ECDLP Can Be Solved in 24-th Root Time
ellipticnews.wordpress.com
ECDLP Can Be Solved in 24-th Root Time
1–10 of 17 posts
Re: ECDLP Can Be Solved in 24-th Root Time
#2Ouch, if true, that's a major blow. I was starting to like these elliptic curves!
edit: April 1st guys:
> Steven Galbraith, April 1, 2016.
Re: ECDLP Can Be Solved in 24-th Root Time
#3Re: ECDLP Can Be Solved in 24-th Root Time
#4Re: ECDLP Can Be Solved in 24-th Root Time
#5> As a result we recommend increasing elliptic curve key sizes from 256 bits to 3072 bits. Ouch, if true, that's a major blow. I was starting to like these elliptic curves! edit: April 1st guys: > Steven Galbraith, April 1, 2016.
Re: ECDLP Can Be Solved in 24-th Root Time
#6> As a result we recommend increasing elliptic curve key sizes from 256 bits to 3072 bits. Ouch, if true, that's a major blow. I was starting to like these elliptic curves! edit: April 1st guys: > Steven Galbraith, April 1, 2016.
April 1st...
Re: ECDLP Can Be Solved in 24-th Root Time
#7is this true?
[commitment: a31500d27e35b23c63287161cb405e20]
Re: ECDLP Can Be Solved in 24-th Root Time
#8Re: ECDLP Can Be Solved in 24-th Root Time
#9This is extremely bad. Think what would happen if you deployed RSA with 256-bit keys for HTTPS and SSH (for host and user key-pairs).
If the results reported above are correct, then we are now effectively at such a situation. Many top websites do use ECDHE with 256-bit (or shorter) ephemeral keys. Many people do relay on 256-bit keys for SSH host and user authentication.
People will be able to decrypt new and previously sniffed HTTPS sessions, SSH sessions, will be able to log into your SSH servers, MITM your SSH connections (by computing the private ECDSA host key).
IIRC previously you needed in the order of 2^128 operations to break ECDLP for 256-bit keys (and ECDHE ECDSA). Now that goes down to 2^(256/24), shortening effective key-size 12-fold (resulting in a speedup of factor 2^117).
I'm not an expert in the field, so take these estimations with a large grain of salt. Corrections welcome.
Update: on a second thought, it is April 1st today. Anxiously waiting for confirmation of hoax.
Re: ECDLP Can Be Solved in 24-th Root Time
#10is this true?
Yes. Even worse, because their are elliptic curve methods for factorising products of primes (Lenstra's ECM), there will be a knock-on effect on RSA. RSA keys will now need to be 131,072-bits to maintain their current level of security. This is effectively the Cryptopocalypse: https://www.schneier.com/blog/archives/2013/08/the_cryptopoc... [commitment: a31500d27e35b23c63287161cb405e20]