Jean-Michel Pouré - GOOZE wrote:
> > Hopefully the quality of your key is.
> 
> The issue of the quality started with a remark from Ludovic:
> 
> > It looks like bad news for me.
> > A prime number generator in constant time is _very_ suspect.
> 
> On mailing list, this kind of remark is meant to start a flame war.

What? That's certainly not how I interpret what Ludovic wrote!

The type of forum is unimportant.

Quality of key material is however very important, for all cards,
since these are security products.

If in fact a card is not so secure, then we will do the world a
service by pointing that out. Peer review, you know how it works.

As has already been pointed out several times by now there has so far
not been really conclusive information about Feitian, only very
limited testing has been done.


> The RSA generation time can be a sign of speed, accuracy,
> slowlyness, etc .. It does not give buyers any information.

It does give an indication of what to expect.


> The time generation of RSA key in the Feitian PKI varies a lot. But
> it is around one minute. So what?

I would appreciate numbers for the variance rather than "around one
minute" which has only very few bits of information. :\

Also, "varies a lot" is somehow not really compatible with "around
one minute".. Either the time is around the same (it varies a little)
or the time is very different each time (it varies a lot).


//Peter
_______________________________________________
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel

Reply via email to