3 ms·
Increasing key length has been the main way to protect crypto from Moore's law. That law is somewhat predictable: we can now how much time a key can hold depend
by geal 13y ago
Increasing key length has been the main way to protect crypto from Moore's law. That law is somewhat predictable: we can now how much time a key can hold depending on ressources needed to crack it.
The real problem here: cryptanalysis advances like Joux's tend to create big leaps, much bigger than what we predict based on Moore's law.
And there's the problem that RSA 2048 is slow, and RSA 4096 is so slow that it's impractical...
- tptacek 13y agoThese are analyses that were available a decade ago, unfortunately. We should already be in the middle of a transition away from RSA and to ECC constructions.
- geal 13y agoWhat were the reasons for this lateness? IIRC there were patent issues for some curves, but is that the only reason?