On Fri, Oct 7, 2016 at 7:18 PM, Chang-An Zhao <[email protected]> wrote: > Do you have an exact citation for this claim of "BN128 still has at least > 96 bits of security"? or any other experts can provide more information for > me?
Hi Chang, See the discussion in my original post: https://moderncrypto.org/mail-archive/curves/2016/000740.html The security situation isn't entirely clear yet, though that post mentions some estimates. Trevor _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
