dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
1680
avze
join:2013-08-19

avze

Member

Gmail to offer RSA 2048-bit SSL

Will this improve the security even after logging on to Gmail?
»nakedsecurity.sophos.com ··· y-sizes/

dandelion
MVM
join:2003-04-29
Germantown, TN

2 recommendations

dandelion

MVM

Security from what? Maybe from hackers however considering the Gmail TOS I don't think much security will be coming from that area.

jack b
Gone Fishing
MVM
join:2000-09-08
Cape Cod

1 recommendation

jack b to avze

MVM

to avze
The government already has access to all your data, so, in the words of a former secretary of state:
" what difference does it make?"

NOYB
St. John 3.16
Premium Member
join:2005-12-15
Forest Grove, OR

1 recommendation

NOYB

Premium Member


The difference it makes is 2048 - 1024 = 1024.
HELLFIRE
MVM
join:2009-11-25

HELLFIRE to avze

MVM

to avze
quote:
But RSA encryption is a public/private key cipher, meaning you have one key to lock and another key to unlock.
...and guess who has access to those keys besides the user?

Dun Dun Dun...

Regards

NOYB
St. John 3.16
Premium Member
join:2005-12-15
Forest Grove, OR

3 edits

NOYB

Premium Member


Well, everyone has access to the public key.

The certificate owner (and anyone they give it to, either willingly or under duress) has access to the private key. In short, probably the same people who have access to the current (soon to be previous) 1024 bit private key.

Right now I'm thinking that you don't know the answer nor how the keys work, so asking for guesses to your insinuating rhetorical question rather than providing your own hypothesis.
evoxllx
join:2007-06-07
Winter Park, FL

evoxllx to avze

Member

to avze
Even if someone got ahold of Google's private key, the most they could do with it is MITM others. Google supports forward secrecy for every major browser, so the private key can't be used to retroactively decrypt any past traffic.

They currently use ECDHE with the P-256 curve, so their RSA equivalent is around 3072-bits of security.
HELLFIRE
MVM
join:2009-11-25

1 recommendation

HELLFIRE to NOYB

MVM

to NOYB
@NOYB See Profile
I do have some knowledge how public / private keys work, tho I usually have to reach for a bottle of aspirin
everytime I have to read an article on it.

The fact of the matter is... and I think it's been mentioned several times in this forum... I trust any commercial
and any governmental agency about as far as I can kick em to actually keep that private [insert here] as what it should
be kept as... PRIVATE.

Next time I'll notate that with "[/cynicism]" to clarify better...

Regards
19579823 (banned)
An Awesome Dude
join:2003-08-04

19579823 (banned) to dandelion

Member

to dandelion

 

Not at all.... This has to be a joke!!