3 ms·
re: discrete log vs ECC, Schneier wrote the following in the comments section of his blog: I no longer trust the constants. I believe the NSA has manipulated t
by pradocchia 13y ago
re: discrete log vs ECC, Schneier wrote the following in the comments section of his blog:
I no longer trust the constants. I believe the NSA has manipulated them through their relationships with industry.
http://www.schneier.com/blog/archives/2013/09/the_nsa_is_brea.html#c1675929 http://www.schneier.com/blog/archives/2013/09/the_nsa_is_bre...
- tptacek 13y agoTo which "constants" is he referrin? Is he suggesting not using the NIST curves, which were themselves selected to avoid a different class of curve attack? Ok, then don't use those curves.
- chopin 13y agoFor end users, this is rather difficult. I maintain a Jetty web server, which is based on Java. The SSL/TLS implementation relies on the cipher suites provided by the JVM. I can restrict Jetty to using ECC as preferred cipher suites but not choose the curves. I assume this is also the case for many other web servers out there. On the other hand it is easy to avoid ECC altogether in this scenario. EDIT: Grammar