NODE b32552c8Re: Un-Documented Feature
schirado@lab.cc.wmich.edu (No Taxes through No Government)Fri, 1 Jul 94 19:54:16 PDT
trollins@debbie.telos.com (Tom Rollins) writes:
>PGP 2.6ui has an undocumented feature.
>
>When generating a Public/Secret key pair PGP documentaion shows
>the command "pgp -kg" as the way to generate the keys.
>I had posted about how pgp uses a small public key exponent
>of 17 which is 5 bits.
>It turns out that this is only the default setting.
>An Un-Documented feature in PGP 2.6ui (I don't know about other
>versions as I don't have source code for them) lets you specify
>the number of bits in your public key exponent.
>The command "pgp -kg keybits ebits" will let you specify this
>public key exponent size. For example "pgp -kg 1024 256" will
>generate a key with modulus of aprox 1024 bits and a public
>key exponent of 256 bits rather than the 5 bit default.
>
>Too Bad pgp doesn't let you look at the public key exponent.
>I had to write some code to see them.
Questions:
1) In non-mathematical terms, if possible, what difference does this
make in terms of security?
2) Does anyone know why is this undocumented?
3) What changes did you make? Sounds like it would be a well-received
set of patches to be made public.
(I'm well aware of the current arguments regarding algorithmic strength
being no substitute for secure key management; I'm merely curious.)
NODE 25d6372eRe: Un-Documented Feature
rarachel@prism.poly.edu (Arsen Ray Arachelian)Sun, 3 Jul 94 09:41:27 PDT
> Questions:
>
> 1) In non-mathematical terms, if possible, what difference does this
> make in terms of security?
None mathematically. A friend of mine (denaro09@darwin.poly.edu) has an
interesting thought on this. If the NSA does have any method of screwing
RSA in any way, it's probably optimized for the common key lengths for PGP.
ie: 512, 1024, etc. So he uses a 1023 bit key. That one bit less may be
unsecure for him, but the idea is still sound. Maybe a 1025 bit key would
give them less of an advantage. Even so this is all speculation. We don't
know what the NSA knows...