Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That’s true of quantum attacks on symmetric systems, but I’m not aware of any work that hints toward such a possible future for elliptic curves.

If you know of something I’d love to hear it.



I don't know of any possible future for such attacks. My point is just that it's really hard to estimate the probability of unknown mathematical advancement so especially for secrets that you want to keep for a while, it's sensible to build in some buffer for mathematical advancement. I'm not an expert, but I would have a hard time being 99% sure that no one will come up with a sub-exponential algorithm (e.g. some sieving technique) that speeds up solving discrete logs (but doesn't make it trivial). If the cost of the improvement were high it would be a hard tradeoff, but I really don't see a strong argument that the extra couple nanoseconds are that important here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: