new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

key_management/key_strength

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Key strength determination and computational resistance

Review NIST SP 800-57 (Recommendation for Key Management) for recommended guidelines on key strength for specific algorithm implementations. Establish the application's minimum computational resistance to attack considering: (1) Sophistication of adversaries, (2) How long data needs to be protected, (3) Where data is stored and if it is exposed. Identifying computational resistance to attack informs minimum cryptographic key length required to protect data over its lifetime. Consult NIST SP 800-131a for guidance on determining appropriate key lengths for the chosen algorithm.

Key encryption strength requirement

When encrypting keys for storage or distribution, always encrypt a cryptographic key with another key of equal or greater cryptographic strength.

Elliptic Curve key length selection

When moving to Elliptic Curve-based algorithms, choose a key length that meets or exceeds the comparative strength of other algorithms in use within the system. Refer to NIST SP 800-57 Table 2 for guidance.

Give your agent this brain