[RC5] RC5-72 Clarity?

Fuzzy Logic fuzzymo at gmail.com
Wed Jun 6 07:28:53 EDT 2007

While RC5-72 is still up in the air, I think that eventually we will
kill the project. I has no significant scientific contribution, while
OGR-P2 and others waiting in the wings still do have value. Some
people joined just for the stats, but most just wanted to do something
cool, and being able to claim you had a part in something that made
even a small difference is certainly cooler than brute-forcing a key
in 20-30 years time.

As for your suggestion of automatic core updates: I find it
interesting, but completely impossible without a first-step manual
effort to replace all existing clients out there one time. The way the
current distributed.new clients work is to retrieve work units, none
of which are executable. They don't have the capability to ask for
anything else or for dnet to push anything else to them. Also, as
several people have mentioned, it is a possible security hole. I work
in cryptography, so I know it can be done, but setting up the
infrastructure to safely and securely distribute automatic updates to
clients is not a small amount of work, and if the private key used to
sign downloads was ever compromised, you would have a large pool of
bots available to you unless the clients were implemented just right.

I hope that answers your questions, at least from my point of view.


On 6/6/07, Danie van Heerden <danievh at csnet.co.za> wrote:
> I do apologise for my reply. When you deal with so many members like we do
> and ask a simple question, somebody like Martin comes along and starts
> something completely offbeat from what I asked and you never get a proper
> answer.
> Any PROPER answers to my questions?

