Conversation

Really weird reading stuff written 5-7 years ago about curve25519 where everyone is pushing a narrative that the 'sales pitch' is that it's faster rather than that the NIST curves can't be trusted.
1
8
Replying to
The most annoying thing about that sales pitch is that I've never found it to match reality in widely used cryptography / TLS libraries. OpenSSL has slower ed25519 than P-256 on every x86_64 and arm64 CPU I've tested despite ed25519 being the default key exchange algorithm now.
Show replies