ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Curve3617 in OpenPGP? Beyond rfc6637.

2013-10-18 02:57:44
On Fri, Oct 18, 2013 at 12:24 AM, Werner Koch <wk(_at_)gnupg(_dot_)org> wrote:
This is a minor drawback because introducing this
latter would still allow to keep on using the same keys.

Beyond the obvious doubling the size of the keys for no increase in
security (and that implementers often make mistakes and do things like
fail to validate the points, which I guess isn't an issue for ed25519
as it is twist secure), it would make it gratuitously incompatible all
the existing (esp fast constant time code) implementations which work
on the X coordinate alone.

Thats unfortunate, if not the end of the world.
_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp