Beyond Curve25519

Daniel Kahn Gillmor dkg at fifthhorseman.net
Thu Jan 15 20:49:38 CET 2015


On Thu 2015-01-15 06:54:58 -0500, Milan Kral wrote:
> the security of Curve25519 is about 2^125. Are there plans to implement
> stronger ECC in GnuPG? Good candidate would be E-521, it's one of the
> recommended curves on http://safecurves.cr.yp.to/
>
> https://eprint.iacr.org/2013/647.pdf

The only stronger curves available in GnuPG at the moment are the NIST
curves.  I agree that E-521 would be a reasonable choice for a
high-strength curve, but i don't think anyone has specified or
implemented it yet for OpenPGP.

            --dkg
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 948 bytes
Desc: not available
URL: </pipermail/attachments/20150115/7d82b495/attachment.sig>


More information about the Gnupg-devel mailing list