Live data from Hacker News

Cracking a 512-bit DKIM key for less than $8 in the cloud

dmarcchecker.app

21–30 of 433 posts

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#22
post #6

Could someone help me understand why we're not dramatically ramping up key sizes across the board on all encryption? Not as a solution, but as a buy-some-time measure. Compute is rapidly increasing, there is continuous chatter about quantum and yet everyone seems to be just staring at their belly buttons. Obviously bigger keys are more expensive in compute, but we've got more too...why only use it on the cracking sid…

512 DKIM was exceedingly rare even 8 years ago when I worked in email.

You're essentially asking "why aren't we doing what we're doing"

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#23
post #6

Could someone help me understand why we're not dramatically ramping up key sizes across the board on all encryption? Not as a solution, but as a buy-some-time measure. Compute is rapidly increasing, there is continuous chatter about quantum and yet everyone seems to be just staring at their belly buttons. Obviously bigger keys are more expensive in compute, but we've got more too...why only use it on the cracking sid…

> Could someone help me understand why we're not dramatically ramping up key sizes across the board on all encryption? Not as a solution, but as a buy-some-time measure.

We've been doing it for decades now… (DES used 56bits back then, AES started at 128).

Also, keep in mind that increasing the key length by 1 means that you need twice as much compute to crack it through brute force (that is, unless cryptanalysis shows an attack that reduces the difficulty of the scheme, like for instance with the number field sieve on RSA) so you don't need to increase key size too often: following Moore's law, you need to increase it by on bit every two years, or 5 bits every decades. Additionally key size generally account for many years of compute progress and theoretical advance, so that you really don't need to worry about that over a short period (for the record higest RSA factorization to date is 829 bits, yet people started recommending migration away from 1024 bit RSA a decade ago or so, and the industry is in the process in deprecating it entirely even though it's probably going to take years before an attack on it becomes realistic.

Re: Cracking a 512-bit DKIM key for less than $8 in the cloud

#25
post #20
post #14

Earlier quoted context omitted.

So 1,700 out of 1,000,000, i.e. around 0.2%. "Not common" is one way of putting it, I guess.

Those 1,700 are easy to find though, just need to dig a bunch of domain names and you'll find plenty vulnerable ones that you can spoof. Yahoo Mail has a market share on the order of 3%. So a black hat could then target a decent chunk of users with @yahoo addresses specifically. Has anyone heard of this being exploited in the wild? Would be interesting to find out whether there are some reputable domains among the 1.…

Your claim that yahoo uses a 512bit key are counterfactual.

Please adhere to honesty and good faith arguments.

Post reply on HN