[tor-bugs] #17748 [Tor]: Is RSA-1024 secure enough to be used to identify HS

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Dec 3 23:02:11 UTC 2015


#17748: Is RSA-1024 secure enough to be used to identify HS
-------------------------+---------------------
 Reporter:  cypherpunks  |          Owner:
     Type:  defect       |         Status:  new
 Priority:  Medium       |      Milestone:
Component:  Tor          |        Version:
 Severity:  Normal       |     Resolution:
 Keywords:  tor-hs       |  Actual Points:
Parent ID:               |         Points:
  Sponsor:               |
-------------------------+---------------------

Comment (by teor):

 I'm not sure if raising a ticket is the best way to get answers to these
 kinds of questions: overall, if we're using a cryptographic primitive in
 Tor, we believe it's secure enough, or we're making plans to transition
 away from it.

 As far as ECC is concerned:

 It depends on the curve, the implementation, and the threat model.

 You may find the following comparison of different ECC schemes helpful:
 http://safecurves.cr.yp.to/

 It's worth noting that ed25519 fulfils all the criteria listed on the
 site.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17748#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list