4 ms·
Its suspected from the snowden docs that this is one of the ones intentionally weakened by NIST. Here's the long answer: https://blog.cr.yp.to/20140323-ecdsa.h
by EnigmaCurry 4y ago
Its suspected from the snowden docs that this is one of the ones intentionally weakened by NIST.
Here's the long answer: https://blog.cr.yp.to/20140323-ecdsa.html https://blog.cr.yp.to/20140323-ecdsa.html
- tptacek 4y agoNobody serious thinks the P-curves, which is what we're talking about, were weakened by NIST. I don't think anybody at all thinks the DSA algorithm was "intentionally weakened", but lots of people, reasonably, believe it was incompetently designed. Ed2519 has the virtue of both a better curve and a better signing algorithm, which is why it's used in preference to ECDSA. If you're using 25519, don't bother keeping the rest of the algorithms enabled. I think these hardening guides are mostly pretty silly too, for whatever that's worth. The important thing is making sure nobody can log into anything with a password. The rest is just liturgical.