[saag] Re: [Ext] Re: draft-paulwh-crypto-components-02
Christian Huitema <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
On 2/17/2025 10:12 AM, Paul Hoffman wrote: > On Feb 14, 2025, at 06:20, Paul Wouters<[email protected]> wrote: > >> The recent past (eg non-pq) shows a narrowing of algorithms to mostly be 1 NIST and 1 non-NIST algorithm. > Defining "NIST algorithm" is both time-dependent and error-prone. I prefer to think of what many WGs do is "look at what NIST has done, see if there is anything that is widely-believed to be better, and pick". X25519 and friends is an excellent example of this. I think the mention of NIST here is a bit of distraction, focusing on administrative issues instead of technology. Over time, I have seen a different concern, based on the life time of algorithm. At some unpredictable time in the future, any algorithm may become broken by some innovative attack. If all implementations implemented only that algorithm, all implementations will become vulnerable until they get updated and start supporting a different algorithm. But if implementations supported two different algorithms, they can instead immediately switch to the non-broken algorithm. We have seen that with RSA versus Elliptic curve cryptography, with 80 bit hashes versus 128 bits or 128 bits versus 256, with Elliptic curves of different groups, with AES128GCM versus ChaCha20, or with Elliptic curve cryptography versus post quantum cryptography. At any given time, the trend is to have two algorithms, one because it is fast and commonly used, the other because it is a safe alternative, unlikely to be broken at the same time as the commonly used one. -- Christian Huitema _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]