Off-by-One: The Curious Case of 2047-Bit RSA Keys (2019)
randomoracle.wordpress.com
randomoracle.wordpress.com
sqlite> select count(*) from keys;
1627715
Quite a difference between the ratio of 2047/2048 bit keys and 1023/1024 bit keys. sqlite> select count(*) from keys where strength = "2048";
936441
sqlite> select count(*) from keys where strength = "2047";
466
sqlite> select count(*) from keys where strength = "1024";
39068
sqlite> select count(*) from keys where strength = "1023";
5908
Interestingly also: sqlite> select count(*) from keys where strength = "2049";
13
sqlite> select count(*) from keys where strength = "2050";
5
sqlite> select count(*) from keys where strength = "2051";
1
sqlite> select count(*) from keys where strength = "2052";
0A 2048 bit RSA key is generated from two 1024 bit primes. Let's assume we randomly choose each prime from the range 2^1023 to 2^1024. Per the Prime Number Theorem, there are ~ N / ln (N) primes below N. That means that there are 2^1024 / (1024 ln 2) - 2^1023 / (1023 ln 2) ≈ 1.3e305 1024-bit primes. It follows that a 1024 bit prime has ~1023 bits of entropy and that a 2048 bit RSA key has ~2022 bits of entropy.
It can and often does have much less¹, depending on how the keys were generated (debian). That may or may not be an issue, depending on the resulting distribution of keys, i.e. how usable is the information that only a teeny fraction of keys are possible (Infineon).
¹ Entropy interpreted as the number of possible, roughly equal-likelihood outcomes.
A final desirable, although ill-defined, property is
resistance to misuse. Schemes should ideally not fail
catastrophically due to isolated coding errors, random
number generator malfunctions, nonce reuse, keypair reuse...
https://csrc.nist.gov/CSRC/media/Projects/Post-Quantum-Crypt...They lose a bit of entropy by pre-setting the leading bit to 1.
There have been discussions about this in the past - https://news.ycombinator.com/item?id=19374758
article mentions a CSR containing a private key. Isn't that a absolute no no? CSRs you send around, but private keys should never leave your machine. Where machine could even he a hardware token in the ideal case. Confused.