Seriously, the default options to ssh-keygen should be all anybody needs. If you need to pass arguments to increase the security of the generated key, then the software has completely failed its purpose. Passing arguments should only be for falling back on less secure options, if there is some limiting factor for a particular deployment. There is absolutely no reason to pass arguments to ssh-keygen. If it is actually…
I too, say, No f'ing thanks https://en.wikipedia.org/wiki/Curve25519 In cryptography, Curve25519 is an elliptic curve offering 128 bits of security - The curve is birationally equivalent to Ed25519, a Twisted Edwards curve.
Ecrypt II - the EU project into encryption security says: https://www.keylength.com/en/3/
That gives you
Very short-term protection against small organizations Should not be used for confidentiality in new systems
and is equivelent to an 816bit RSA key
So how is this new key "Sexy" in any way.