3 ms·
The author made no mention the more trusted curve25519 the web wants to move to. Edit: Curve25519 may have been unheard of in 2010.
by spikengineer 10y ago
The author made no mention the more trusted curve25519 the web wants to move to.
Edit: Curve25519 may have been unheard of in 2010.
- tptacek 10y agoWe don't want to move to it because it's "more trusted". We want it because it's a better curve. Most critically: for the most common applications, Curve25519 avoids the need for point validation, eliminating a class of vulnerabilities. It's also much easier to implement in constant time.
- brohee 10y agoIIRC Curve25519 was introduced in 2005, possibly earlier but the earliest reference a cursory search finds is https://cr.yp.to/ecdh/curve25519-20051115.pdf https://cr.yp.to/ecdh/curve25519-20051115.pdf from November 2005. This "analysis" just isn't good at all. My personal acid test to quickly check the worthiness of a page discussing crypto standards : whether IPsec is spelled correctly.