‘Facebook use unsafe and obsolete 1024 bit-rsa-encryption’

0
534

The social-networking site Facebook would still have the 1024 bit rsa encryption for ssl connections, while cryptografen for some time 2048bit keys recommend. The NSA would, moreover, in a relatively short time, the 1024 bit keys can be cracked.

While companies such as Apple, Microsoft, and Dropbox for some time, 2048bit rsa keys handling and several parties already 4096bit keys choose, uses Facebook still 1024 bit encryption, writes CNET. The U.s. National Institute of Standards and Technology recommends, however, since 2010, to no longer 1024 bit keys for ssl connections to use due to their lack of strong encryption. The use of 1024 bit keys has the advantage that the owner has less processing power on its servers need.

According to cryptograaf Eran Tromer, who previously had a document drafted that includes specific hardware for decoding has been described, a 1024 bit key now cracked be there for roughly 1 million dollars in hardware is purchased. How to find the key would take around a year to complete. Intelligence agencies like the NSA with miljardenbudgetten would encrypted data is relatively easy to know.

Facebook did not respond to the findings of CNET, but an anonymous source would have to know that the social-networking site, however, were preparing to make the transition to 2048bit encryption. Incidentally, it also uses Google still 1024 bit keys, but because the search giant for each session via the forward secrecy mechanism becoming a new key to generate, and Google are rsa keys every two weeks to refresh, the vulnerability significantly lower.