3 ms·
> To me, the real takeaway: RSA is obsolete. Stop using it. RSA also has the nice property of being deterministic. ECDSA may not be, depending on how you impl
by DanielDent 11y ago
> To me, the real takeaway: RSA is obsolete. Stop using it.
RSA also has the nice property of being deterministic.
ECDSA may not be, depending on how you implement it. EDDSA is.
This matters a great deal in a world where it's important to assume your hardware may have some adversarial properties. It's much easier for your ECDSA device to purposefully leak your private key than it is for RSA (both because there's an explicit covert channel available, and also because of how much smaller elliptic key-pairs are in practice).
Also, as we prepare for a post-quantum crypto world, this might be a bad time for shorter keylengths.
There are lots of great reasons to use curves, but I think describing RSA as obsolete is a little premature.
- tptacek 11y agoDon't use ECDSA, and don't use RSA. I don't think reasonable key lengths are going to make much of a difference if quantum computing becomes a practical threat. All the RSA cryptosystems and all the ECC cryptosystems will fall. Meanwhile: the literature suggests that RSA and classical DH keys are threatened much more by conventional computing advances than curve keys; curve keys resist index calculus attacks.