in reply to Re: [OT] E-mail security
in thread [OT] E-mail security
I agree that "automatically decrypting and storing the data" would be useful in overcoming difficulty with personnel training. But I think that this adds complexity, and could only be justified if the sensitivity of the application were such that 128bit SSL was inadequate to protect the data.
As to 2048bit keys and ten years of protection, I'd be wary of that. The number suggests you are referring to public key cryptography. Such systems are probably vulnerable to breakthroughs in quantum cryptography. Whether such a breakthrough is likely to occur in the next ten years is debatable, but a symmetric system is more likely to have a good shelf life nowadays. Second, it is very, very rare that data need protection over a term of ten years, If the data is that sensitive, using the Internet at all needs to be seriously questioned.
But hey, Perl can handle it regardless. 8)
"Even if you are on the right track, you'll get run over if you just sit there." - Will Rogers
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: [OT] E-mail security
by bradcathey (Prior) on Aug 16, 2004 at 17:28 UTC |