Crypto-keys break question

"Anders Rundgren" <anders.rundgren@telia.com> Thu, 22 March 2001 15:28 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id KAA13044 for <pkix-archive@odin.ietf.org>; Thu, 22 Mar 2001 10:28:52 -0500 (EST)
Received: from localhost by above.proper.com (8.9.3/8.9.3) with SMTP id HAA26302; Thu, 22 Mar 2001 07:28:12 -0800 (PST)
Received: by mail.imc.org (bulk_mailer v1.12); Thu, 22 Mar 2001 07:28:08 -0800
Received: from mailc.telia.com (mailc.telia.com [194.22.190.4]) by above.proper.com (8.9.3/8.9.3) with ESMTP id HAA26262 for <ietf-pkix@imc.org>; Thu, 22 Mar 2001 07:28:06 -0800 (PST)
Received: from arport ([212.181.94.147]) by mailc.telia.com (8.11.2/8.11.0) with SMTP id f2MFS6X19788 for <ietf-pkix@imc.org>; Thu, 22 Mar 2001 16:28:07 +0100 (CET)
Message-ID: <003d01c0b2e3$9fa2c9a0$0500a8c0@arport>
From: Anders Rundgren <anders.rundgren@telia.com>
To: ietf-pkix@imc.org
References: <200103011658.LAA17796@stingray.missi.ncsc.mil>
Subject: Crypto-keys break question
Date: Thu, 22 Mar 2001 16:20:26 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Precedence: bulk
List-Archive: http://www.imc.org/ietf-pkix/mail-archive/
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: mailto:ietf-pkix-request@imc.org?body=unsubscribe
Content-Transfer-Encoding: 7bit

Hi 
Some Internet-banks use key-pad boxes for authentication and signing.

A popular brand uses an 8-digit input string that produces an 8-digit result
and with no timing built-in.  On the manufacturer's site there is not a single word on
crypto-graphic strength which makes me wonder how great this thing really is.

Question: This should be like a 27-bit symmetric key which should be *very* easy to break assuming
that you have a few input and  output values at hand.  Is this a correct assumption?
If so, how many seconds/minutes/hours on a standard-PC?  Any links?

Anders