7 ms·
A good deal of encrypted material these days depends on the security of the private key, though -- e.g., HTTPS loses a good deal of security if the server's pri
by assafs 13y ago
A good deal of encrypted material these days depends on the security of the private key, though -- e.g., HTTPS loses a good deal of security if the server's private key is known.
Given the reach of PRISM and related projects, and given that a lot of the internet was using 1024-bit RSA keys for HTTPS, it's a good question wondering how much of those private keys are still ... private.
- Torgo 13y agoI have always wondered about this. What kind of security do you really get if, for example, your SSL key is distributed to a couple thousand CloudFlare servers all over the world?
- ra 13y agoZilch. Cryptographic security depends on good key management practices.
- rurounijones 13y agoWhat you have just mentioned is talked about here: https://news.ycombinator.com/item?id=5933784 https://news.ycombinator.com/item?id=5933784