Great Circle Associates Firewalls
(December 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: How strong is RC4 with 40bit key?
From: Adam Shostack <adam @ homeport . org>
Date: Wed, 18 Dec 1996 22:19:02 -0500 (EST)
To: aaron @ hkpo . hongkong . ncr . com (Tong, Aaron)
Cc: firewalls @ GreatCircle . COM, ssl-users @ mincom . com
In-reply-to: <32B84300 @ ncrhk . HongKong . ncr . com> from "Tong, Aaron" at "Dec 18, 96 12:02:00 pm"

Tong, Aaron wrote:

| Hi,
| 
| How long does it take to break a message encrypted using RC4 with 40bit   
| secret key?  What computer resource is required?

Depends how much you spend.  Several students have put together the
resources to do it in a little over a day; presumably any cracker with
a sniffer could get the same at a university.  The Schneier, Blaze,
Rivest, et al paper estimated the cost per key, when amortized over 3
years, to be 8 cents.  ftp://ftp.research.att.com/dist/mab/keylength.ps

| Is the US Government considering to allow longer bit length to export?   
|  If so, what bit length will be allowed (56bit or 128bit)?  How strong is   
| 56bit and 128bit?

	No, but they want industry to think that they are.  56 bit des
is on the verge of being breakable by a large network attempt.  I
strongly counsel my clients against deploying anything at all with
plain des.

	OTOH, Judge Patel just ruled the ITARs to be unjustifiable
prior restraint of free speech in Northern California, in regards to
academic publication.  www.eff.org should have something soon.

| Does those browser that support longer bit length (>40bit e.g. 128bit)   
| can be used outside US?

	Sure, as long as you didn't export it illegally from the US.

| Any advise or pointer to related site is appreciated

	www.brokat.de:  128 bit SSL in Java
	www.r3.ch: 	Something similar that I haven't looked at.

Adam

-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume




References:
Indexed By Date Previous: Re: smap delays
From: Rick Murphy <rick @ tis . com>
Next: Re: Is there any freeware implementation of NAT (network address translation)?
From: Paul Ferguson <pferguso @ cisco . com>
Indexed By Thread Previous: How strong is RC4 with 40bit key?
From: "Tong, Aaron" <aaron @ hkpo . hongkong . ncr . com>
Next: ipfwadm firewall for linux
From: <winspace @ void . hell . net> (Norman Widders)

Google
 
Search Internet Search www.greatcircle.com