Photuris 512bit Prime Challenge? (Re: Photuris Primality verification needed)
-----BEGIN PGP SIGNED MESSAGE----- Hilarie Orman <ho@cs.arizona.edu> wrote:
Well, since we already require 56-bit DES in ESP in the interests of promoting basic interoperability, wouldn't a 512-bit prime be similarly sufficient?
If you are willing to accept that in all likelihood, one year from now, some group will announce that can "crack" all key exchanges that using the published modulus, then sure, call it sufficient.
Sounds like someone just threw down a gauntlet. Is it even possible to do the precomputations in a distributed manner in less than a year or two? Or maybe starting a few years down the road? It would be nice to give Photuris a chance to get established before the least common denoninator shared modulus gets taken out, if we even can take it out. Richard -----BEGIN PGP SIGNATURE----- Version: 2.6.2 iQCVAwUBMKDVvfobez3wRbTBAQHpkgP9Fg+MGMz8U6Bisv45PZohoZxWbiEYuxJK tg8oHD8TZRQsuqCwveWFRTnmPGiGKs2cBs5ZKXkFNU6ot7lZLO8d/1BSSjo0yX2Q 0FSXDSaBjUKIFcjHHGYBWrZZ+gjc/bdab94EqQvmFSUmAp73/mnKZgcyUPGL3Cmt MW3jZhlVMdw= =bfsQ -----END PGP SIGNATURE-----
Richard Johnson writes:
Hilarie Orman <ho@cs.arizona.edu> wrote:
If you are willing to accept that in all likelihood, one year from now, some group will announce that can "crack" all key exchanges that using the published modulus, then sure, call it sufficient.
Sounds like someone just threw down a gauntlet.
Is it even possible to do the precomputations in a distributed manner in less than a year or two?
I would guess that it probably is. However, there is no point in trying to do this yet since I suspect that Phil and Bill can be convinced that its a bad idea to specify a 512 bit modulus. Perry
participants (2)
-
Perry E. Metzger -
Richard.Johnson@Colorado.EDU