Live data from Hacker News

Bruce Schneier has changed his PGP key to 4096 bits

news.ycombinator.com

71–80 of 144 posts

Re: Bruce Schneier has changed his PGP key to 4096 bits

#72
post #18

Earlier quoted context omitted.

Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.

I met Bruce this last weekend at a conference, and every single business card I collected had the individual's PGP key on it.

Well, I'm a professional security researcher, and I end up using ZIP+AES more often than I do PGP.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#73
post #67
post #65

I know the fundamental idea behind PGP and related technologies. My question is, if bumping his key from 2048 to 4096 bits will keep him safe until around the year 2020 (as stated by a previous reader, and from keylength.com), why not just use a 8192 bit key, or 16384 bit key and be safe for virtually your lifetime? Does the computing cost to encrypt/decrypt make this impractical?

4096 is the largest key size gpg offers today. It was the largest key size gpg offered in 2009, which is why that's the key size I'm using now. In 1996 the largest key size pgp supported was probably 768 , which is why my first pgp key is that size. I know for sure that in 1999, the largest key I could manage to make was 2048. Looking back at those older keys, I would prefer if I could have chosen larger key sizes fo…

Seems that if you're really paranoid, gpg --gen-key --batch with an approptiate batch file can make 8192 or larger keys. Currently trying to generate a 81920 bit key, for general giggles and to increase my NSA rating.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#74
post #18

Earlier quoted context omitted.

Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)

Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.

Oh, look. It's the government contractor sowing FUD.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#75

It's curious that he didn't sign his new key with his old key. Does anyone have a good explanation for why he wouldn't want to do that?

If someone can crack his key old as of 2020, then they can start distributing a fake Bruce Scheneier 4096 bit key at that time. He might think it's better for him as something of a security celebrity to just publish a new key.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#76

Earlier quoted context omitted.

Does the reason for that ever come up in a conversation? I thought that everyone working in security used PGP a lot.

In fact, it is unusual to see people even sign emails in the (academic) cryptography community, let alone encrypt messages (at least in my experience). It is surprisingly rare to see academic crypto researchers actually use the systems they design, even for basic things like signing and encryption.

Strategically, you are probably better off not signing a message unless you want the message to be verifiable.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#77
post #70
post #50

Earlier quoted context omitted.

Meh, you can do fine by using two one-way ethernet cables (you might have to cut the receive wires yourself), and some tweaked network stack.

The ol' DIY Data-Diode[1] I've heard of using serial lines/modems with the appropriate tx->rx cut, but I don't know if it would actually work for ethernet (maybe 10BaseT only?) [1] https://en.wikipedia.org/wiki/Unidirectional_network

I'm just speculating here... but I think it could be done PC-to-PC up to 100mbit. IIRC, there's a "link" signal that normally exists -- you'll have to configure both cards to ignore the link signal. (Which, I suppose, would mean that this wouldn't work going to a switch or hub with factory-default firmware.)

Half-duplex, 100mbit, ignore link. I suppose it can be done?....

Re: Bruce Schneier has changed his PGP key to 4096 bits

#78
post #71

I wish there were a decent hardware PGP key token available now -- something which could support 4096 RSA and communicated via (ideally) BT but also acceptable USB to a host. The GPF stick is out of stock.

I don't even know if common linux distributions even support the right combination of drivers and gnupg to even support 4096-bit RSA keys. I tried this a couple of times over the last two years or so, and there was always some bug, or it was fixed in a later version not in the repos yet.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#79
Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa Nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa nsa
Post reply on HN