Re: [TLS] Safe ECC usage

Dan Brown <> Fri, 18 October 2013 14:21 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 7AB1011E82B3 for <>; Fri, 18 Oct 2013 07:21:58 -0700 (PDT)
X-Quarantine-ID: <TpiydFmrJS38>
X-Virus-Scanned: amavisd-new at
X-Amavis-Alert: BAD HEADER SECTION, Duplicate header field: "MIME-Version"
X-Spam-Flag: NO
X-Spam-Score: -2.479
X-Spam-Status: No, score=-2.479 tagged_above=-999 required=5 tests=[AWL=0.120, BAYES_00=-2.599]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id TpiydFmrJS38 for <>; Fri, 18 Oct 2013 07:21:53 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 8EB4B11E82AE for <>; Fri, 18 Oct 2013 07:21:50 -0700 (PDT)
Content-Type: multipart/mixed; boundary="===============1213953503=="
MIME-Version: 1.0
Received: from ([]) by with ESMTP/TLS/AES128-SHA; 18 Oct 2013 10:21:44 -0400
Received: from ( by ( with Microsoft SMTP Server (TLS) id; Fri, 18 Oct 2013 10:21:43 -0400
Received: from ([fe80::24f3:cc30:b596:7ca0]) by ([::1]) with mapi id 14.03.0123.003; Fri, 18 Oct 2013 10:21:43 -0400
From: Dan Brown <>
To: "''" <>
Thread-Topic: [TLS] Safe ECC usage
Thread-Index: AQHOxuJRxn3XJXmgAkKRAg2ZE6kwf5n3qq2ggAC0kACAAKQ6QIAAYI2AgAEXd7A=
Date: Fri, 18 Oct 2013 14:21:43 +0000
Message-ID: <>
References: <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <>
In-Reply-To: <>
Accept-Language: en-CA, en-US
X-MS-Has-Attach: yes
x-originating-ip: []
MIME-Version: 1.0
Cc: "''" <>, "''" <>
Subject: Re: [TLS] Safe ECC usage
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 18 Oct 2013 14:21:58 -0000

Nico Williams wrote:
> Dan Brown  wrote:
> > Why couldn't a new attack just work on one curve, namely Curve25519?
> > If I understand correctly, DJB has argued that the ECC theory and
> > experience would be evidence for a claim similar, but perhaps not as
> strong, as your claim.
> Let's say that there are single-curve attacks.  We don't know how many
> curves have such attacks, nor how hard it is to find such attacks for
> specific curves, or specific curves with such attacks.  Perhaps DJB
> does know, but either he got spectacularly lucky (if such attack/curve

Well, you've assumed here, just like others, that attacks are random.  If you 
assume that attacks are random, then you are right that manipulation is the 
main threat.

I've argued a few times that assuming random attacks is too optimistic, and 
also close to circular reasoning, and not supported by the evidence.

Remember, Curve25519, though free from the potential of malicious 
manipulation, is chosen, in part, for its special efficiency properties. 
These special properties may also given an attacker special advantages.  DJB 
has already argued, based on the existing attacks  -- not random attacks --  
that this is unlikely.   And I agreed.

Consider the ECC history.  After resisting all generic attacks, we have the 

Miyaji proposed special trace 1 curves.  A few years later, these were broken 
by the SASS attack.

Various proposed supersingular curves.  Later, they were broken by the MOVFR 

But ever since then, it has been fairly quiet on the prime-field side of ECC.

> pairs are rare) or such attack/curve pairs are very common.  The latter
> would imply that all ECC is busted, in which case we needn't worry
> about whether Curve25519 is weak because we have bigger problems, so we
> must ignore this possibility when comparing curves to one another.

Furthermore, if we admit this possibility, i.e. to justify that the ECDLP over 
P256, then we should not just ignore it, but consider alternatives to ECC.

As I understand it, DJB has put forward his reasonable supposition of what the 
bigger problem is.  Maybe you should review it.

> That leaves the former, and now we need some estimate of frequency of
> such attack/curve pairs in order to decide if any one curve is weak.

Of course, it's very hard to make such estimates.  Even so, there is merit in 
making such estimates.  They have to been based on evidence.  There two types 
of evidence here:

1.  The lack of new attacks, despite efforts and incentives.

2.  The existing attacks, e.g. MOVFR and SASS.

Intuition might entirely dismiss inferring estimates from this evidence set, 
as wild speculation.  More formally, intuition would be saying the inference 
drawn from the set have low confidence.

This transmission (including any attachments) may contain confidential information, privileged material (including material protected by the solicitor-client or other applicable privileges), or constitute non-public information. Any use of this information by anyone other than the intended recipient is prohibited. If you have received this transmission in error, please immediately reply to the sender and delete this information from your system. Use, dissemination, distribution, or reproduction of this transmission by unintended recipients is not authorized and may be unlawful.