From: Derek Atkins <warlord@MIT.EDU>
To: Bill Stewart <stewarts@ix.netcom.com>
Message Hash: cb30e9b41bbb342e00317a4d308e80e38f27f8aac569853d80eef25825dee3e7
Message ID: <199603041635.LAA08126@toxicwaste.media.mit.edu>
Reply To: <199603022121.NAA10418@ix8.ix.netcom.com>
UTC Datetime: 1996-03-04 19:06:21 UTC
Raw Date: Tue, 5 Mar 1996 03:06:21 +0800
From: Derek Atkins <warlord@MIT.EDU>
Date: Tue, 5 Mar 1996 03:06:21 +0800
To: Bill Stewart <stewarts@ix.netcom.com>
Subject: Re: Problems with certificates.
In-Reply-To: <199603022121.NAA10418@ix8.ix.netcom.com>
Message-ID: <199603041635.LAA08126@toxicwaste.media.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain
Just a quick clarification...
> PGP KeyIDs are 8 hexes long (formerly 6), and there have been some natural
> collisions and it's easy to manufacture them. On the other hand,
> the MD5 hash used for key fingerprints is 128 bits long, and
> cryptographically strong.
The printable part of the keyid is 8 hexes long. The internal keyID
that PGP uses for choosing keys is actually 8 bytes, not 8 hexes.
Besides, its not the length that matters, but the security.
-derek
Return to March 1996
Return to “Derek Atkins <warlord@MIT.EDU>”