On Sat, Nov 29, 2014 at 6:14 PM, David Leon Gil <[email protected]> wrote:
> egregious blunders are entirely mine, however.)

Speaking of egregious blunders: those results are incorrect. I was
inadvertently omitting curves with small factors on the twist; the
real probability of a twist-secure curve is somewhat lower.

(For example, the curve with j-invariant 480 has prime order, but its
twist has small factors of 11 and 41; the trace is
0x2469cf14a46eb41c5aacf42bc9d61c9168d12ef701ad0f09. It was not counted
as a curve with prime order.)

Urgh. Re-running.
_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to