All the latest UK technology news, reviews and analysis

No crisis over 1,024-bit encryption

by James Middleton

02 May 2002

Be the first to comment

  • Tweet this

Security firm RSA has hit back at cryptography experts' claims that 1,024-bit encryption is no longer secure.

A discussion on security mailing list Bugtraq at the end of March concluded that 1,024-bit encryption was "compromised", but RSA is now claiming that the situation has been misinterpreted.

At the Financial Cryptography conference in March the main topic of discussion was a paper published last October by cryptographer Dan Bernstein which proposed an architecture capable of factoring 1,024-bit RSA keys.

Based on this proposal, the experts suggested that such a device could be built by an agency with good resources - the National Security Agency, for example - for less than $1bn.

But Burt Kaliski, director of RSA Laboratories, insisted that such estimates were done quickly and proved to be inaccurate by a significant factor.

"The Bernstein paper was also misinterpreted, because it is highly theoretical and not practical," he said. "Bernstein himself has been very conservative in his claims."

Kaliski explained that the architectural proposals didn't offer much more than what was already available, and that encryption is still in the same position as it was before the debate kicked off.

He said that, based on estimations, "a well funded agency could build a machine capable of breaking strong encryption by the end of the decade".

But at the cost, it is likely that decryption machines will only be built if they offer the best return on investment, added Kaliski. "If it works out better than bribery, for example, then a machine will be built," he said.

1,024-bit is still adequate protection for the average user but, if they do want to use a larger key, vendors are gradually moving along to stronger encryption.

"Lots of people support 1,024-bit," stated Kaliski. "It'll be good for a few years yet. There's no crisis."

He said that, with encryption export conditions from the US being relaxed, he saw the industry legitimising the practice of stronger encryption.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Principle Network Design Engineer

Key skills for this role include a comprehensive understanding...

Senior Information Security Consultant

Fantastic opportunity for an Information Security Professional...

VB.NET Developer Cheshire

VB.NET Developer / SQL / VB6 / ASP / XML / Cheshire...

Security Architect

Fantastic opportunity for a high calibre Security Architect...

To send to more than one email address, simply separate each address with a comma.