4 ms·
I don't say switching is a bad idea but not sure it would prevent this kind of attack :)
by dc352 10y ago
I don't say switching is a bad idea but not sure it would prevent this kind of attack :)
- tptacek 10y agoThe secret scalar in ECDH doesn't need to be prime; it's just a random number.
- lisper 10y agoYes, exactly. To generate an RSA key you need a complex mechanism wherein many vulnerabilities can hide. To generate an ECC key all you need is a source of entropy. To be sure vulnerabilities can hide in entropy sources as well, but it's a lot easier to swap out an entropy source than it is to swap out a random prime generator.
- api 10y ago... and yet again this shows that complexity is inherently BAD in secure systems.
- dc352 10y agoECDH doesn't give you authenticity, i.e., you can't get a certificate for that. When you look at ways to generate ECC keys, there are classes of vulnerable numbers for which you need to test.
- tptacek 10y agoCould you be more specific about the "vulnerable numbers" we're talking about? The curve base point is a parameter for ECDSA as well. I agree that any protocol that required you to generate curves or even base points on the fly would have similar concerns, but we generally don't use those kinds of protocols.
- dc352 10y agoMy err - rubbish wording as I was thinking primes and talking curves. Still, while I'm punching here a wee bit above my weight - I should read the 186-4 again - there are some tests to verify the strength of the prime. Is it enough for a similar classification? - I don't know...
- tptacek 10y agoThe prime field is part of the definition of the curve. Everyone interoperating on that curve shares it. It may have been generated weirdly --- the Curve25519 prime sure was! --- but all that tells you is what curve they're using. It's true that the particular curves a system supports could be a kind of fingerprint, but that's a banal observation, equally true of the ciphers they support, or the compression algorithms.
- zeveb 10y ago> ECDH doesn't give you authenticity, i.e., you can't get a certificate for that. ECDH doesn't, but ECDSA does. That's why we have Curve25519 & Ed25519, respectively.