Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Break a dozen secret keys, get a million more for free (2015) (ecrypt-eu.blogspot.com)
72 points by ColinWright on Aug 15, 2018 | hide | past | favorite | 9 comments


This is from 2015.


Thanks for noticing.

For everyone else, has the situation got better?? Or has it got worse? Would someone more experienced and/or qualified care to comment?

I know a bit, but not enough.


Two researchers at DEF CON this past weekend showed that the situation is better but people are still using old tech for their crypto. So, better mathematically, but not practically.

Slides are here off the DEF CON media server: https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20pre...


It has nothing to do with age. if it cant be cracked it cant be cracked. choose 12 words at random from a small dictionary, write em' down somewhere safe and secret, and forget about it. That will work forever. Overkill security is better than trying to find the computational limit and then going one bit above that. keys are cracked when the process of generating them is flawed or the key is not big enough. That's why bitcoin private keys are so long and why 12 words are used even though 8 would probably still be enough.


Cool - thanks.


Thanks; added.


The title is a tiny poem.


> even though a 280 attack will break somebody's AES-128 key out of a batch of 248 keys.

Yeah, "somebody's", but what does the average somebody have that's worth cracking their encryption over? It seems to me that most cryptanalysis threat models would be very specifically targeted: what is the President saying on his secure line? Where are the submarines being dispatched? What are the corporate earnings or fed rate decisions going to be?

Trawling thousands of encrypted connections and cracking one or two is a pretty cool feat,but probably not valuable enough to recoup the costs or yield anything of extraordinary value.


A nation-state actor that could read a random 0.0001% of another country's internal communications would have a decisive advantage. The number of big secrets flying around is enough that you'll get a few of them.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: