
17 Dec
2003
17 Dec
'03
11:17 p.m.
Adam Shostack writes:
| Adam Shostack writes: | > Well, if Leahy passes, DCE is exportable. Anyone know if the | > 'SecureRPC' in DCE is the one BAL broke years back? | | No, they broke Sun's Secure RPC, which is different.
I wasn't aware there were multiple things masquerading under the name Secure RPC. In any event, does the crypto in DCE stand up to the LaMacchia/Odlyzko attacks?
They are attacks against Diffie-Hellman. I don't know if DCE uses D-H in a similar manner. The main problem was too small a (fixed) modulus.
(And did Sun ever upgrade what they ship?)
I don't believe so. Perry