ietf-openpgp
[Top] [All Lists]

Re: including the entire fingerprint of the issuer in an OpenPGP certification

2011-01-18 18:24:24

"Daniel A. Nagy" <nagydani(_at_)epointsystem(_dot_)org> writes:

generating a new key with the same 64-bit key ID as an existing key is on the
very far end of the realm of feasibility.

That should be:

  generating a *secure* new key with the same 64-bit key ID as an existing key
  is on the very far end of the realm of feasibility.

If you don't mind that your key's weak then it's not that much more work than
just finding a 64-bit collision.

Peter.