Banks and 128 bit DES

Ian Jackson ijackson at chiark.greenend.org.uk
Wed, 22 Mar 2000 10:58:48 +0000 (GMT)


Peter Gutmann writes ("Re: Banks and 128 bit DES"):
> The problem occurs when the same people write security requirements which
> stipulate the use of "128-bit RSA encryption" and "X.509 certificates with
> 128-bit keys" and similar gobbledigook (I've seen a number of these,
> including ones from government departments requiring that everyone in a
> particular field use these key sizes).

Clearly the solution is to write security policies that require
`hunnertwenneeatebit encryption' :-).

Ian.