spf-discuss
[Top] [All Lists]

Re: proposed PGP mechanism for SPF

2004-01-15 09:50:25
"George Schlossnagle" <george(_at_)omniti(_dot_)com> wrote:
On Jan 15, 2004, at 9:45 AM, wayne wrote:
In <200401151123(_dot_)I0FBNNS2001804(_at_)asarian-host(_dot_)net> Mark
<admin(_at_)asarian-host(_dot_)net> writes:
Personally, I think the overhead of PGP is way too heavy. Take a
lightening
fast xs module like Crypt::Rijndael: it is stronger than PGP,
cleaner, much
faster, and does not require shelling out to any PGP executable.

It's a pretty bold claim to say that Rijndael/AES is stronger than PGP. PGP
can use TripleDES, and you'll have a hard time convincing me that AES is
stronger than TripleDES. AES is much faster and we hope that is is stronger,
but AES is a young cypher and time will only tell if it's stronger than
TripleDES.

First off, the actual messages in pgp/gpg are (can be) encrypted using
fast cyphers, it is the public key stuff that is really expensive.  We
can't get around using public key stuff for this kind of thing, so we
are stuck with the "heavy weight" pgp/gpg.

Yeah, we can't get around RSA or DSA for signing stuff with public keys.

Best,
GFK's
-- 
Guillaume Filion, ing. jr
Logidac Tech., Beaumont, Québec, Canada - http://logidac.com/
PGP Key and more: http://guillaume.filion.org/

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.4.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)½§Åv¼ð¦ç?2b¥yÈbox(_dot_)com