Damus
Jacob Christian Munch-Andersen profile picture
Jacob Christian Munch-Andersen
@Jacob Christian Munch-Andersen
@nprofile1q... I read your old post on key sizes, unfortunately still relevant: https://blog.cr.yp.to/20151120-batchattacks.html

I noted two points that it probably should mention, but doesn't:

1. That the issue also apply to random number generators, all cryptographic algorithms are vulnerable if their key stems from an RNG with 128 bits of state.

2. That mitigation is free. For most symmetric algorithms a change that increases key/state size does not have to increase computation.
1
Daniel J. Bernstein · 10w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq2q3v2cfmwnz8nhmv3wvva5vgmmkdty0gd5kd7mpn9smkplzjuusts26t9 Yeah, it's very low cost to just use 256-bit secrets everywhere. I commented on this in more detail in https://cr.yp.to/papers.html#bruteforce.