4 ms·
Suite B does not contain RSA. EDIT: To your latter point, some people would consider this to be a telling fact.
by sdevlin 13y ago
Suite B does not contain RSA.
EDIT: To your latter point, some people would consider this to be a telling fact.
- sneak 13y agoOr non-EC DH, either. (It does include ECDH.) Perhaps they were simply anticipating DLP progress and wanted to be future-proof?
- ctz 13y agoIt's more likely because you can't achieve modern security levels with cryptosystems built on the DLP or IFP at acceptable performance. Suite B aims for 128-bit or 192-bit security levels; for comparison 1024-bit modulus RSA is currently thought to provide 73-bit security. (The next natural question is why the internet community is still failing to widely deploy cryptosystems with appropriate security levels. I don't know. But HTTPS, OTR and DNSSEC are all built of cheese in this respect.)
- pbsd 13y agoIt's telling that RSA is not practical to deploy at 256-bit security today.
- yk 13y agoJudging from the wikipedia link, Suite B does not contain a public key cypher. Which either tells us, that the NSA does not use asymmetric cyphers because they are broken. Or that they have a technical reason for it, like being able to do everything they want with key exchange, signature and symmetric cypher. So it is probably worth pointing out, that this speculations are interesting, but ultimately fruitless since we simply do not have enough information.
- harshreality 13y agoThere's ECDH and ECDSA.
- yk 13y agoYes, I should have read the wiki link. However my point was, that Suite B is so generic that we can not really speculate why the NSA did recommend this set of algos and not something else.
- twotwotwo 13y agoThey've written up a case for ECC. More elsewhere in the comments, but a key point is "RSA's really slow if you want 2^256 security": http://www.nsa.gov/business/programs/elliptic_curve.shtml http://www.nsa.gov/business/programs/elliptic_curve.shtml