<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.ellipticcurve.info/Bad_curves_and_weak_crypto/history?feed=atom</id>
	<title>Bad curves and weak crypto - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.ellipticcurve.info/Bad_curves_and_weak_crypto/history?feed=atom"/>
	<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/Bad_curves_and_weak_crypto/history"/>
	<updated>2026-06-20T05:55:50Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=283&amp;oldid=prev</id>
		<title>Rational Point: bad govt refs</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=283&amp;oldid=prev"/>
		<updated>2025-01-11T17:55:15Z</updated>

		<summary type="html">&lt;p&gt;bad govt refs&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:55, 11 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l4&quot;&gt;Line 4:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 4:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &amp;#039;&amp;#039;Federal Register,&amp;#039;&amp;#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &amp;#039;&amp;#039;The Need for Lawful Access&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &amp;#039;&amp;#039;Federal Register,&amp;#039;&amp;#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &amp;#039;&amp;#039;The Need for Lawful Access&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&amp;#039;&amp;#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &amp;#039;&amp;#039;Lawful Access to Encrypted Data Act.&amp;#039;&amp;#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &amp;#039;&amp;#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&amp;#039;&amp;#039; September 2020. https://www.hsaj.org/articles/16650&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;U.S. Department of Justice // Office of Legal Policy // Lawful Access // Encryption and Lawful access. https://www.justice.gov/olp/lawful-access#5&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&amp;#039;&amp;#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &amp;#039;&amp;#039;Lawful Access to Encrypted Data Act.&amp;#039;&amp;#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &amp;#039;&amp;#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&amp;#039;&amp;#039; September 2020. https://www.hsaj.org/articles/16650&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;U.S. Department of Justice // Office of Legal Policy // Lawful Access // Encryption and Lawful access. https://www.justice.gov/olp/lawful-access#5&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/ref&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;NIST // Information Technology Laboratory //&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Computer Security Resource Center // Projects //&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Elliptic Curve Cryptography (ECC) https://csrc.nist.gov/Projects/Elliptic-Curve-Cryptography&lt;/ins&gt;&amp;lt;/ref&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=280&amp;oldid=prev</id>
		<title>Rational Point: //</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=280&amp;oldid=prev"/>
		<updated>2025-01-11T13:08:43Z</updated>

		<summary type="html">&lt;p&gt;//&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 13:08, 11 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &amp;#039;&amp;#039;Federal Register,&amp;#039;&amp;#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &amp;#039;&amp;#039;The Need for Lawful Access&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &amp;#039;&amp;#039;Federal Register,&amp;#039;&amp;#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &amp;#039;&amp;#039;The Need for Lawful Access&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&#039;&#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &#039;&#039;Lawful Access to Encrypted Data Act.&#039;&#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &#039;&#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&#039;&#039; September 2020. https://www.hsaj.org/articles/16650&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;U.S. Department of Justice // Office of Legal Policy // Lawful Access Encryption and Lawful access. https://www.justice.gov/olp/lawful-access#5&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&#039;&#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &#039;&#039;Lawful Access to Encrypted Data Act.&#039;&#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &#039;&#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&#039;&#039; September 2020. https://www.hsaj.org/articles/16650&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;U.S. Department of Justice // Office of Legal Policy // Lawful Access &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;// &lt;/ins&gt;Encryption and Lawful access. https://www.justice.gov/olp/lawful-access#5&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/ref&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/ref&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=279&amp;oldid=prev</id>
		<title>Rational Point: more refs</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=279&amp;oldid=prev"/>
		<updated>2025-01-11T13:07:13Z</updated>

		<summary type="html">&lt;p&gt;more refs&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 13:07, 11 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &amp;#039;&amp;#039;Federal Register,&amp;#039;&amp;#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &amp;#039;&amp;#039;The Need for Lawful Access&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &amp;#039;&amp;#039;Federal Register,&amp;#039;&amp;#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &amp;#039;&amp;#039;The Need for Lawful Access&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&#039;&#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &#039;&#039;Lawful Access to Encrypted Data Act.&#039;&#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &#039;&#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&#039;&#039; September 2020. https://www.hsaj.org/articles/16650&amp;lt;/ref&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&#039;&#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &#039;&#039;Lawful Access to Encrypted Data Act.&#039;&#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &#039;&#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&#039;&#039; September 2020. https://www.hsaj.org/articles/16650&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;U.S. Department of Justice // Office of Legal Policy // Lawful Access Encryption and Lawful access. https://www.justice.gov/olp/lawful-access#5&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/ref&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=278&amp;oldid=prev</id>
		<title>Rational Point: refs</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=278&amp;oldid=prev"/>
		<updated>2025-01-11T12:57:29Z</updated>

		<summary type="html">&lt;p&gt;refs&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 12:57, 11 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l2&quot;&gt;Line 2:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 2:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Ed448-geometry-off.svg|frame|right|Bad crypto curve. The geometry is a little bit off. Come to find out, it&amp;#039;s a squared conic section.]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Ed448-geometry-off.svg|frame|right|Bad crypto curve. The geometry is a little bit off. Come to find out, it&amp;#039;s a squared conic section.]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;ref&amp;gt;Dustin Moody. “Announcing Issuance of Federal Information Processing Standard (FIPS) 186-5, Digital Signature Standard.” &#039;&#039;Federal Register,&#039;&#039; 02/03/2023. https://www.federalregister.gov/documents/2023/02/03/2023-02273/announcing-issuance-of-federal-information-processing-standard-fips-186-5-digital-signature-standard&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Anonymous. (FBI). &#039;&#039;The Need for Lawful Access&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;FBI Asks Technology Companies for Support in Pursuing Child Abusers, Other Criminals,&#039;&#039; Oct 4, 2019. https://www.fbi.gov/news/stories/wray-speaks-at-lawful-access-summit-100419&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;S.4051 - &#039;&#039;Lawful Access to Encrypted Data Act.&#039;&#039; Latest Action:	Senate - 06/23/2020 Read twice and referred to the Committee on the Judiciary. https://www.congress.gov/bill/116th-congress/senate-bill/4051&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;William Mack. “The Key to Lawful Access: An Analysis of the Alternatives Offered in the Encryption Debate.” &#039;&#039;Homeland Security Affairs: The Journal of the NPS Center for Homeland Defense and Security.&#039;&#039; September 2020. https://www.hsaj.org/articles/16650&amp;lt;/ref&amp;gt;&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=163&amp;oldid=prev</id>
		<title>Rational Point: category</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=163&amp;oldid=prev"/>
		<updated>2025-01-03T03:39:15Z</updated>

		<summary type="html">&lt;p&gt;category&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 03:39, 3 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Conic section cryptography]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Ed448-geometry-off.svg|frame|right|Bad crypto curve. The geometry is a little bit off. Come to find out, it&amp;#039;s a squared conic section.]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Ed448-geometry-off.svg|frame|right|Bad crypto curve. The geometry is a little bit off. Come to find out, it&amp;#039;s a squared conic section.]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l7&quot;&gt;Line 7:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;What implementers and users need is abstract pseudocode or general guidelines or feedback, peer review or auditing of open source code, on developing branch-free or look-up-free code for critical places in programs. However, peer review doesn’t work when the peers are all insiders of the educational and corporate government-political Establishment. The focus on extreme efficiency of implementation or hand-optimized machine or assembly code is misplaced. Of course we want applications of crypto code to be efficient, but we want the cracking of it to be as inefficient and difficult as possible. Clocking cycle counts on particular machine architectures is a general purpose computing concern, not especially relevant to the safety or security cryptographic operations.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;What implementers and users need is abstract pseudocode or general guidelines or feedback, peer review or auditing of open source code, on developing branch-free or look-up-free code for critical places in programs. However, peer review doesn’t work when the peers are all insiders of the educational and corporate government-political Establishment. The focus on extreme efficiency of implementation or hand-optimized machine or assembly code is misplaced. Of course we want applications of crypto code to be efficient, but we want the cracking of it to be as inefficient and difficult as possible. Clocking cycle counts on particular machine architectures is a general purpose computing concern, not especially relevant to the safety or security cryptographic operations.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The keys are too small, and when extremely “efficient” implementations exist, the same methods of linear and differential cryptanalysis, Turbo and Viterbi algorithms etc., applied to block ciphers might be used to back out the computations of elliptic curve encryption and recover secrets from ciphertext. Methods of simulated annealing, “quantum” or not, might be used, and even enhanced with artificial intelligence to pick up correlations from which secret keys and/or secret data may be derived.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The keys are too small, and when extremely “efficient” implementations exist, the same methods of linear and differential cryptanalysis, Turbo and Viterbi algorithms&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, logit and probit models, &lt;/ins&gt;etc., applied to block ciphers might be used to back out the computations of elliptic curve encryption and recover secrets from ciphertext. Methods of simulated annealing, “quantum” or not, might be used, and even enhanced with artificial intelligence to pick up correlations from which secret keys and/or secret data may be derived.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=162&amp;oldid=prev</id>
		<title>Rational Point: positive recommendations</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=162&amp;oldid=prev"/>
		<updated>2025-01-03T03:34:53Z</updated>

		<summary type="html">&lt;p&gt;positive recommendations&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 03:34, 3 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l11&quot;&gt;Line 11:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 11:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Back &lt;/del&gt;to [[Elliptic Curve Crypto:General disclaimer]].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;So back &lt;/ins&gt;to [[Elliptic Curve Crypto:General disclaimer]]&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;== Recommendations for elliptic curve PKE ==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;At the same time we cannot have an article that is all negative, without suggestions to move things along in a more positive direction for elliptic curve public key encryption schemes of adequate security.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;===  Public key encryption schemes of adequate security ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The basic recommendations of a total beginner at the black arts would be to start at the beginning with &#039;&#039;&#039;irreducible&#039;&#039;&#039; elliptic curves in the classic [[Weierstraß normal form]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;:&amp;lt;math&amp;gt;y^2 = x^3 + ax + b&amp;lt;/math&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;using rational coefficients &#039;&#039;a&#039;&#039; and &#039;&#039;b&#039;&#039; chosen at random and enforced to be of a minimum [[height]] or algebraic complexity. The classic [[point group operation]] may be employed, without oversimplifying it to a simple cyclic group.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;Large prime numbers&#039;&#039;&#039;, again, chosen at random, should be used as moduli in all elliptic curve cryptographic schemes.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;We should generally be on the lookout for &#039;&#039;&#039;weak keys&#039;&#039;&#039; and &#039;&#039;&#039;strive to avoid them&#039;&#039;&#039; without overspecifying the implementation. If there isn&#039;t a good justifiable reason to specify particular common &#039;&#039;&#039;magic numbers&#039;&#039;&#039; for any cryptographic scheme, then they should be &#039;&#039;&#039;chosen at random&#039;&#039;&#039;, unique for each user.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Do not pay attention to clamors for extreme efficiency in particular implementations or cycle counts on particular machine architectures. Instead, publish full engineering specifications with &#039;&#039;&#039;theoretical justifications of all “choices”&#039;&#039;&#039; made for implementation of recommended algorithms by qualified software engineers in any programming language of their choice with all the diagrams, flow charts, and pseudocode, with indications of critical sections of code that need to be made branch-free or lookup-free to guard against timing attacks&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=150&amp;oldid=prev</id>
		<title>Rational Point: disclaimer</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=150&amp;oldid=prev"/>
		<updated>2025-01-02T03:56:45Z</updated>

		<summary type="html">&lt;p&gt;disclaimer&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 03:56, 2 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l10&quot;&gt;Line 10:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 10:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Back to [[Elliptic Curve Crypto:General disclaimer]].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=147&amp;oldid=prev</id>
		<title>Rational Point: illustration</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=147&amp;oldid=prev"/>
		<updated>2025-01-01T22:59:04Z</updated>

		<summary type="html">&lt;p&gt;illustration&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 22:59, 1 January 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Image:Ed448-geometry-off.svg|frame|right|Bad crypto curve. The geometry is a little bit off. Come to find out, it&#039;s a squared conic section.]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
	<entry>
		<id>https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=142&amp;oldid=prev</id>
		<title>Rational Point: weak keys, too</title>
		<link rel="alternate" type="text/html" href="https://www.ellipticcurve.info/index.php?title=Bad_curves_and_weak_crypto&amp;diff=142&amp;oldid=prev"/>
		<updated>2024-12-31T16:39:37Z</updated>

		<summary type="html">&lt;p&gt;weak keys, too&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Any area of applied science is going to need a “loser article” to describe what can and will go wrong, according to “Murphy’s Law.” There’s a totally Establishment-oriented [http://safecurves.cr.yp.to/ SafeCurves®] initiative that’s starting to become obnoxious at certain levels.&lt;br /&gt;
&lt;br /&gt;
One of Bernstein’s goals was to avoid conditional branches and array look-ups based on secret keys or secret data in crypto algorithms. However the cycle counts on particular microprocessor models are irrelevant at best and misleading at worst to long-term security. The intention there has been to establish [https://en.wikipedia.org/wiki/ECC_patents patent claims] on elliptic curve cryptography as a tangible marketable invention, and tying the implementation to particular microprocessor architectures and specific sequences of machine instructions was perceived, perhaps wrongly, as a valid way to do that in court.&lt;br /&gt;
&lt;br /&gt;
What implementers and users need is abstract pseudocode or general guidelines or feedback, peer review or auditing of open source code, on developing branch-free or look-up-free code for critical places in programs. However, peer review doesn’t work when the peers are all insiders of the educational and corporate government-political Establishment. The focus on extreme efficiency of implementation or hand-optimized machine or assembly code is misplaced. Of course we want applications of crypto code to be efficient, but we want the cracking of it to be as inefficient and difficult as possible. Clocking cycle counts on particular machine architectures is a general purpose computing concern, not especially relevant to the safety or security cryptographic operations.&lt;br /&gt;
&lt;br /&gt;
The keys are too small, and when extremely “efficient” implementations exist, the same methods of linear and differential cryptanalysis, Turbo and Viterbi algorithms etc., applied to block ciphers might be used to back out the computations of elliptic curve encryption and recover secrets from ciphertext. Methods of simulated annealing, “quantum” or not, might be used, and even enhanced with artificial intelligence to pick up correlations from which secret keys and/or secret data may be derived.&lt;br /&gt;
&lt;br /&gt;
So we’re doing it all wrong, and that’s why most of us are losers at the crypto game. We lack the abstract pseudocode, engineering diagrams, flowcharts, test vectors to describe the algorithm and where it needs to be made branch-free or look-up-free in critical spots. We don’t need to know the details of cache timing on your already outdated Pentium or PowerPC architecture to develop sound, theoretically justified secure architecture-independent crypto implementations, in any given programming language.&lt;/div&gt;</summary>
		<author><name>Rational Point</name></author>
	</entry>
</feed>