Re: Curve25519/448 key agreement for SSH
[email protected] (Niels Möller)
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
"Mark D. Baushke" <[email protected]> writes: > If so, why is the Key Exchange Method name "curve448-sha256" rather than > "curve488-sha512" ? I think Damien Miller's argument for using sha512 here makes sense: "curve448 is a backup against as-yet-unknown attacks on curve25519. Since we're not likely to need it, we might as well pair it with SHA512 as a backup against as-yet-unknown attacks on SHA256." Regards, /Niels -- Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26. Internet email is subject to wholesale government surveillance.