NODE 40dfb477No Subject
montgo@nws.globe.comWed, 6 Apr 94 11:09:05 PDT
Undersigned is non-computing, non-cyphering reporter at Boston Globe working
on a little story on the solution of RSA129 (I believe the primes will be
published April 23, or so). Looking for people who loaned computer cycles for
the project, hoping to hear why they did, what fun if any it was, and what's it
like when they tell you to shut down...sense of loss? Whatever
M. R. Montgomery
The Boston Globe
montgo@nws.globe.com
NODE 95b9232aReporting the RSA129 story
Phil Karn <karn@qualcomm.com>Wed, 6 Apr 94 13:28:56 PDT
When you write your story, *please* help correct what already seems to
be a widespread misconception by emphasizing that solving RSA129 does
*not* mean that the RSA public key cryptosystem has been "broken". It
only means that one *particular* and relatively short RSA key, chosen
long ago for test purposes, has been broken by brute computational
force.
An equally intensive effort would have to be mounted from scratch to
break any other RSA key of the same length; this is why it's good
practice to change "real" keys from time to time.
And, of course, the longer the RSA key, the more work it is to
crack. Barring major breakthroughs in the underlying algorithms for
attacking RSA, which have not occurred, a sufficiently long key (e.g.,
1024 bits) will be secure for quite some time even with present trends
in brute-force computer power.
The real importance of the RSA129 effort is that it provides a new
experimental "data point" on the security of a particular key length.
This is a good example of the seemingly paradoxical principle that
publishing the design of a cryptographic system and inviting attacks
by all comers can actually help to strengthen it in actual use.
This is in sharp contrast to, say, Clipper/Skipjack, where the NSA
classifies the algorithm and says "trust us, it's secure". The NSA may
believe that it's secure. It may even *be* secure (except, of course
for the gaping front door of key escrow). But without a sustained,
long-term public review there's no way to know if they missed
something.
Phil