Live data from Hacker News

Bruce Schneier has changed his PGP key to 4096 bits

news.ycombinator.com

41–50 of 144 posts

Re: Bruce Schneier has changed his PGP key to 4096 bits

#41

There is nothing suspicious with that. He has worked previously in mostly corporate and private context, so 2048 is just fine. Now he works with people and data NSA wants their hands on and he wants the data to be secure also in the future. It's just reasonable to move to 4096 key sizes. http://www.pgp.net/pgpnet/pgp-faq/pgp-faq-keys.html#key-size >Dr Lenstra and Dr Verheul offer their recommendations for keylengths.…

Your secrets are not safe against multinational corporations with 1024 bit keys. The likely cost of the capability to break a 1024 bit key is probably (for a private entity) in the low tens of millions. You wouldn't even be safe from the operators of HN with that margin of security.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#42

Anyone know of a good tutorial for revoking and recreating your key as painlessly as possibly?

I'd imagine the process works something like this: * Generate the new key * Sign the new key with the old key * Generate the revocation cert for the old key * Push the revocation publicly with a reason of "Superseded by (fingerprint of new key)" or similar * Push the new key * Try to get your new key signed by everyone that signed your old key for authenticity's sake I'm not too sure how the community of GPG users ou…

One issue I have noticed is that people do not frequently update their keys from the key servers. Key revocation is not all that useful if you are not periodically checking for published revocations...

Re: Bruce Schneier has changed his PGP key to 4096 bits

#43
Bruce's article on staying secure from the NSA[1] talks about using an air gapped computer to avoid being compromised via the network. If he hadn't been keeping his keys on such a machine previously - recent disclosures may have changed his mind and forced him to regenerate his keys.

[1] http://www.theguardian.com/world/2013/sep/05/nsa-how-to-rema...

Re: Bruce Schneier has changed his PGP key to 4096 bits

#44
post #18

Earlier quoted context omitted.

Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.

Does the reason for that ever come up in a conversation? I thought that everyone working in security used PGP a lot.

In a dozen years, I think I've had a grand total of 4 clients (out of several hundred) that ever used PGP (despite recommending it specifically on project kickoff calls, particularly for communicating discovered vulnerabilities). I only had one who already had a key.

Outside of those few work examples, I don't think I've ever sent or received a PGP encrypted message. In fact, the only signed messages I think I've ever seen were mailing list messages from people who signed all their messages.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#45
post #41

There is nothing suspicious with that. He has worked previously in mostly corporate and private context, so 2048 is just fine. Now he works with people and data NSA wants their hands on and he wants the data to be secure also in the future. It's just reasonable to move to 4096 key sizes. http://www.pgp.net/pgpnet/pgp-faq/pgp-faq-keys.html#key-size >Dr Lenstra and Dr Verheul offer their recommendations for keylengths.…

Your secrets are not safe against multinational corporations with 1024 bit keys. The likely cost of the capability to break a 1024 bit key is probably (for a private entity) in the low tens of millions. You wouldn't even be safe from the operators of HN with that margin of security.

that's why we are talking 2048 vs. 4096.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#46

So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…

I've seen keysigning parties at a few technical conferences. Find one, preferably one that caters to programmers and/or sysadmins rather than managers and/or marketers, and which has extra space for not-scheduled-in-advance meetings. Then schedule a keysigning party and see who shows up. Remember to bring ID.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#47
post #22
post #13

Is he really afraid of 2^n/2 brute power of quantum computers or this is just overkilling of overkill?

There's no need for a quantum computer. Everyone should be using at least 4096bit RSA. 1024bit RSA keys can be factored with conventional non-specialized hardware (read: CPU's, not even GPU's) with GNFS. IMHO, 2048bit RSA keys can be factored by custom hardware that the NSA has developed. I posted my reasoning for this hypothesis in other hackernews threads. A very quick/terse run down of the main key points - 1) NSA…

The (public) factorization record with GNFS is 768 bits, in an effort that took about 2000 CPU years. 1024 bits is about 1000x harder, so probably within reach with government resources. 2048 bits is 10^12 times harder, which surely is out of reach for the time being time unless the NSA has a better algorithm.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#48
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)

I've had a PGP key since 2001. I upgraded to 2048 bit some years ago due to the increasing weakness of 1024 bit keys.

I think I've received maybe one message encrypted to me. Everything else I use PGP for is to send signed emails to mailing lists.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#49
post #41

Earlier quoted context omitted.

Your secrets are not safe against multinational corporations with 1024 bit keys. The likely cost of the capability to break a 1024 bit key is probably (for a private entity) in the low tens of millions. You wouldn't even be safe from the operators of HN with that margin of security.

that's why we are talking 2048 vs. 4096.

I think he's referring to the trailing sentence that you quoted which mentioned 1024-bit keys being safe against multinationals.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#50
post #31

Earlier quoted context omitted.

With linux, is there any way to compromise the USB stick used for the air gap? AFAIK the Stuxnet virus was originally spread via USB stick, however I reckon that it involved Windows machines that are known to execute files on USB sticks.

Years ago, a classmate of mine built a rig out of a receipt printer and one of those old handheld scanners to provide an "air gap", though it never really worked (sort of an art project at the time). Might be time to revive the idea...

Meh, you can do fine by using two one-way ethernet cables (you might have to cut the receive wires yourself), and some tweaked network stack.
Post reply on HN