TLS 1.2 and TLS 1.3 need Curve25519 and Curve448 SSL certificates

Puts on aluminium hat

Because they're payed by the NSA

Puts off aluminium hat :stuck_out_tongue:

I'm pretty sure the risk for low-order points can probably be mitigated?

Personally I'd very much like to use Ed25519. I'd also rather use Ed448-Goldilocks. But if EdDSA is going to get used in practice, I'm sure browsers will refuse to add Ed448-Goldilocks support as they decide for their users "it's unnecessary" et cetera.. :confused:

Also, Let's Encrypt is "bound" to the features offered by their HSMs, so I don't even know if LE could support EdDSA, even if they wanted to..

vvv I trust neither of those.

4 Likes