Security Basics mailing list archives

Re: Crypto Question


From: Mitchell Rowton <mitchell () attackprevention com>
Date: Fri, 14 Nov 2003 19:51:04 -0500

McGill, Lachlan wrote:

Am I right in assuming that an encrypted file/email is only as secure as the passphrase used for the private key? i.e. If i use 
the passphrase 'password' then does it become irrelevant what key size I use to encrypt the data?

If someone can please briefly explain this to me I would be much appreciative.

Thanks.
Maybe the same question from a different angle. If I make a private key with "password" as the password and you do the same... Our private keys still cant decrypt each others messages. So while im confident that it is somehow bad to have simple passwords, i dont know why. Can anyone explain this better?


---------------------------------------------------------------------------
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security to simplify the management and deployment of PGP and reduce overall PGP costs by up to 80%. FREE WHITEPAPER & 30 Day Trial - http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027 ----------------------------------------------------------------------------


Current thread: