Bruce Schneier has changed his PGP key to 4096 bits
71–80 of 144 posts
Re: Bruce Schneier has changed his PGP key to 4096 bits
#72Earlier quoted context omitted.
Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.
I met Bruce this last weekend at a conference, and every single business card I collected had the individual's PGP key on it.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#73I know the fundamental idea behind PGP and related technologies. My question is, if bumping his key from 2048 to 4096 bits will keep him safe until around the year 2020 (as stated by a previous reader, and from keylength.com), why not just use a 8192 bit key, or 16384 bit key and be safe for virtually your lifetime? Does the computing cost to encrypt/decrypt make this impractical?
4096 is the largest key size gpg offers today. It was the largest key size gpg offered in 2009, which is why that's the key size I'm using now. In 1996 the largest key size pgp supported was probably 768 , which is why my first pgp key is that size. I know for sure that in 1999, the largest key I could manage to make was 2048. Looking back at those older keys, I would prefer if I could have chosen larger key sizes fo…
Re: Bruce Schneier has changed his PGP key to 4096 bits
#74Earlier quoted context omitted.
Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)
Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#75It's curious that he didn't sign his new key with his old key. Does anyone have a good explanation for why he wouldn't want to do that?
Re: Bruce Schneier has changed his PGP key to 4096 bits
#76Earlier quoted context omitted.
Does the reason for that ever come up in a conversation? I thought that everyone working in security used PGP a lot.
In fact, it is unusual to see people even sign emails in the (academic) cryptography community, let alone encrypt messages (at least in my experience). It is surprisingly rare to see academic crypto researchers actually use the systems they design, even for basic things like signing and encryption.
Re: Bruce Schneier has changed his PGP key to 4096 bits
#77Earlier quoted context omitted.
Meh, you can do fine by using two one-way ethernet cables (you might have to cut the receive wires yourself), and some tweaked network stack.
The ol' DIY Data-Diode[1] I've heard of using serial lines/modems with the appropriate tx->rx cut, but I don't know if it would actually work for ethernet (maybe 10BaseT only?) [1] https://en.wikipedia.org/wiki/Unidirectional_network
Half-duplex, 100mbit, ignore link. I suppose it can be done?....
Re: Bruce Schneier has changed his PGP key to 4096 bits
#78I wish there were a decent hardware PGP key token available now -- something which could support 4096 RSA and communicated via (ideally) BT but also acceptable USB to a host. The GPF stick is out of stock.