[Cryptography] composing EC & RSA encryption?

Tony Arcieri bascule at gmail.com
Mon Oct 26 12:28:03 EDT 2015


On Mon, Oct 26, 2015 at 8:18 AM, Bill Cox <waywardgeek at gmail.com> wrote:

> On Sun, Oct 25, 2015 at 3:47 PM, Tony Arcieri <bascule at gmail.com> wrote:
>
>> First, if your worry is QCs, then trying to combine ECC and RSA isn't
>> going to help you as they'll both be obliterated by QCs.
>>
>
> We expect 256-bit ECC to fall to QCs before RSA-2048 or DH-2048
>

Even if this is true (and I'm pretty sure it's not in any meaningful way,
i.e. if a quantum computer successfully breaks 256-bit ECC in the real
world, 2048-bit RSA/DH is definitely next within a timeframe so short
anyone with sense would abandon it), if you're pairing pre-quantum and
post-quantum algorithms anyway, shouldn't you pick the fastest pre-quantum
algorithm you can?

-- 
Tony Arcieri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20151026/d554e5c3/attachment.html>


More information about the cryptography mailing list