3 ms·
The signing key for Gmail's certificate is a 1024-bit RSA key. That key size is simply not safe against an attacker like the NSA today, so we may as well assume
by mti 13y ago
The signing key for Gmail's certificate is a 1024-bit RSA key. That key size is simply not safe against an attacker like the NSA today, so we may as well assume they have the private key even if Google didn't voluntarily give it to them.
But while the signing key may allow them to impersonate Google in some circumstances, it doesn't really help decrypting passively recorded TLS traffic to the real Google. For that, they would need to break the ECDH key exchange, and if Google uses reasonable elliptic curve parameters, that's presumably much harder than factoring a 1024-bit RSA modulus, at least with known cryptanalytic techniques.
- abraham 13y agoGoogle is currently working on upgrading their certificates so in the future it will be better: http://googleonlinesecurity.blogspot.com.au/2013/05/changes-to-our-ssl-certificates.html http://googleonlinesecurity.blogspot.com.au/2013/05/changes-...