Bedford, MA, Thursday, September 26, 2002 RSA Laboratories . . . announced that a coordinated team of computer programmers and enthusiasts, known as distributed.net, has solved the RC5-64 Secret-Key Challenge. The distributed.net team solved the challenge in approximately four years, using 331,252 volunteers and their machines.

G

Gee . . . it took four years and gazillion processor hours to find a 64-bit key to an encryption algorithm that was already known. The word is the key actually was discovered a few months ago, but the team didnt know it had cracked the nut (a 35-character plain text message). Could it be that we are getting a little obsessive about security? Is there any particular piece of information in your enterprise that would be of sufficient value to warrant that type of attack? OK, maybe senior managements unsecured loans and other perquisites need to be locked down that tight. Oops. Just kidding. In fact, most of us probably are using even stronger security than this. On our secure Web sites here at The National Underwriter Co., we use RC4 with 128-bit encryption. A 128-bit key means it is exponentially (adding 1 bit to the key doubles the number of possible keys) more difficult to crack than a 64-bit key using brute force. Maybe we need to step back and explore just what all this security is buying us.

Want to continue reading?
Become a Free PropertyCasualty360 Digital Reader

Your access to unlimited PropertyCasualty360 content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking insurance news and analysis, on-site and via our newsletters and custom alerts
  • Weekly Insurance Speak podcast featuring exclusive interviews with industry leaders
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the employee benefits and financial advisory markets on our other ALM sites, BenefitsPRO and ThinkAdvisor
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.