3 ms·
> NSA recommended people stop using ECC <384 bits (https://apps.nsa.gov/iaarchive/programs/iad-initiatives/cnsa... https://apps.nsa.gov/iaarchive/programs/iad-i
by dependenttypes 7y ago
> NSA recommended people stop using ECC <384 bits (https://apps.nsa.gov/iaarchive/programs/iad-initiatives/cnsa... https://apps.nsa.gov/iaarchive/programs/iad-initiatives/cnsa...).
Yet they are still fine with AES-128, even though it is objectively a weaker link in the chain. See https://blog.cr.yp.to/20151120-batchattacks.html https://blog.cr.yp.to/20151120-batchattacks.html
- nullc 7y agoIf you follow the link in my message you will see a table with "Use 256 bit keys" for AES.