You are here: silicon.com > Software > Security Strategy

Security Strategy

Flawed encryption leaves networks open to attack

Short keys not up to the job...

By Pia Heikkila

Published: 15 April 2002 16:39 GMT

Companies are being warned to stop using short encryption keys as their only measure of protection against hackers.

The most well-known application of short encryption is the Secure Sockets Layer (SSL) protocol, which is commonly used to protect internet transmissions.

But UK encryption specialist nCipher has now warned companies that the short key used in an SSL session could leave networks prone to hack attacks.

nCipher said in a paper entitled The Risk of Short RSA keys for Secure Communications using SSL: "If the RSA key used at the start of secure sessions is compromised, the results could be a devastating attack to the victim. With the increase in computer power over the last few years, the means to carry out such an attack are within reach of a determined and technically competent attacker.

"Given this, the use of short (512-bit) RSA keys for SSL should be abandoned in favour of longer keys. In countries where short keys have been widely used for regulatory reasons, internet commerce over a high proportion of sites should not be regarded as secure."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
New Business Development

SSL VPNs. ENCRYPTION including Perimeter and NETWORK ACESS CONTROL  Understands SERVER ENVIRONMENT TESTING and SCALEABLE NETWORKS  ...

UK Sales Executive-Disk Encryption & Data Protection

JOB TITLE: UK Sales Executive-Disk Encryption & Data Protection Sales SELLING: Disk Encryption and Data Protection SELLING TO: Enterprise and Mid ...

Security Operations Centre Manager (SOC Manager), SC Security Cleared

Basic awareness of computer based network attack scenarios.Desirable Experience: Detailed understanding of networking protocols. Moderate awareness ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: