Live data from Hacker News

4096 RSA key in the strongset factored?

trilema.com

111–114 of 114 posts

Re: 4096 RSA key in the strongset factored?

#111

I was extremely surprised to see the source of this at the top of HN, as I am familiar with this web site and its operator from an an extremely toxic online forum, which I won't mention or elaborate on. I am careful not to share negative remarks, but I will firmly state that I believe that this: >Consequently, the originally intended, civilised process of emailing the victim, keeping things quiet for a while to give…

The forum you are referring to is 8chan ( http://8ch.net/ ), yes? Are you sure you are not trolling ?

[deleted]

Re: 4096 RSA key in the strongset factored?

#112
post #86
post #85

Earlier quoted context omitted.

The SKS keyserver pool (which keys.gnupg.net alias's to) doesn't do any cryptographic verification, even verifying self-signatures, before upload. The software just checks to see if the format is valid. It's up to the clients to do their own verification, which in this case GPG does perfectly (it doesn't import the invalid subkey since the self-signature is invalid).

If it's true it's a nice DoS vector

fwiw this is currently being discussed on the sks mailing list, but the overwhelming opinon seems to be that the current behaviour should stay. https://lists.nongnu.org/archive/html/sks-devel/2015-05/msg0...

Re: 4096 RSA key in the strongset factored?

#113
post #48

Earlier quoted context omitted.

It might not be a good idea for other reasons to have them on your screen, where other locally-installed software could view them, they would be (more strongly) broadcast in the RF spectrum, someone might see them over your shoulder, etc.

Valid points about other software, but I don't think 1000+-digit random-looking numbers would be easily memorised by someone looking over your shoulder casually. http://www.recordholders.org/en/list/memory.html#numbers-1mi...

In the era of 120fps 12MP smartphone cameras, capturing a 1000+ digit number on a screen doesn't seem so implausible, and "someone looking over your shoulder" shouldn't be taken so literally.

Re: 4096 RSA key in the strongset factored?

#114
post #70

I'm almost certain this news is wrong. I know that because I made the same mistake a while ago. Luckily for me I didn't publish it, but I already had written mails to a number of people (including hpa) warning them of a compromised key (which was a false alarm). Here's what's going on: There are a number of keys on the keyservers that are faulty copies of real keys - they share most of the values, but have some error…

What do you make of this? https://news.ycombinator.com/item?id=9575598
Post reply on HN