1995-09-29 - Re: VISA and Microsoft STT Specs available

Header Data

From: Bill Stewart <stewarts@ix.netcom.com>
To: hallam@w3.org
Message Hash: 5bba727d1f341c028ebbc96b46f3ced26a54ab26c7e4aea22604c0e40406e82d
Message ID: <199509291902.MAA23808@ix8.ix.netcom.com>
Reply To: N/A
UTC Datetime: 1995-09-29 19:02:48 UTC
Raw Date: Fri, 29 Sep 95 12:02:48 PDT

Raw message

From: Bill Stewart <stewarts@ix.netcom.com>
Date: Fri, 29 Sep 95 12:02:48 PDT
To: hallam@w3.org
Subject: Re: VISA and Microsoft STT Specs available
Message-ID: <199509291902.MAA23808@ix8.ix.netcom.com>
MIME-Version: 1.0
Content-Type: text/plain


At 11:10 AM 9/29/95 -0400, Phill wrote:
>Yes, VISA put the ASCII on their site... 
>We only host the ps version.

Thanks!  I looked at the Visa site, and it has a usable form
of the documents still under construction; I waded through
the 73-separate-page HTML version for a while....
There's some good intro material on how you use the stuff and
who's responsible for what.

Microsoft has the technical specs as one big slightly-HTMLized
text file under http://www.windows.microsoft.com/windows/ie/stt.htm ;
it's _much_ more readable, and has a pointer to the Visa version.
(It's one big <PRE> with a few <B> and hrefs, in black-on-white.)

Some cryptographic high points, from a brief scan.
- 1024-bit RSA signatures, using PKCS#1 format.
- SHA 160-bit hashes
- Symmetric bulk crypto includes two options (I haven't yet seen
  how you choose between them; I assume it's export/domestic?)
  == RC4/64 with 24 bits of salt leaving 40 bits of real key
  == DES-CBC - yes, that's single-DES.  IV=0.
#---
# Bill Stewart, Freelance Information Architect, stewarts@ix.netcom.com
# Phone +1-510-247-0664 Pager/Voicemail 1-408-787-1281
#---






Thread