The only downside to Ed25519 is that it will fall to quantum computing before RS... (2024)


The only downside to Ed25519 is that it will fall to quantum computing before RSA 4096.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (1)

Except nobody knows when that's gonna really happen. I've personally switched to ed25519-sk wherever I could.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (2)

lucb1e on Aug 26, 2020 | parent | next [–]


Same, the short key looks much nicer and both will fall to quantum anyhow. Haven't run into any incompatibilities among the services I use.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (3)

ShorsHammer on Aug 27, 2020 | prev | next [–]


OpenSSH has a post-quantum hybrid algo using SNTRUPrime and ed25519.

> * ssh(1), sshd(8): Add experimental quantum-computing resistant key exchange method, based on a combination of Streamlined NTRU Prime 4591^761 and X25519.

https://www.openssh.com/txt/release-8.0

The only downside to Ed25519 is that it will fall to quantum computing before RS... (4)

dependenttypes on Aug 27, 2020 | prev | next [–]


As far as I know elliptic curves at the same size as RSA are stronger both in a quantum and post-quantum setting.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (5)

aborsy on Aug 27, 2020 | parent | next [–]


True, in fact an elliptic key with 4096 bits would be way overkill. But there is also the issue of support.

Ed25519 and RSA3072 offer around 128 bits of entropy, which is kind of on margin even classically. RSA 4096 offers more protection against brute force, around 144 bits if I recall correctly. Of course, RSA is vulnerable to side channel attacks (though these nay not be in the threat model of many people).

You could use ed448 with 224 bits of security with still shorter keys than common RSA variants. But then it’s not supported in most places.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (6)

dependenttypes on Aug 27, 2020 | root | parent | next [–]


> which is kind of on margin even classically

Is it though? It requires around 2^128 operations to be broken. It does not seem very marginal to me.

It is not like AES where you have to deal with batch-attacks or cryptographic hash functions where collisions for a n-length output require only sqrt(2^n) attempts.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (7)

aborsy on Aug 27, 2020 | root | parent | next [–]


That’s not how it works!

That 128 bits is theoretical upper bound, not necessarily an achievable security rate. That’s the point of margin.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (8)

dependenttypes on Aug 27, 2020 | root | parent | next [–]


Very well, in that case, which symmetric encryption algorithm would you say has an acceptable security margin?

The only downside to Ed25519 is that it will fall to quantum computing before RS... (9)

NewJazz on Aug 27, 2020 | prev | next [–]


Is that because elliptic curve cryptography is more sensitive to quantum brute force in general, or is the key size of ed25519 the real factor?

The only downside to Ed25519 is that it will fall to quantum computing before RS... (10)

And the only downside to RSA 4096 is that it will fall before Niederreiter using binary Goppa codes?

The only downside to Ed25519 is that it will fall to quantum computing before RS... (11)

benlivengood on Aug 27, 2020 | parent [–]


The upside of RSA is that we'll likely have evidence of ed25519 being breakable (~1500 qubits) before breaking RSA 4096 is possible (~8000 qubits). [https://crypto.stackexchange.com/questions/35137/how-many-qu...]

The number of usable qubits in a single computation is expensive and has been growing slowly and until that changes I figure it's more likely to be surprised by a break of ed25519 but not RSA 4096 than to be surprised by a break of both.

The only downside to Ed25519 is that it will fall to quantum computing before RS... (2024)
Top Articles
What are the differences between the Apple M1 and M2 chips?
GigPro 1099 Income Tax Calculator | Everlance
Artem The Gambler
Dragon Age Inquisition War Table Operations and Missions Guide
Chicago Neighborhoods: Lincoln Square & Ravenswood - Chicago Moms
How To Do A Springboard Attack In Wwe 2K22
Atvs For Sale By Owner Craigslist
Did 9Anime Rebrand
Hertz Car Rental Partnership | Uber
Craigslist Furniture Bedroom Set
Tx Rrc Drilling Permit Query
Mikayla Campino Video Twitter: Unveiling the Viral Sensation and Its Impact on Social Media
Www.paystubportal.com/7-11 Login
Cooktopcove Com
Beau John Maloney Houston Tx
All Buttons In Blox Fruits
Restaurants Near Paramount Theater Cedar Rapids
Most McDonald's by Country 2024
Best Nail Salon Rome Ga
iZurvive DayZ & ARMA Map
Pretend Newlyweds Nikubou Maranoshin
The Menu Showtimes Near Regal Edwards Ontario Mountain Village
Bidevv Evansville In Online Liquid
Craigslist Dubuque Iowa Pets
Is Holly Warlick Married To Susan Patton
Weathervane Broken Monorail
'Insidious: The Red Door': Release Date, Cast, Trailer, and What to Expect
Ups Drop Off Newton Ks
49S Results Coral
Devotion Showtimes Near The Grand 16 - Pier Park
Pokemmo Level Caps
UPS Drop Off Location Finder
Microsoftlicentiespecialist.nl - Microcenter - ICT voor het MKB
Trebuchet Gizmo Answer Key
Metro 72 Hour Extension 2022
Best Workers Compensation Lawyer Hill & Moin
American Bully Xxl Black Panther
Laff Tv Passport
Wal-Mart 2516 Directory
Cal Poly 2027 College Confidential
Lovein Funeral Obits
Joey Gentile Lpsg
Cuckold Gonewildaudio
Rage Of Harrogath Bugged
Autozone Battery Hold Down
DL381 Delta Air Lines Estado de vuelo Hoy y Historial 2024 | Trip.com
Strange World Showtimes Near Marcus La Crosse Cinema
Pas Bcbs Prefix
Bbwcumdreams
King Fields Mortuary
How to Choose Where to Study Abroad
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 6378

Rating: 4 / 5 (51 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.