I've factored the RSA keys of a Certificate Authority from the 90s
31–40 of 131 posts
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#32How was it actually factored though? Where is the code for that? How was the private key created and how are the new certs issued?
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#33Earlier quoted context omitted.
For what it's worth, this comment was better than the article... When you outsource to the slop machine, you don't have anything interesting to say (usually).
Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#34Earlier quoted context omitted.
Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy
Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#35Earlier quoted context omitted.
Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.
I don't recall doing any of that. But thanks for affirming my point? :)
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#36A bit unfortunate that so many of the interesting bits were left to ai. I would've enjoyed some commentary on why the custom TLS implementation was necessary. Oh well. Update: found this explanation in a comment at the top of the (surprisingly short) Go file in the linked repo: The target client is Netscape Communicator 4.51 (both the 40-bit export build and the 128-bit US build) with its clock set to the year 2000.…
(As the author of the post) I've written and worked on a few TLS implementations, so it wasn't terribly interesting to me. And I have to go to work tomorrow and solve real, modern CA problems :) But in short, I wanted to use Go, and it doesn't support SSLv3, the SSLv2 Client Hello, or the 40-bit RC4-MD5 export-grade cipher suites which I wanted to support too. I was more shocked that I managed to get stock OpenSSL to…
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#37Earlier quoted context omitted.
I don't recall doing any of that. But thanks for affirming my point? :)
Did I imply you did? I simply said I never see a "pro AI" mob, only an "anti AI" mob.
Is the "anti AI mob" in the room with us right now? If not, why did you feel the need to lament it?
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#38Re: I've factored the RSA keys of a Certificate Authority from the 90s
#39Earlier quoted context omitted.
Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy
Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#40Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encrypted at all! But about a decade later, it became normal to encrypt everything. I do wonder which governments around the world are just waiting to crack anonymous political speech by recording and saving for later when decryption can happen.
Probably not too many, because anonymous political speech from 10+ years ago isn't that interesting. Punishing people a decade after the fact isn't very effective for anything.