Posted Friday 5th June 2009 09:36 GMT
@AC 00:49
"secure dns uses public key crypto to generate digital signatures of the output from strong hash algorithms like md5 and sha. 1024 or 2048 bit rsa keys are never going to be broken in "roughly 3 hours", except for the dumbest hollywood movie scripts"
Uh isn't MD5 considered reasonably trivial amongst the available encryption algorithms? And a 1K or 2K key seems good but surely if this serves as the DNS root key you would anticipate that there would be a *lot* of parties interested in breaking this key with the computing power to throw at it.
But then I know little about DNS so flame away.