Re: sntrup761x25519-sha512
Simon Josefsson <simon=40josefsson.org-Tr9gZwTxerDR74oF6e/[email protected]> Tue, 16 May 2023 07:53:11 +0200
| Newsgroups | gmane.ietf.curdle,gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
"Salz, Rich" <rsalz=40akamai.com-Tr9gZwTxerDR74oF6e/[email protected]> writes: > Nice to hear from you Mark! > >> I personally believe that using the @openssh.com extension is > sufficient until final NIST candidate parameters are published. > > Okay, if that works, then that makes sense :) It doesn't work -- sntrup761 is used widely on the Internet today and will continue to be used. What decision could NIST make that would affect anything for sntrup761x25519-sha512? The algorithm has been stable since 2017. Deferring publication of protocol specifications until some external organization has made some unrelated decision is an active decision that is harmful to Internet security, in my opinion. Organization will continue to harvest data that will be decrypted in the future, and this is contrary to the goals of the IETF. It is similar to say that we shouldn't have published Curve25519 because it wasn't published by NIST. Or ChaCha20. Or TLS 1.3. Or OpenPGP. Or just about anything that the IETF has ever published. /Simon _______________________________________________ Curdle mailing list [email protected] https://www.ietf.org/mailman/listinfo/curdle
signature.asc
(application/pgp-signature, 255 B)
-----BEGIN PGP SIGNATURE----- iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCZGMaRxQcc2ltb25Aam9z ZWZzc29uLm9yZwAKCRBRcisI/kdForOHAP9BQNIoVh75V7vCZvFcQ7q3N0+jvyMC wsLrTSc6CUr0SwD/bX9qWUU/k92GGPFdZeyERUklj2kSuzyjE2WJAt+0QQU= =JH+U -----END PGP SIGNATURE-----