[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Why I have a 512 bit PGP key



   Read Ken Thompson's Turing Award lecture for why that isn't
   sufficient. Its quite amusing.

I'm quite familiar with the work.  [For those who aren't, it's about
compilers that compile in self-perpetuating bugs from their own source
code.]

The question, however, is not one of possibility but timeliness.
Attacks against persistent information are easier than attacks against
transient information.  If the sysadmin is going to go modifying
compilers, it's no longer annoyance.

Eric