4 ms·
Security FYI: This situation concerns RSA keys, not 128-bit symmetric keys; our problem is "factoring a really big number", not "guessing a really big number".
by mnordhoff 13y ago
Security FYI:
This situation concerns RSA keys, not 128-bit symmetric keys; our problem is "factoring a really big number", not "guessing a really big number". A 128-bit RSA key can be broken in seconds.
RSA keys are commonly 2048 bits at the moment. NIST's rough rule of thumb is that a 2048-bit RSA key is equivalent in secureness to a 112-bit symmetric key; for 128-bit equivalence, you need around a 3072-bit RSA key. (2048 provides fine security for the next few decades at least.)
Edit:
You referred to "128 bits of entropy", which could be interpreted as "equivalent to a 3072-bit RSA key". I'm not accusing you of recommending insecure RSA key sizes, I just wanted to make a public service announcement. I've seen people make that mistake before.