Computation of a 30750-Bit Binary Field Discrete Logarithm
eprint.iacr.org
eprint.iacr.org
An unpopular opinion: time until the end of ECC = 20 years
Good links:
[1] https://en.wikipedia.org/wiki/Discrete_logarithm_records
[3] http://www.dtc.umn.edu/~odlyzko/doc/arch/discrete.logs.pdf
A: because this record is on binary fields.
Qs: What about AES? RSA first or ECC?
My real unpopular opinion: designing a secure asymmetric cipher is much harder than symmetric.
ECB is insecure regardless of which cipher you use. There's no excuse for using it in production applications.
The website you've linked is citing legitimate cryptanalytic papers, but it loses credibility by interpreting systems with minor weaknesses as "not considered strong." Minor weaknesses are exhibited in all cryptosystems older than a few years. Can you find me a professional cryptographer who will say SHA-2 is not strong? Because I can't think of any. The authors of these cryptanalytic papers would probably choose it for new projects without being nervous.
It's an attractive idea that cryptographic algorithms will trend towards insecurity over time. But that's a very oversimplified look at how they work, and it's not a reliable prediction over a period <20 years. We are almost certainly several deep research breakthroughs away from a meaningful break in SHA-2.
But I'm just some guy on the internet. If you don't trust my opinion on this, here is the opinion of one of the BLAKE authors, a finalist in the SHA-3 competition: https://twitter.com/veorq/status/834872988445065218
[1] http://www.dima.unige.it/~morafe/MaterialeCTC/p80-menezes.pd...
[2] https://pdfs.semanticscholar.org/8823/54510ddc955c8d7e13c529...
[3] https://eprint.iacr.org/2015/1022.pdf
PS. I am a beginner in cryptography.
Personally, I am not aware of any alternative systems outside of the post-quantum-crypto world.
Yes, in the sense that any system which is not based on an intractability assumption that reduces to the discrete logarithm problem is of research interest for post-quantum cryptography.
No, in the sense that some of the systems under consideration predate serious research in quantum cryptanalysis (including Shor's and Grover's attacks).