Re: 307 digit number factored

2007-05-23 Thread Florian Weimer
* Victor Duchovni: >> That's good of you not to expect it, given that zero of the major CAs >> seem to support ECC certs today, and even if they did, those certs >> would not work in IE on XP. > > We are not talking about this year or next of course. My estimate is > that Postfix releases design

RE: 307 digit number factored

2007-05-23 Thread Dave Korn
On 21 May 2007 19:44, Perry E. Metzger wrote: > http://www.physorg.com/news98962171.html > > My take: clearly, 1024 bits is no longer sufficient for RSA use for > high value applications, though this has been on the horizon for some > time. Presumably, it would be a good idea to use longer keys

Re: 307 digit number factored

2007-05-23 Thread Victor Duchovni
On Wed, May 23, 2007 at 02:45:49PM +1200, Peter Gutmann wrote: > Victor Duchovni <[EMAIL PROTECTED]> writes: > > >As 1024 RSA keys are not a major risk *today*, > > I would go further and say that for most applications of PKCs/PKI today, 1024- > bit RSA keys are not a risk at all, or more specif

Re: 307 digit number factored

2007-05-23 Thread Peter Gutmann
Victor Duchovni <[EMAIL PROTECTED]> writes: >As 1024 RSA keys are not a major risk *today*, I would go further and say that for most applications of PKCs/PKI today, 1024- bit RSA keys are not a risk at all, or more specifically that on a scale of risk they're so far down the list that they're clo

Re: 307 digit number factored

2007-05-23 Thread Paul Hoffman
For the math weenies on the list, see the full announcement here: . --Paul Hoffman, Director --VPN Consortium - The Cryptography Mailing List Unsubscrib

Re: 307 digit number factored

2007-05-23 Thread John Levine
>somewhere over the yrs the term "certification authority" was truncated >to "certificate authority" ... along with some impression that >certificates are being sold (as opposed to certification processes). When I pay $14.95 for a certificate, with the investigation of my bona fides limited to cl

dnssec?

2007-05-23 Thread Anne & Lynn Wheeler
re: http://www.garlic.com/~lynn/aadsm27.htm#14 307 digit number factored http://www.garlic.com/~lynn/aadsm27.htm#15 307 digit number factored sometimes i wonder if at least some of the dnssec issue doesn't turn out to be related to not having a revenue flow champion. domain name certification

Re: 307 digit number factored

2007-05-23 Thread Anne & Lynn Wheeler
Ivan Krstić wrote: That can't happen until we make sure you can trust DNS, which in turn can't happen until we get a concrete proposal that has clearly defined goals and isn't braindead. As has been amply pointed out, it's not clear that DNSSEC will cut it anytime soon. A big part of the issue

RE: Russian cyberwar against Estonia?

2007-05-23 Thread Dave Korn
On 22 May 2007 14:51, Trei, Peter wrote: > In fairness, its worth noting that the issue is also mixed up > in Estonian electoral politics: > > http://news.bbc.co.uk/1/hi/world/europe/6645789.stm > > The timing of the electronic attacks, and the messages left by > vandals, leave little doubt that

Re: 307 digit number factored

2007-05-23 Thread Ivan Krstić
Anne & Lynn Wheeler wrote: > it would be really great to make it an excuse to move away from offline > paradigm to real online operation ... getting totally rid of the need for > domain name certificates ... DNS serving up both ip-addresses and public > keys in single operation. That can't happen