From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 5451F1381F3 for ; Mon, 9 Sep 2013 19:25:02 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 894C7E0C27; Mon, 9 Sep 2013 19:24:58 +0000 (UTC) Received: from mail2.viabit.com (mail2.viabit.com [65.246.80.16]) (using TLSv1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 7AD02E0C10 for ; Mon, 9 Sep 2013 19:24:57 +0000 (UTC) Received: from [172.17.29.6] (vpn1.metro-data.com [65.213.236.242]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail2.viabit.com (Postfix) with ESMTPSA id 3cYfTN54sLz1hgM for ; Mon, 9 Sep 2013 15:24:56 -0400 (EDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=orlitzky.com; s=mail2; t=1378754696; bh=LOxr7YjRAFac42SmH/qYW+2gmR3Q/hydyj4MN/Fyxfk=; h=Date:From:To:Subject:References:In-Reply-To; b=LUHn13k2mJk8Qy0v0yl3Vdp53tTjrNwKeBzm5Qav2Q3JRX4848sqF7DcgnGcGdm7q facMNsdj2mOUktrDnKl0+dsj5s0/BkPrLEcubYLCeRUyJZ7AKXesklZ1diIsOuPor0 //Y0MpNEjnanzCD7F0Hrg7ShGbZtL/MJ9d4A2B9A= Message-ID: <522E2088.20902@orlitzky.com> Date: Mon, 09 Sep 2013 15:24:56 -0400 From: Michael Orlitzky User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130825 Thunderbird/17.0.8 Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org MIME-Version: 1.0 To: gentoo-user@lists.gentoo.org Subject: Re: [gentoo-user] Internet security. References: <522D257C.5060902@gmail.com> <201309090628.49473.michaelkintzios@gmail.com> <522DD044.8080604@orlitzky.com> <201309091907.08701.michaelkintzios@gmail.com> In-Reply-To: <201309091907.08701.michaelkintzios@gmail.com> X-Enigmail-Version: 1.5.2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Archives-Salt: bcb52455-449c-474f-a589-f0deda1ca1ef X-Archives-Hash: b8629460f7182c91d78ffacff895ebb1 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 09/09/2013 02:07 PM, Mick wrote: > On Monday 09 Sep 2013 14:42:28 Michael Orlitzky wrote: >> On 09/09/2013 01:28 AM, Mick wrote: >>> Are you saying that 2048 RSA keys are no good anymore? >> >> They're probably fine, but when you're making them yourself, the >> extra bits are free. I would assume that the NSA can crack >> 1024-bit RSA[1], so why not jump to 4096 so you don't have to do >> this again in a few years? > > Right, but my router won't work with keys larger than 2048 and its > admin GUI is controlled with 1024-bit public certificate. > How often do you need to admin the router? Just do it from home (i.e. on the LAN side). -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.20 (GNU/Linux) iQIcBAEBAgAGBQJSLiCIAAoJEBxJck0inpOiOxUQAKLD/ZpyhmdbyKYhw8git9A9 omPhNJPrIiRFNiw2uS9RrdRTqNaoAQyzRy8QkyfQK5MxYqSR7Xf3YUFv/fNXiahS pT3wSi9OVmaJQ7p5yHkmEdPTp30nhg53kFFeZ6h2Qd1BQ9GmzCoq5ajPavLoIreF DMjpLAsE3fY+1JcMe1qbyqfrAGrfpVrh2h5VdMneIFe2t8/yRQKX5F/z6JWnb8/V pdHQfFkybnJOiul1aLy/C/wKKyHVcrFvpM8QwhfGuDVY/q9h9gg99QN/5KqtahfJ jAuzaygTcSHsYfxNzf83ik0O25RR7UJ/dW4YGbK+PCb11RQZ3i/scxkuW3y11DGS iFMT9bQAP8InqUi8lWawu5fNwJBGlMgbHIYbkzpd/9U2YSQBbjJJgyOczsLcL8cC S8F9i8LqhRW3w6IczSGq6rt51gFgSVpBNaysJprq95Ei3/ZoAZY/jcpKAZhlV0wS 3xRCkiNBjPcyTHuSV5Z4QzgLB77EtO8fdV6vIBshY5zdX1jXFA8n5jKgb9tmTCKQ Eu6c1VvmJ4sIS437UgVcMVs7c08rp5qI3BhM1uKVuD/PIuQkaTnT6MZ57+AsvCjc hQ+tKaDhrnxY1aHkSwimtKKZKTZxmpi6TuMC+kxE9Ytl6/Br5IJhg0QcqZAUY06W A6X/s6n7XYboLXBiBg4c =N9w5 -----END PGP SIGNATURE-----