Live data from Hacker News

Elliptic Curve Cryptography: A Basic Introduction

blog.boot.dev

11–20 of 41 posts

Re: Elliptic Curve Cryptography: A Basic Introduction

#11

This is indeed basic. Half the article explains public key cryptography, the other gives a basic overview that omits key details, such as the purpose of reflection, and how the curve can get combined with finite fields in practical applications (although point 2 does partly address this aspect). Not a bad way to get a general intuition of the algorithm, but not overly useful, either.

Point 2 is a simplification that borders on wrong: you don't "wrap around if it's too big" - the point operation will always cross the curve (except for the zero point)!

You "wrap around" because you're using a finite field. As far as I understand, the finite field of the scalars allows you to have an inverse for the multiplication, and the finite field of the points is there to make the calculation easier.

Re: Elliptic Curve Cryptography: A Basic Introduction

#12
It's important to note that most ECC is not quantum-resistant and will be obsoleted in the coming years following completion of NIST's post-quantum cryptography competition.

Indeed, OpenSSH recently enabled PQC by default (NTRU Prime over X25519) [1]. ECC has, at best, a short-to-medium term lifespan right now.

1. https://www.zdnet.com/article/openssh-now-defaults-to-protec...

Re: Elliptic Curve Cryptography: A Basic Introduction

#14
post #12

It's important to note that most ECC is not quantum-resistant and will be obsoleted in the coming years following completion of NIST's post-quantum cryptography competition. Indeed, OpenSSH recently enabled PQC by default (NTRU Prime over X25519) [1]. ECC has, at best, a short-to-medium term lifespan right now. 1. https://www.zdnet.com/article/openssh-now-defaults-to-protec...

also, elliptic curves are much more vulnerable to quantum attacks than regular rsa since it uses smaller keys.

Re: Elliptic Curve Cryptography: A Basic Introduction

#15
post #12

It's important to note that most ECC is not quantum-resistant and will be obsoleted in the coming years following completion of NIST's post-quantum cryptography competition. Indeed, OpenSSH recently enabled PQC by default (NTRU Prime over X25519) [1]. ECC has, at best, a short-to-medium term lifespan right now. 1. https://www.zdnet.com/article/openssh-now-defaults-to-protec...

I just recently played with an online quantum computer simulator to get a better understanding of how quantum fourier transform works, it's a lot of fun:

https://algassert.com/quirk

Re: Elliptic Curve Cryptography: A Basic Introduction

#16
post #13

Asymmetric encryption learning would be a lot quicker if they'd call public keys "locks". Maybe not very accurate, but when I heard the word once, I immediately understood the whole concept, easily.

I saw that analogy in Simon Singh's The Code Book and found it very helpful.

Re: Elliptic Curve Cryptography: A Basic Introduction

#18
post #12

It's important to note that most ECC is not quantum-resistant and will be obsoleted in the coming years following completion of NIST's post-quantum cryptography competition. Indeed, OpenSSH recently enabled PQC by default (NTRU Prime over X25519) [1]. ECC has, at best, a short-to-medium term lifespan right now. 1. https://www.zdnet.com/article/openssh-now-defaults-to-protec...

also, elliptic curves are much more vulnerable to quantum attacks than regular rsa since it uses smaller keys.

I wouldn't say more vulnerable necessarily — it requires fewer qubits, but requires larger coherence time. RSA requires more qubits and drastically less time. They're both vulnerable in different ways.

Re: Elliptic Curve Cryptography: A Basic Introduction

#19
post #12

It's important to note that most ECC is not quantum-resistant and will be obsoleted in the coming years following completion of NIST's post-quantum cryptography competition. Indeed, OpenSSH recently enabled PQC by default (NTRU Prime over X25519) [1]. ECC has, at best, a short-to-medium term lifespan right now. 1. https://www.zdnet.com/article/openssh-now-defaults-to-protec...

I'm very excited to see the results of the post-quantum crypto competition. Most of it is above my head, but it's neat to read about lattice problems. Asymmetric cryptography in general is incredible to me.

Re: Elliptic Curve Cryptography: A Basic Introduction

#20
A funny story related to ECC: I was hanging out with a friend of mine about 10 years ago, and I was asking him what he was researching (he is a math professor in Colorado). He told me he was researching Ecliptic curves and their properties. So I said, "oh you must be really interested in elliptic curve cryptography then!" and he said, "what's that?".

He was so deeply into math theory that he hadn't even looked at or cared about the practical applications of his work.

Post reply on HN