ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Curve448 in ECDH

2021-02-28 11:09:50
On Sat, 27 Feb 2021, brian m. carlson wrote:

I'm wondering, however, if there's consensus for adding Curve448 as well

That is being tracked by the WG chairs.

The reason I ask is that in many implementations, of the NIST curves,
only P-256 is implemented in a constant-time manner, whereas Curve25519
and Curve448 are almost always implemented in a constant-time manner.

Is that a concern for openpgp ? openpgp is not an interactive protocol
where there is a server-client with possible MITM observing time spent?

Paul

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp