[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: why I like having a proprietary archive format



In article <nugundamE7HLMC.5nM@netcom.com>,
Joseph Lee <nugundam@netcom.com> wrote:
>Nathan Mates (nathan@visi.com) wrote:
>:    PGP is a publically encryption format that uses the products of
>: very large primes to encode stuff up; a 2048 bit key is essentially
>: uncrackable (see millions of years above) without math coming up with
>: a fast factorization algorithm. [None is known to date, and so PGP and
>: related algorithms are trusted]

>As I remember, a math prof and a bunch of his students decoded PGP
>encryption without the key, given 3 months of computer time and a lot of
>math theory.  It was some story I read a while ago.

   PGP is not one single key; it is the user-chosen product of two big
primes. The number of bits that you use make it harder to crack, from
the easier 48-bit keys to the 2048 bit ones. Each extra bit should
roughly double the difficulty of hacking at a given key.

   A few 48-bit RSA keys have fallen already (a month and a half of
time by several thousand machines, including one or two at work :) and
some 56 bitters are now under the same kind of scrutiny. But, with
that exponential increase, I'd say a 2048 bit key is pretty darn
tough.

   If you can hack out a big key with a few thousand processor hours,
I'd think that some random proprietary archive format could also be
undone...

Nathan Mates

--
<*> Nathan Mates http://www.visi.com/~nathan/      <*>
# What are the facts? Again and again and again-- what are the _facts_?
# Shun wishful thinking, avoid opinion, care not what the neighbors
# think-- what are the facts, and to how many decimal places?  -R.A. Heinlein