> Long-term protection
> Generic application-independent recommendation, protection from 2016 to 2040
25519 is an asymetric key using eliptic curves
> High security level. This system has a 2^128 security target; breaking it has similar difficulty to breaking NIST P-256, RSA with ≈ 3000-bit keys, strong 128-bit block ciphers, etc. (The same techniques would also produce speed improvements at other security levels.) The best attacks known actually cost more than 2^140 bit operations on average, and degrade quadratically in success probability as the number of bit operations drops.
which takes our comp sci lab 35 seconds on a cluster of 8 machines.
so still no.
Except for the ones recommending 512bit EC's
Perhaps you can find the parameters for a 512bit,non NIST EC and we can both be happy?
Otherwise I'll stick with 8000 and 15424 RSA thnx.
http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublic...
Plus, we KNOW they were routinely breaking 64bit effective strength since the 90s, 30 years on we need a lot lot more than twice the strength, even against half decent hackers - but changing the backbone is considered "too expensive".
So that isn't ME saying the US doesn't have anything valuable enough to protect. Its the US standards agencies.
thats a lot closer to 2 than 10 million million million
whoever taught you integer factorisation and the dlp are order c^n was either lying to you or had been lied to.