Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It does matter where RSA-1024 is being actually used in Tor. As far as I understand, as long as it's not for some long-term keys, it still shouldn't be a problem. Please write if you know more on this subject.


I'm not an expert on Tor code, so I can only speculate and agree partly with you: it matters where it is used. But temporary keys do not necessarily help against an attacker who has access to all/most past Tor traffic. RSA-1024 is used in node identification and hidden services, the weaknesses are known:

https://blog.torproject.org/blog/prism-vs-tor

https://blog.torproject.org/blog/hidden-services-need-some-l...

(note: current state of affairs unknown to me since Tor doesn't seem to update these documents)




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: