3 ms·
Neither. ECDHE on P-256 doesn't have this problem, is available almost everywhere and is faster and safer: use that, or better still, Curve25519 and friends (in
by qrmn 11y ago
Neither. ECDHE on P-256 doesn't have this problem, is available almost everywhere and is faster and safer: use that, or better still, Curve25519 and friends (in OpenSSH already, coming up in TLS later this year hopefully?).
There's very little reason in practice to bother trying to patch DHE, it's slow and old and interoperates worse (thanks Java). Chrome's just taking it out in the medium-term.
- sarciszewski 11y agoThey standardized on Ed448-Goldilocks: https://mailarchive.ietf.org/arch/msg/cfrg/BPDuOnVbrWiMSCjcfP6YTiaS6NY https://mailarchive.ietf.org/arch/msg/cfrg/BPDuOnVbrWiMSCjcf...