ECC in OpenPGP

Ian G <iang@iang.org> Tue, 31 August 2010 00:13 UTC

Received: from hoffman.proper.com (localhost [127.0.0.1]) by hoffman.proper.com (8.14.4/8.14.3) with ESMTP id o7V0Dn0e016096 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 30 Aug 2010 17:13:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by hoffman.proper.com (8.14.4/8.13.5/Submit) id o7V0DnNU016095; Mon, 30 Aug 2010 17:13:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: hoffman.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from fiddle.it (slice.reviewedpress.com [67.207.137.25] (may be forged)) by hoffman.proper.com (8.14.4/8.14.3) with ESMTP id o7V0DmSE016090 for <ietf-openpgp@imc.org>; Mon, 30 Aug 2010 17:13:48 -0700 (MST) (envelope-from iang@iang.org)
Received: from viento.local (localhost [127.0.0.1]) by fiddle.it (Postfix) with ESMTP id 8EB51406C2; Tue, 31 Aug 2010 00:13:46 +0000 (UTC)
Message-ID: <4C7C4939.8050009@iang.org>
Date: Tue, 31 Aug 2010 10:13:45 +1000
From: Ian G <iang@iang.org>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.8) Gecko/20100802 Lightning/1.0b2 Thunderbird/3.1.2
MIME-Version: 1.0
To: ietf-openpgp@imc.org
Subject: ECC in OpenPGP
References: <1282856536.11340.29.camel@fermat.scientia.net> <87pqx4mm0b.fsf@vigenere.g10code.de> <04ac7894a29b891da7cbde98adb287e5@imap.dd24.net> <83BF96BC-A771-4511-B431-9B9B1545E351@callas.org> <49ee22eb2e5747f077b3bc885f197083@imap.dd24.net> <87y6boj5e0.fsf@vigenere.g10code.de>
In-Reply-To: <87y6boj5e0.fsf@vigenere.g10code.de>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Open Question!


On 31/08/10 4:56 AM, Werner Koch wrote:

>> That's also why I'm very pleased about the ID on ECC,... having it sooner
>> than later available makes me sleep much better.
>
> That is something more worth to put your energy it.  I'd really like to
> see ECC implemented.


ECC has been around for a while now, and while we don't have the inside 
info on what Certicom/NSA really think, I'm curious whether the open 
crypto community has got an impression as to its relative merits as 
against RSA.

Is it really worth switching horses across to ECC from RSA?  The NSA 
seems to think so...

Let me put it this way, as a hypothetical:  if OpenPGP next-gen had to 
choose between RSA and ECC, only implement one of them, which would we 
choose?

iang