1999-02-01 09:00:00+01 by Dan Lyke 0 comments
I think that this note is going to screw up the headers again. I'll fix 'em in the morning. Deal with it. But, some cause for celebration (and as these things usually are, this is a mixed bag). For a short while, at least, this will have the announcement of DES-III being broken in 22 hours:
http://nodezero.distributed.net/cgi/dnet-finger.cgi?user=nugget
What does this mean to you? Well, the morons who run "our" government have decided that U.S. companies can't export keys longer than 40 bits. If you want to keep your data secure from anyone with $50k or a couple of friends, that means that your data is secure for less than 24 hours. Contact your representative and tell them that people who do business have secrets, and if we're going to be competitive in the real world we need to be able to keep those secrets for longer than a day. It also means that if you're using one of the U.S. government approved encryption techniques, your data certainly isn't safe from them, and probably isn't safe from anyone else.