• rockSlayer@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      9 days ago

      There are tradeoffs with encryption. RSA is so secure, that the US government has tried to insert a mathematic backdoor into the key selection because that’s the easiest method to attack the encryption. RSA uses thousands of bits for their encryption, making it inefficient for most attacks. The attack detailed in this article is on one of the weaker RSA algorithms, with only 1024 bits. The high end RSA uses 4096 bits or more, I believe the algorithm has increased the bit length to officially support 8192.

      On the other side of RSA is another secure algorithm called AES. It can go up to 512 bits, but it hashes the key to meet the key length instead of relying on generating huge prime numbers. It makes it more resilient to certain types of attacks, but the bit limitation makes it easier to brute force or use rainbow tables.

      • sik0fewl@piefed.ca
        link
        fedilink
        English
        arrow-up
        4
        ·
        9 days ago

        AES is asymmetric encryption and cannot be used for the same things as RSA. EdDSA would be more comparable to RSA.

        • rockSlayer@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          9 days ago

          I know that AES is symmetrical. I was using it to illustrate that symmetrical and asymmetrical encryption have tradeoffs that cannot be worked around.

      • rockSlayer@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        9 days ago

        Elliptical curve for RSA was immediately phased out as soon as it was proven that the NIST was influenced by the NSA to implement it

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 days ago

          Elliptical curve for RSA was immediately phased out

          what? when did RSA want to use elliptical curves? its a completely different technology. and ECC itself was not phased out of anywhere. certain curves were, not ECC as a whole.

    • solrize@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 days ago

      Yes we’re supposed to use ECC instead of RSA now. The major crypto libraries support it so you just configure your program to use it.