Re: [Cryptography] Popular curves (was: NSA and cryptanalysis)

2013-09-04 Thread Jose Luis Gomez Pardo
At 08:20 04/09/2013, ianG wrote: On 3/09/13 18:13 PM, Phillip Hallam-Baker wrote: Do we have an ECC curve that is (1) secure and (2) has a written description prior to 1 Sept 1993? (Not answering your direct question.) Personally, I was happy to plan on using DJB's Curve25519. He's do

[Cryptography] Popular curves (was: NSA and cryptanalysis)

2013-09-03 Thread ianG
On 3/09/13 18:13 PM, Phillip Hallam-Baker wrote: The real issue is that the P-521 curve has IP against it, so if you want to use freely usable curves, you're stuck with P-256 and P-384 until some more patents expire. That's more of it than 192 bit security. We can hold our no