<html><head><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">Thanks, Salanieta for sharing this.<div class=""><br class=""></div><div class="">Even if it might seem intuitive to always go for a higher key length, sometimes it does not improve anything including the performance, at least from a certain threshold. </div><div class=""><br class=""></div><div class="">Firstly, the root server may have the required capacity to process all the requests, but not the tiny small device, which should also be able to afford the crypto algorithm complexity and key length too. </div><div class="">Secondly, since signing a file involves transforming messages from a set M to hashes on a set H, from a certain point, increasing the key size without modifying the set H will not increase performance/efficiency because the collision domain remains unchanged (A collision is an event that occurs when two different messages produce the same hash or signature).</div><div class="">Thirdly, if a key of length K cannot be brute forced within a very very very long time (power of the human-being lifetime such as 2,000,000 years), it is unnecessary (but not useless) to increase it.</div><div class=""><br class=""></div><div class="">That said, Tomslin could you please share the ICANN document that says it is not necessary to increase the key size? Perhaps, they have different arguments.</div><div class=""><br class=""><div class="">
<div dir="auto" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class="Apple-interchange-newline">@__f_f__<br class=""><br class="">Best Regards<br class=""><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;">____________________________________</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;"><br class=""></div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;">(Ekue) Farell FOLLY</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;">NCUC Rep. to the NCSG Policy Committee</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;"><a href="http://linkedin.com/in/farellf" class="">linkedin.com/in/farellf</a> <br class=""></div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;"><br class=""></div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><br class=""></div><br class="Apple-interchange-newline"></div></div><br class="Apple-interchange-newline" style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;"><br class="Apple-interchange-newline" style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;"></div></div></div></div>
</div>
<div><br class=""><blockquote type="cite" class=""><div class="">On 16 Oct 2018, at 02:42, Tomslin Samme-Nlar <<a href="mailto:mesumbeslin@gmail.com" class="">mesumbeslin@gmail.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div dir="auto" class="">Thanks for sharing Salanieta. <div dir="auto" class=""><br class=""></div><div dir="auto" class="">A higher crypto key strength/size is indeed something ICANN should consider, since the root zone is well, the root! </div><div dir="auto" class="">I haven't read the report where RSPK found no compelling ground to increase the algorithm size of the key. I'll dig it up and see why they believe it is not necessary.<br class=""><br class=""><div data-smartmail="gmail_signature" dir="auto" class="">Cheers,<br class="">Tomslin<br class=""></div><br class=""><div class="gmail_quote" dir="auto"><div dir="ltr" class="">On Mon., 15 Oct. 2018, 05:13 Salanieta Tamanikaiwaimaro, <<a href="mailto:sala@pasifikanexus.nu" class="">sala@pasifikanexus.nu</a>> wrote:<br class=""></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr" class=""><div dir="ltr" class="">Dear All,<div class=""><br class=""></div><div class=""><ol class=""><li style="margin-left:15px" class="">Here is an Article I posted yesterday, following the successful KSK Rollover on the 11th of October, 2018 and most of Oceania's 12th October, 2018.<br class=""></li><li style="margin-left:15px" class="">In it I raise issues concerning Surveillance, Privacy, Cyber Security and vulnerabilities of the <i class="">Elliptical Curve Cryptography</i> and I make a correlation with the Surveillance at the Telecommunications layer and wonder what is to stop this from happening in the Root Level.<br class=""></li><li style="margin-left:15px" class="">You can read the Article by clicking <a href="http://www.circleid.com/posts/20181013_ksk_rollover_elliptical_curve_vulnerabilities_surveillance/" target="_blank" rel="noreferrer" class="">here</a>. </li><li style="margin-left:15px" class="">As an additional note, you would think they would go with the highest size key strength available as it is the single point of failure for the entire DNSSEC system and single point of target as Todd Knarr points out.<br class=""></li></ol></div><div class=""><br class=""></div><div class=""><div dir="ltr" class="m_-6517453004394486830gmail_signature"><div dir="ltr" class=""><div class=""><div dir="ltr" class=""><div class=""><div dir="ltr" class=""><div dir="ltr" class=""><div class=""><font class="">Cell: +679 <span class="">7656770; +679 7220149</span></font></div><div class=""><font class="">Tel: +679 3362003</font></div><div class=""><font class="">E: <a href="mailto:sala@pasifikanexus.nu" target="_blank" rel="noreferrer" class="">sala@pasifikanexus.nu</a></font></div><div class=""><font class="">Website: <a href="http://www.pasifikanexus.nu/" target="_blank" rel="noreferrer" class="">www.pasifikanexus.nu</a> </font></div><div class=""><font class="">Twitter: @SalanietaT</font></div><div class=""><font color="#0000ff" class=""><br class=""></font></div><div class=""><p class=""><font size="1" class=""><font face="arial, helvetica, sans-serif" style="color:rgb(0,0,255)" class="">Please consider the </font><font face="arial, helvetica, sans-serif" color="#38761d" class=""><b class="">environment</b></font><font face="arial, helvetica, sans-serif" style="color:rgb(0,0,255)" class=""> before printing this email.<br class=""></font></font></p><p class=""><span lang="EN-US" class=""><font face="arial, helvetica, sans-serif" color="#0000ff" size="1" class=""> <u class=""></u><u class=""></u></font></span></p><p class=""><span lang="EN-US" class=""><font face="arial, helvetica, sans-serif" size="1" class=""><font color="#0000ff" class="">This transmission is intended only for the use of the addressee. It may contain confidential or legally privileged information. If you are not the intended recipient,</font><font color="#ff0000" class=""> <b class="">KINDLY NOTE</b></font> <font color="#0000ff" class="">any use or dissemination of this communication is prohibited and no confidentiality rights or legal professional privilege are hereby waived. If you have received this transmission in error, please notify us immediately  and destroy and/or delete all hard and soft copy data relating to this transmission. The contents of this email, unless expressly stated, do not comprise the views of, or any representation by, Pasifika Nexus, directors or staff. Pasifika Nexus has active anti-virus and anti malware measures on its electronic mail system but cannot accept any liability for virus damage suffered by any recipient as a result of this or any transmission to that recipient.</font></font></span></p></div></div></div></div></div></div></div></div></div></div></div>
</blockquote></div></div></div>
</div></blockquote></div><br class=""></div></body></html>