oldid=1342076926#Schemes https://en.wikipedia.org/w/index.php?title=PKCS_1&oldid=1342...