1996-03-04 - Re: Problems with certificates.

Header Data

From: Derek Atkins <warlord@MIT.EDU>
To: Bill Stewart <stewarts@ix.netcom.com>
Message Hash: cb30e9b41bbb342e00317a4d308e80e38f27f8aac569853d80eef25825dee3e7
Message ID: <199603041635.LAA08126@toxicwaste.media.mit.edu>
Reply To: <199603022121.NAA10418@ix8.ix.netcom.com>
UTC Datetime: 1996-03-04 19:06:21 UTC
Raw Date: Tue, 5 Mar 1996 03:06:21 +0800

Raw message

From: Derek Atkins <warlord@MIT.EDU>
Date: Tue, 5 Mar 1996 03:06:21 +0800
To: Bill Stewart <stewarts@ix.netcom.com>
Subject: Re: Problems with certificates.
In-Reply-To: <199603022121.NAA10418@ix8.ix.netcom.com>
Message-ID: <199603041635.LAA08126@toxicwaste.media.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain


Just a quick clarification...

> PGP KeyIDs are 8 hexes long (formerly 6), and there have been some natural
> collisions and it's easy to manufacture them.  On the other hand,
> the MD5 hash used for key fingerprints is 128 bits long, and
> cryptographically strong.

The printable part of the keyid is 8 hexes long.  The internal keyID
that PGP uses for choosing keys is actually 8 bytes, not 8 hexes.
Besides, its not the length that matters, but the security.

-derek





Thread