Subject: Re: 1024 bit key considered insecure (sshd)
To: Paul Hoffman <phoffman@proper.com>
From: Curt Sampson <cjs@cynic.net>
List: tech-security
Date: 08/29/2002 12:27:54
On Wed, 28 Aug 2002, Paul Hoffman wrote:

> Apparently not closely enough. In the first link, the sentence "I
> have long believed that a 1024-bit key could fall to a machine
> costing $1 billion" should give you an indication of the strength of
> the default key size. If you have adversaries who want to spend $1
> billion to break your key, you probably have spent the time to do a
> security analysis of your machine and have already changed your keys
> to something longer.

Well, if I have adversaries with a billion bucks, they'll spend a
lot less than that to get to my data through other means.

Probably they should just come to me with a couple million, and
I'll sell it to 'em. :-)

cjs
-- 
Curt Sampson  <cjs@cynic.net>   +81 90 7737 2974   http://www.netbsd.org
    Don't you know, in this new Dark Age, we're all light.  --XTC