There is nothing suspicious with that. He has worked previously in mostly corporate and private context, so 2048 is just fine. Now he works with people and data NSA wants their hands on and he wants the data to be secure also in the future. It's just reasonable to move to 4096 key sizes. http://www.pgp.net/pgpnet/pgp-faq/pgp-faq-keys.html#key-size >Dr Lenstra and Dr Verheul offer their recommendations for keylengths.…
Bruce Schneier has changed his PGP key to 4096 bits
41–50 of 144 posts
Re: Bruce Schneier has changed his PGP key to 4096 bits
#42Anyone know of a good tutorial for revoking and recreating your key as painlessly as possibly?
I'd imagine the process works something like this: * Generate the new key * Sign the new key with the old key * Generate the revocation cert for the old key * Push the revocation publicly with a reason of "Superseded by (fingerprint of new key)" or similar * Push the new key * Try to get your new key signed by everyone that signed your old key for authenticity's sake I'm not too sure how the community of GPG users ou…
Re: Bruce Schneier has changed his PGP key to 4096 bits
#43[1] http://www.theguardian.com/world/2013/sep/05/nsa-how-to-rema...
Re: Bruce Schneier has changed his PGP key to 4096 bits
#44Earlier quoted context omitted.
Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.
Does the reason for that ever come up in a conversation? I thought that everyone working in security used PGP a lot.
Outside of those few work examples, I don't think I've ever sent or received a PGP encrypted message. In fact, the only signed messages I think I've ever seen were mailing list messages from people who signed all their messages.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#45There is nothing suspicious with that. He has worked previously in mostly corporate and private context, so 2048 is just fine. Now he works with people and data NSA wants their hands on and he wants the data to be secure also in the future. It's just reasonable to move to 4096 key sizes. http://www.pgp.net/pgpnet/pgp-faq/pgp-faq-keys.html#key-size >Dr Lenstra and Dr Verheul offer their recommendations for keylengths.…
Your secrets are not safe against multinational corporations with 1024 bit keys. The likely cost of the capability to break a 1024 bit key is probably (for a private entity) in the low tens of millions. You wouldn't even be safe from the operators of HN with that margin of security.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#46So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…
Re: Bruce Schneier has changed his PGP key to 4096 bits
#47Is he really afraid of 2^n/2 brute power of quantum computers or this is just overkilling of overkill?
There's no need for a quantum computer. Everyone should be using at least 4096bit RSA. 1024bit RSA keys can be factored with conventional non-specialized hardware (read: CPU's, not even GPU's) with GNFS. IMHO, 2048bit RSA keys can be factored by custom hardware that the NSA has developed. I posted my reasoning for this hypothesis in other hackernews threads. A very quick/terse run down of the main key points - 1) NSA…
Re: Bruce Schneier has changed his PGP key to 4096 bits
#48Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.
Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)
I think I've received maybe one message encrypted to me. Everything else I use PGP for is to send signed emails to mailing lists.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#49Earlier quoted context omitted.
Your secrets are not safe against multinational corporations with 1024 bit keys. The likely cost of the capability to break a 1024 bit key is probably (for a private entity) in the low tens of millions. You wouldn't even be safe from the operators of HN with that margin of security.
that's why we are talking 2048 vs. 4096.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#50Earlier quoted context omitted.
With linux, is there any way to compromise the USB stick used for the air gap? AFAIK the Stuxnet virus was originally spread via USB stick, however I reckon that it involved Windows machines that are known to execute files on USB sticks.
Years ago, a classmate of mine built a rig out of a receipt printer and one of those old handheld scanners to provide an "air gap", though it never really worked (sort of an art project at the time). Might be time to revive the idea...