Live data from Hacker News

On Encryption

privateinternetaccess.com

11–20 of 21 posts

Re: On Encryption

#11

> We will also be adding support for something no other provider is currently offering called Elliptic Curve Cryptographic security, with both 256bit and 521bit curves. Any particular reason to not offer 384bit as well? ps. likely a typo: 521 should be 512? edit: Nope. 521 is correct[1]. thanks @mtoledo [1]: https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#ci...

"The sequence may seem suggestive of a typographic error. Nevertheless, the last value is 521 and not 512 bits."

https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#ci...

Re: On Encryption

#12

> We will also be adding support for something no other provider is currently offering called Elliptic Curve Cryptographic security, with both 256bit and 521bit curves. Any particular reason to not offer 384bit as well? ps. likely a typo: 521 should be 512? edit: Nope. 521 is correct[1]. thanks @mtoledo [1]: https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#ci...

[deleted]

Re: On Encryption

#14
post #11

> We will also be adding support for something no other provider is currently offering called Elliptic Curve Cryptographic security, with both 256bit and 521bit curves. Any particular reason to not offer 384bit as well? ps. likely a typo: 521 should be 512? edit: Nope. 521 is correct[1]. thanks @mtoledo [1]: https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#ci...

"The sequence may seem suggestive of a typographic error. Nevertheless, the last value is 521 and not 512 bits." https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#ci...

oh interesting. ha. thanks for that!

Re: On Encryption

#15
I'd be interested to hear what VPN providers are doing in terms of physical security and the risk of key theft/infiltration.

Re: On Encryption

#16
post #3
post #2

[deleted]

For OpenVPN - which is the only protocol we advise for real security (PPTP and IPSec/L2TP are fine for just hiding your IP) - we don't use pre-shared keys. OpenVPN uses TLS for exchanging strong symmetric keys. Your password is only used for authentication and its entropy isn't related to your session's security.

PPTP is well documented as being broken at this point but I have not seen any equivalent for IPSec/L2TP. Please quote sources as I would be interested in researching further as well as the rationale for OpenVPN being the only "real" security.

Re: On Encryption

#17
post #3

Earlier quoted context omitted.

For OpenVPN - which is the only protocol we advise for real security (PPTP and IPSec/L2TP are fine for just hiding your IP) - we don't use pre-shared keys. OpenVPN uses TLS for exchanging strong symmetric keys. Your password is only used for authentication and its entropy isn't related to your session's security.

PPTP is well documented as being broken at this point but I have not seen any equivalent for IPSec/L2TP. Please quote sources as I would be interested in researching further as well as the rationale for OpenVPN being the only "real" security.

The current basis for this is John Gilmore's speculation[1] on a cryptography mailing list.

[1] http://www.mail-archive.com/cryptography@metzdowd.com/msg123...

Re: On Encryption

#18
If I were the NSA, I would run these VPN services.

They provide a perfect honeypot to gather the "illegal" web users or those with something to hide, in one place.

Re: On Encryption

#19

Earlier quoted context omitted.

PPTP is well documented as being broken at this point but I have not seen any equivalent for IPSec/L2TP. Please quote sources as I would be interested in researching further as well as the rationale for OpenVPN being the only "real" security.

The current basis for this is John Gilmore's speculation[1] on a cryptography mailing list. [1] http://www.mail-archive.com/cryptography@metzdowd.com/msg123...

Exactly, speculation.
Post reply on HN