2 ms·
When I was in college there was a distinct worry about elliptic curves vs rsa. My professors were intuitively worried that discrete logs over elliptic curves ma
by tsmarsh 11y ago
When I was in college there was a distinct worry about elliptic curves vs rsa. My professors were intuitively worried that discrete logs over elliptic curves may well have a simple solution, unlike factorization which has millenia of research proving that it is hard. They were worried enough that I just assumed that GCHQ had already cracked it. Is that still a worry?
- pbsd 11y agoSuch worries have mostly faded by now, though you will see some conservative people still preferring RSA. Keep in mind that the computational study of integer factorization only started seriously in the 70s with CFRAC, making the "milennia" argument somewhat moot. There is a fascinating article by (among others) Neal Koblitz, one of the inventors of elliptic curve cryptography, which describes the history and development of ECC through the 80s, 90s, and 00s, and some of the worries that developed: https://eprint.iacr.org/2008/390 https://eprint.iacr.org/2008/390.