{"type":"rich","version":"1.0","author_name":"npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd","author_url":"https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-03-21\n📝 Original message:Oh, one other reason I found - apparently RIM, at least in the past, has\nbeen telling CA's that they need to pay mad bux for the Certicom ECC\npatents. So that's another reason why most certs are still using RSA.\n\n\nOn Fri, Mar 21, 2014 at 12:08 PM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\n\u003e On Fri, Mar 21, 2014 at 11:59 AM, Adam Back \u003cadam at cypherspace.org\u003e wrote:\n\u003e\n\u003e\u003e Maybe its time to explore raw ECDSA signed message based certs.\n\u003e\u003e\n\u003e\n\u003e If you want to create and run a new CA, by all means. But I bet you don't.\n\u003e So we're stuck with the current system for now.\n\u003e\n\u003e\n\u003e\u003e btw I dont think its quite 4kB.  eg bitpay's looks to be about 1.5kB in\n\u003e\u003e der\n\u003e\u003e format.  And they contain a 2048-bit RSA server key, and 2048-bit RSA\n\u003e\u003e signatures (256byte each right there = 512bytes).  And even 2048 is weaker\n\u003e\u003e than 256-bit ECDSA.\n\u003e\n\u003e\n\u003e But you have to chain up to the root.\n\u003e\n\u003e The only reason more certs aren't ECC is backwards compatibility. Some old\n\u003e browsers don't know how to handle them. It wasn't so long ago that Fedora\n\u003e and Android were deleting ECC code from upstream libraries before shipping\n\u003e them, either for patent reasons for disk space saving measures.\n\u003e\n\u003e But it's possible to get ECC certs if you want. For example, Entrust is\n\u003e starting to sell them:\n\u003e\n\u003e http://www.entrust.net/ecc-certs/index.htm\n\u003e\n\u003e But their intermediate cert is still RSA. My understanding is that ECC\n\u003e roots for many CA's have been submitted and are now included, but of course\n\u003e \"give up compatibility with lots of users\" vs \"save a bit of cpu time and a\n\u003e handful of bytes\" is no real competition so it will be a long time until\n\u003e most websites are using ECC certs.\n\u003e\n\u003e Regardless, it's all irrelevant. Who knows when we might want to add\n\u003e another feature that uses some bytes into PaymentRequests. Stuffing them\n\u003e into a QR code will never make much sense IMO - it's far more sensible to\n\u003e just use Bluetooth where the data size constraints are so much easier.\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140321/4938b65f/attachment.html\u003e"}
