Re: gnupg rsa question // why use e of 41 ?
- From: tomstdenis@xxxxxxxxx
- Date: 30 Apr 2006 04:38:47 -0700
daniel bleichenbacher wrote:
Sorry, I do not agree with this opinion. There are many attacks that
work
well with very small exponents such as e=3, but don't work or are much
harder with e=65537 or larger. Of course these attacks can be avoided
if implemented correctly. But implementations do have mistakes. And
from
analysing many cryptographic libraries I know that these libraries have
much
more mistakes that one commonly expects. Thus, to me it seems to be a
good
idea to make RSA implementations more robust by avoiding the smallest
exponents. In fact, I'd even avoid e=41 and just generally use at least
e=65537.
Without padding even e=65537 is not secure.
What's your point?
Tom
.
- References:
- gnupg rsa question // why use e of 41 ?
- From: vedaal
- Re: gnupg rsa question // why use e of 41 ?
- From: David Wagner
- Re: gnupg rsa question // why use e of 41 ?
- From: daniel bleichenbacher
- gnupg rsa question // why use e of 41 ?
- Prev by Date: Re: gnupg rsa question // why use e of 41 ?
- Next by Date: Re: Elliptic Curve RSA
- Previous by thread: Re: gnupg rsa question // why use e of 41 ?
- Next by thread: Re: gnupg rsa question // why use e of 41 ?
- Index(es):
Relevant Pages
|
|