Hi...

On 11.07.2026 13:00, Ken Kubota wrote:
"I'm not sure what your point is here"
Although strong cryptography (256 bits of security) could generally have been 
available for every end user for the past two decades on standard consumer 
devices, the U.S. government is intentionally deploying, through the NSA, 
degraded (weakened) encryption.
RFC 9151 (2022), which provides only 192 bits of security (curve P-384), is one 
example.

You've misunderstood RFC 9151.

What RFC 9151 and friends say is, “here is how *commercial* entities should *interoperate* with the USG infrastructure”.  And it's not just ECDSA with P-384, but also RSA with either 3072 or 4096 bits.  Weak indeed.  Regardless, if you're not talking to the USG, have a party.  Use whatever suite floats your boat.

Eliot


Attachment: OpenPGP_0x87B66B46D9D27A33.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to