Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Phantasm (phnt@fluffytail.org)'s status on Friday, 07-Mar-2025 06:30:53 JST Phantasm
@vic @charlie_root @dcc @cowanon
>NIST P-256 curve
The elliptic curve is ackshualy fine. You are likely even using it right now (or the P-384 version) for signature verification (ECDSA), if not, you are using Curve25519 which is usually the only supported widely used alternative. The P and Q values are just points on the curve whose relationship to each other is the problematic part for the DRBG, not the curve.