TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Large cluster of domains sharing the same pair of 512bit ZSKs and RSA key oddities

151 pointsby pwtweetover 7 years ago

4 comments

ryan-cover 7 years ago
Just as an example of how easy* it is for even experts to screw these things up, Viktor&#x27;s followup email suggests that tools should enforce parameters.<p>One of his suggestions:<p>&gt; exponent is unconditionally 65535 (F_4)<p>The value for public exponent F_4 is actually 65537 (a low hamming weight prime), not 65535.<p>* This comment originally read &quot;hard&quot; instead of &quot;easy&quot;, which I <i>totally</i> did on purpose as a joke but fixed because it was confusing.
评论 #15598002 未加载
评论 #15597757 未加载
评论 #15598366 未加载
评论 #15599621 未加载
cpercivaover 7 years ago
<p><pre><code> RR count | length ---------+-------- 107 | 131 (1024-bit with exponent 65337 == 3*29*751) </code></pre> What the hell? I can imagine the occasional person typing 65337 when they mean 65537, but <i>107</i> such records?
评论 #15598184 未加载
评论 #15597745 未加载
评论 #15599838 未加载
评论 #15598877 未加载
feelin_googleyover 7 years ago
This aligns with at least one person&#x27;s predictions about the use of weak encryption and high margin for error of setting up and maintaining DNSSEC. He occasionally presents on the &quot;DNS Security Mess&quot; and has long highlighted this among DNSSEC&#x27;s various flaws, with examples of the screw ups so far and their consequences.
评论 #15603433 未加载
userbinatorover 7 years ago
I wonder who are the two domains using such long keys:<p><pre><code> 2 | 1028 (8192-bit keys)</code></pre>
评论 #15598726 未加载
评论 #15600391 未加载
评论 #15599257 未加载