[Cryptography] [FORGED] Re: ratcheting DH strengths over time

Tony Arcieri bascule at gmail.com
Tue Nov 17 14:46:38 EST 2015


On Tue, Nov 17, 2015 at 7:01 AM, ianG <iang at iang.org> wrote:

> Yes - but how do you get the protocol designers to agree


You don't. If you think you can, good luck.


> to use 2048 only?


It should probably be something like:

- 2048 (ok for approximately the next 10 years or so)
- 4096

Both MTI for now, then retire 2048 after approximately 10 years

...unless large quantum computer appears, in which case you retire
everything

-- 
Tony Arcieri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20151117/13dc79a1/attachment.html>


More information about the cryptography mailing list