None
EN
Comment on Guidance for Choosing an Elliptic Curve Signature Algorithm in 2022 by Sofia
['View Archive', 'Post Author']
Comments for Dhole Moments
Years ago, there would have an additional list item: Ed25519 uses Edward Curves, which have complete addition formulas and are therefore safer to implement in constant-time than Weierstrass curves (i.e. the NIST curves). Naturally, elliptic curve security is more complicated than merely security against the Elliptic Curve Discrete Logarithm Problem (ECDLP). Most of the advice for the NIST Curves at each security level can be copy/pasted for the Brainpool curves, with one important caveat: