Hacker News new | past | comments | ask | show | jobs | submit login

It does matter where RSA-1024 is being actually used in Tor. As far as I understand, as long as it's not for some long-term keys, it still shouldn't be a problem. Please write if you know more on this subject.



I'm not an expert on Tor code, so I can only speculate and agree partly with you: it matters where it is used. But temporary keys do not necessarily help against an attacker who has access to all/most past Tor traffic. RSA-1024 is used in node identification and hidden services, the weaknesses are known:

https://blog.torproject.org/blog/prism-vs-tor

https://blog.torproject.org/blog/hidden-services-need-some-l...

(note: current state of affairs unknown to me since Tor doesn't seem to update these documents)




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: