In the post he also describes that he now uses a new process which involves a computer that has never been connected to the internet and its sole purpose is encrypting and decrypting files. Why not use it to encrypt and decrypt emails as well? That'd also potentially involve generating a new key pair. > 3) Assume that while your computer can be compromised, it would take work and risk on the part of the NSA – so it p…
With linux, is there any way to compromise the USB stick used for the air gap? AFAIK the Stuxnet virus was originally spread via USB stick, however I reckon that it involved Windows machines that are known to execute files on USB sticks.
Bruce Schneier has changed his PGP key to 4096 bits
31–40 of 144 posts
Re: Bruce Schneier has changed his PGP key to 4096 bits
#32Earlier quoted context omitted.
Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)
Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#33Is he really afraid of 2^n/2 brute power of quantum computers or this is just overkilling of overkill?
There's no need for a quantum computer. Everyone should be using at least 4096bit RSA. 1024bit RSA keys can be factored with conventional non-specialized hardware (read: CPU's, not even GPU's) with GNFS. IMHO, 2048bit RSA keys can be factored by custom hardware that the NSA has developed. I posted my reasoning for this hypothesis in other hackernews threads. A very quick/terse run down of the main key points - 1) NSA…
Re: Bruce Schneier has changed his PGP key to 4096 bits
#34In the post he also describes that he now uses a new process which involves a computer that has never been connected to the internet and its sole purpose is encrypting and decrypting files. Why not use it to encrypt and decrypt emails as well? That'd also potentially involve generating a new key pair. > 3) Assume that while your computer can be compromised, it would take work and risk on the part of the NSA – so it p…
With linux, is there any way to compromise the USB stick used for the air gap? AFAIK the Stuxnet virus was originally spread via USB stick, however I reckon that it involved Windows machines that are known to execute files on USB sticks.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#35Is he really afraid of 2^n/2 brute power of quantum computers or this is just overkilling of overkill?
There's no need for a quantum computer. Everyone should be using at least 4096bit RSA. 1024bit RSA keys can be factored with conventional non-specialized hardware (read: CPU's, not even GPU's) with GNFS. IMHO, 2048bit RSA keys can be factored by custom hardware that the NSA has developed. I posted my reasoning for this hypothesis in other hackernews threads. A very quick/terse run down of the main key points - 1) NSA…
Re: Bruce Schneier has changed his PGP key to 4096 bits
#36Is he really afraid of 2^n/2 brute power of quantum computers or this is just overkilling of overkill?
There's no need for a quantum computer. Everyone should be using at least 4096bit RSA. 1024bit RSA keys can be factored with conventional non-specialized hardware (read: CPU's, not even GPU's) with GNFS. IMHO, 2048bit RSA keys can be factored by custom hardware that the NSA has developed. I posted my reasoning for this hypothesis in other hackernews threads. A very quick/terse run down of the main key points - 1) NSA…
3. Most corps, diplomats, criminals, and normal people use 2048bit RSA either directly (SSH keys, Website Certs, VPNs) or indirectly (CA's still use 2048bit RSA certs valid until 2020)"
I don't see how this is evidence that NSA has the ability to compromise 2048 bit keys, at will. Only that they very likely desire that ability. Math doesn't respond to desire.
That's not to say I believe they don't. Just that I can't accept two of your three premises for why one should believe they do.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#37I know I'm still a cryptographic neophyte, but why doesn't he use four times the bits?
Re: Bruce Schneier has changed his PGP key to 4096 bits
#38Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#39Earlier quoted context omitted.
Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.
Does the reason for that ever come up in a conversation? I thought that everyone working in security used PGP a lot.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#40Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.
I'm not sure this is so much an "or", but maybe, at best, an "and" given the circumstances of source material he is currently working with. I'm not as ready to assume the timing is only routine maintenance.