Live data from Hacker News

I've factored the RSA keys of a Certificate Authority from the 90s

mcpherrin.ca

31–40 of 131 posts

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#33
post #22

Earlier quoted context omitted.

For what it's worth, this comment was better than the article... When you outsource to the slop machine, you don't have anything interesting to say (usually).

Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy

Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#34

Earlier quoted context omitted.

Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy

Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.

I don't recall doing any of that. But thanks for affirming my point? :)

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#35

Earlier quoted context omitted.

Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.

I don't recall doing any of that. But thanks for affirming my point? :)

Did I imply you did? I simply said I never see a "pro AI" mob, only an "anti AI" mob.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#36
post #11

A bit unfortunate that so many of the interesting bits were left to ai. I would've enjoyed some commentary on why the custom TLS implementation was necessary. Oh well. Update: found this explanation in a comment at the top of the (surprisingly short) Go file in the linked repo: The target client is Netscape Communicator 4.51 (both the 40-bit export build and the 128-bit US build) with its clock set to the year 2000.…

(As the author of the post) I've written and worked on a few TLS implementations, so it wasn't terribly interesting to me. And I have to go to work tomorrow and solve real, modern CA problems :) But in short, I wanted to use Go, and it doesn't support SSLv3, the SSLv2 Client Hello, or the 40-bit RC4-MD5 export-grade cipher suites which I wanted to support too. I was more shocked that I managed to get stock OpenSSL to…

I bet all the certificate metadata shown in the „View a certificate“ popup window is vulnerable to cross-site scripting. Back then you probably wouldn’t get a tag through a CA's review process and I found such a problem in Netscape's image „About page“ popup.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#37

Earlier quoted context omitted.

I don't recall doing any of that. But thanks for affirming my point? :)

Did I imply you did? I simply said I never see a "pro AI" mob, only an "anti AI" mob.

Let's flip it, then

Is the "anti AI mob" in the room with us right now? If not, why did you feel the need to lament it?

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#39

Earlier quoted context omitted.

Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy

Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.

You must be new here then.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#40
post #4

Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encrypted at all! But about a decade later, it became normal to encrypt everything. I do wonder which governments around the world are just waiting to crack anonymous political speech by recording and saving for later when decryption can happen.

> which governments around the world are just waiting to crack anonymous political speech by recording and saving for later

Probably not too many, because anonymous political speech from 10+ years ago isn't that interesting. Punishing people a decade after the fact isn't very effective for anything.

Post reply on HN