zlacker

[parent] [thread] 0 comments
1. pbsd+(OP)[view] [source] 2014-12-29 18:17:58
When I say DHE, I mean finite field DH in general; I have no beef with replacing the old TLS DHE mechanism by the one from the ffdhe draft, with curated prime fields to work with.

Index calculus. Over prime fields it has seen essentially no major progress (beyond small complexity tweaks, some of which are useful) since 1992 with the number field sieve. Index calculus also exists for elliptic curves, under some conditions: once again, over prime fields things seem fine (modulo MOV, anomalous, etc curves). I suspect we will also have to drop RSA if the index calculus for prime field discrete logs ever improves significantly. Likewise, some efficient attack against P-256 or curve25519 has a good chance to eliminate most or all curves in that size range.

[go to top]