5 ms·
Congratulations Werner and GnuPG team! > GnuPG now support Elliptic Curve keys for public key encryption. This is defined in RFC-6637. Because there is no othe
by cryptbe 12y ago
Congratulations Werner and GnuPG team!
> GnuPG now support Elliptic Curve keys for public key encryption. This is defined in RFC-6637. Because there is no other mainstream OpenPGP implementation yet available which supports ECC, the use of such keys is still very limited. [1]
Google End-To-End [2] supports ECC by default. We are working on supporting Ed25519, but encrypting and signing with NIST curves should work and be compatible with GnuPG. That said, we've had a lot of compat issues, so it'll be great if Hacker News readers and GnuPG users can help test our implementation against GnuPG. You can generate keys in GnuPG and import them to End-To-End and vice versa, or you can encrypt/sign messages on one software and decrypt/verify them on the other. If you found a bug or anything that doesn't work as expected, you can report it at https://code.google.com/p/end-to-end/wiki/Issues?tm=3 https://code.google.com/p/end-to-end/wiki/Issues?tm=3. If it's a security bug you're eligible for a monetary reward under our bug bounty program :-).
[1] https://gnupg.org/faq/whats-new-in-2.1.html#ecc https://gnupg.org/faq/whats-new-in-2.1.html#ecc
[2] https://code.google.com/p/end-to-end/ https://code.google.com/p/end-to-end/
- a3_nm 12y agoHopefully this is not too obvious, but what is the advantage of ECC crypto compared to what GnuPG 2.0 is using?
- tptacek 12y agoThere are three big issues; in order of importance: 1. PGP's RSA constructions are archaic; they use a format defined in the 1990s that is vulnerable to multiple different attacks and likely to harbor more that we don't know about yet. (This, bafflingly, is also a problem with DNSSEC.) I should be clear: PGP is not itself known to be vulnerable to these attacks. But neither was Java's TLS implementation, before it was found to be vulnerable a few months back. 2. RSA is well-studied but it's hard to say how well we understand its strength. There are no credible attacks on RSA-2048, but academic progress is being made on a cousin of the factoring problem it relies on (the discrete log problem). ECC is based on a harder math problem, is also well studied, and is believed to be stronger. 3. ECC is faster and provides more security with fewer key bits. A combination of all three of these factors gives a sort of second-order issue, which is that modern public key crypto constructions tend to be based on ECC and not multiplicative group IFP/DLP algorithms. EdDSA is good for reasons other than that it's based on good ECC crypto. Hope that's helpful and not just noise. Looking forward to inevitable 'pbsd correction. :)
- cryptbe 12y agoSpeed. Key generation (and most other operations) in ECC is order of magnitude faster than in RSA, DSA or ElGamal. Last time I checked it took End-To-End's Javascript library seconds to generate a key pair in RSA, but only milliseconds in ECC.
- tedunangst 12y agoKey gen time probably doesn't matter too much in the particular case of pgp, but key size is a big deal. Keys that you might conceivably type by hand. Keys, not fingerprints, that can fit in tweets. Or tattoos. :)
- glass- 12y agoDo you know of anyone with a signify (or reop) key tattoo yet?
- tedunangst 12y agoHeh. No, I'm not trying to encourage that, but I think it's useful as rough measure of practical size for exchanging data. Like "Olympic swimming pools" is a popular measure.