3 ms·
(Also, obviously RSA does not do DH or a similar mechanism for establishing a shared secret. The workaround is to generate ephemeral keys and sign their public
by throwawayish 10y ago
(Also, obviously RSA does not do DH or a similar mechanism for establishing a shared secret. The workaround is to generate ephemeral keys and sign their public keys with RSA, then generating a shared secret from the ephemeral keys. This is what eg. TLS does in principle, but also shows that RSA still has it's uses: RSA signatures for long-term proofs of identity, ECC for forward-secure communication.)
There are also other caveats. Eg. EC keys tend to be tiny, just like symmetric keys, so one can much more easily distribute them through eg. QR codes, or even read them out loud. RSA keys, not so much.
If ECC fits the application well then using eg. Curve25519-based crypto over RSA or other EC is pretty much a no-brainer: it's, by a large margin, the asymmetric crypto systems with the fewest caveats both in implementation and application, and it's also very fast for any operation.
- tptacek 10y agoRSA signatures are valuable in TLS because the installed base uses RSA, not because you need RSA to solve the problem RSA solves in TLS. There are better ECC constructions for signing and verifying.