Re: [Cfrg] "Abandoning ECC" — Any replies to "A riddle wrapped in a curve"?

Peter Gutmann <pgut001@cs.auckland.ac.nz> Fri, 23 October 2015 04:38 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 276CE1B2C6B for <cfrg@ietfa.amsl.com>; Thu, 22 Oct 2015 21:38:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.289
X-Spam-Level:
X-Spam-Status: No, score=0.289 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_NONE=-0.0001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uttNU2-XtmVS for <cfrg@ietfa.amsl.com>; Thu, 22 Oct 2015 21:38:22 -0700 (PDT)
Received: from mx4.auckland.ac.nz (mx4.auckland.ac.nz [130.216.125.248]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 988EC1B2C65 for <cfrg@irtf.org>; Thu, 22 Oct 2015 21:38:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1445575101; x=1477111101; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=rZABoOZkPaRCIDQYIS380A9adnzvHQdkKhXtz2kYbJA=; b=MOPXApOp690cxSF0ZSmNot8G7oJUSZD4yWXZ/Hmsc54tS8M3qTSQHsS9 Q+ddJf1mfKyM4Xwe3RY2i8ISUAEPXikuj0KUCrGzxxtrtn7b9UBgDMlQS YRnXViXGwwPEUhR5qOmM/WDZeLtLAJoeW6jrCI66EkiJioHctA9IZ6Djz vNQTVoJS+JXlSye7dpdvGlVNil+WyMaG0Sv+eCHn4G/vsLaUR7CsCd4mn URA8sc5SNj9dqDKi/i2eXRfmu31HYIpNliMnuIGBaukCJSBiWCeYscR5a qMB++gc3W1wObmJAYw5cpFnexQTvc8y444u6B0a58Kmr4Tx/7HKsMWTkL g==;
X-IronPort-AV: E=Sophos;i="5.20,185,1444647600"; d="scan'208";a="50375683"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 130.216.4.125 - Outgoing - Outgoing
Received: from uxchange10-fe3.uoa.auckland.ac.nz ([130.216.4.125]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES128-SHA; 23 Oct 2015 17:38:17 +1300
Received: from UXCN10-5.UoA.auckland.ac.nz ([169.254.5.51]) by uxchange10-fe3.UoA.auckland.ac.nz ([169.254.143.234]) with mapi id 14.03.0174.001; Fri, 23 Oct 2015 17:38:17 +1300
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Tony Arcieri <bascule@gmail.com>, Tao Effect <contact@taoeffect.com>
Thread-Topic: [Cfrg] "Abandoning ECC" — Any replies to "A riddle wrapped in a curve"?
Thread-Index: AQHRDTjsvoFmR1wFIkCMPqW09FGeKp53nCEAgADiaU4=
Date: Fri, 23 Oct 2015 04:38:16 +0000
Message-ID: <9A043F3CF02CD34C8E74AC1594475C73F4B419C4@uxcn10-5.UoA.auckland.ac.nz>
References: <95750F19-2233-4CE9-BD91-6B1AA0C91F16@taoeffect.com>, <CAHOTMVJ2hoq5=Hh2tjGUWe3FGn-xX-gr5Gvn2h_RW8TwC3d8jA@mail.gmail.com>
In-Reply-To: <CAHOTMVJ2hoq5=Hh2tjGUWe3FGn-xX-gr5Gvn2h_RW8TwC3d8jA@mail.gmail.com>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/cfrg/I-Od5Eo_vCOIbsAp8b6d4BCE8bI>
Cc: "cfrg@irtf.org" <cfrg@irtf.org>
Subject: Re: [Cfrg] "Abandoning ECC" — Any replies to "A riddle wrapped in a curve"?
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 04:38:25 -0000

Tony Arcieri <bascule@gmail.com> writes:

>The larger concern cited by both the Koblitz paper and Matt Green's blog post
>is that the NSA feels it is urgent to move to post-quantum cryptography

It's not really that.  There are two things, the move off Suite B and the
attempt to find a replacement.  The move off Suite B is no surprise, the NSA
are simply admitting that after a decade of fruitless attempts to get anyone
interested in it (outside of organisations with a government gun pointed at
their heads, who had no choice), no-one wanted it.  They were in the same
position they were in before Suite B in terms of people not being able to take
advantage of COTS products, it still didn't solve the Type-1-algorithm product
problem.

The second issue is what to replace Suite B with.  They could have said "AES,
'25519, and SHA2, and we're done".  Instead, they're pushing yet another white
elephant to follow on from their previous herd.  After all this time they
still don't understand how COTS actually works.

Peter.