Bottomley: Using Elliptic Curve Cryptography with TPM2
Bottomley: Using Elliptic Curve Cryptography with TPM2
Posted Oct 16, 2017 3:43 UTC (Mon) by luto (subscriber, #39314)In reply to: Bottomley: Using Elliptic Curve Cryptography with TPM2 by Wol
Parent article: Bottomley: Using Elliptic Curve Cryptography with TPM2
> But individual elliptic curves can be solved, and that is not a particularly noteworthy achievement.
Please clarify. There are certainly insecure curves, but I've never heard that you can take an otherwise-okay curve, compute something, and thus "solve" the curve.
In contrast, one can use a number field sieve to do a massive pre-computation that makes DLP easier mod any given prime. IIRC djb has run the numbers, and 1024-bit DH is likely economically breakable this way by an NSA-style attacker as long as enough users are using the same prime.
