Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

even if that is true. its still not enough to protect anything of value.


That's not what your own source says about 128-bit symmetric keys:

> Long-term protection

> Generic application-independent recommendation, protection from 2016 to 2040


total nonsense.

25519 is an asymetric key using eliptic curves


As both rockdoe and hannob have mentioned, ed25519 provides the same attack resistance as a 128-bit symmetric cipher. This is even mentioned in the original DJB ed25519 paper:

> High security level. This system has a 2^128 security target; breaking it has similar difficulty to breaking NIST P-256, RSA with ≈ 3000-bit keys, strong 128-bit block ciphers, etc. (The same techniques would also produce speed improvements at other security levels.) The best attacks known actually cost more than 2^140 bit operations on average, and degrade quadratically in success probability as the number of bit operations drops.


->similar difficulty to breaking NIST P-256

which takes our comp sci lab 35 seconds on a cluster of 8 machines.

so still no.


If that's possible, I'm sure you'll have no difficulty finding a public source to cite that states the same.


All the public sources I've found say it is secure.

Except for the ones recommending 512bit EC's

Perhaps you can find the parameters for a 512bit,non NIST EC and we can both be happy?

Otherwise I'll stick with 8000 and 15424 RSA thnx.


Absolutely incorrect. Anything above 90-100 bits of effective (symmetric) strength is currently more than enough, even against nation state actors.


112 bit effective strength has been the required MINIMUM for FIPS/NIST since 2014. ->and that is just to protect you from NON nation state actors.

http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublic...

Plus, we KNOW they were routinely breaking 64bit effective strength since the 90s, 30 years on we need a lot lot more than twice the strength, even against half decent hackers - but changing the backbone is considered "too expensive".

So that isn't ME saying the US doesn't have anything valuable enough to protect. Its the US standards agencies.


128 bits isn't twice as strong as 64 bits. 65 bits is twice as strong as 64 bits. 2^64 ~= 10^19 - or 10 million million million times stronger.


technically its around ln(n)ln(ln(n)) stronger "best case"

thats a lot closer to 2 than 10 million million million

whoever taught you integer factorisation and the dlp are order c^n was either lying to you or had been lied to.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: