Re: Curve25519/448 key agreement for SSH

[email protected] (Niels Möller)
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
"Mark D. Baushke" <[email protected]> writes:

> If so, why is the Key Exchange Method name "curve448-sha256" rather than
> "curve488-sha512" ?

I think Damien Miller's argument for using sha512 here makes sense:
"curve448 is a backup against as-yet-unknown attacks on curve25519.
Since we're not likely to need it, we might as well pair it with SHA512
as a backup against as-yet-unknown attacks on SHA256."

Regards,
/Niels

-- 
Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26.
Internet email is subject to wholesale government surveillance.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.