2 ms·
Signing/verification speed are both important on things like TLS/SSH/etc and sadly SPHINCS+ can not compete in either, see page 55 in https://sphincs.org/data/s
by dependenttypes 6y ago
Signing/verification speed are both important on things like TLS/SSH/etc and sadly SPHINCS+ can not compete in either, see page 55 in https://sphincs.org/data/sphincs+-round2-specification.pdf https://sphincs.org/data/sphincs+-round2-specification.pdf
But I agree that it can be used in the OpenPGP use-case. Anyway, Rainbow seems quite solid for TLS.
> McEliece's slow key generation is a big problem when you're creating 1000 connections per second and want good perfect forward secrecy
I personally think that if you want forward secrecy you should derive the session key from both the static McEliece key and the ephemeral ntru/whatever key.
- nullc 6y agoSSH probably could use a much simpler hash based signature than sphincs+ -- e.g. you wouldn't really care if the signature (which is just sent once at connection time) was 40kbytes. Nothing in the competition does that. (too bad, because it would also be the fastest algo in the competition to verify and one of the fastest to sign).