<oembed><type>rich</type><version>1.0</version><author_name>npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_name><author_url>https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-03-21&#xA;📝 Original message:On Fri, Mar 21, 2014 at 11:59 AM, Adam Back &lt;adam at cypherspace.org&gt; wrote:&#xA;&#xA;&gt; Maybe its time to explore raw ECDSA signed message based certs.&#xA;&gt;&#xA;&#xA;If you want to create and run a new CA, by all means. But I bet you don&#39;t.&#xA;So we&#39;re stuck with the current system for now.&#xA;&#xA;&#xA;&gt; btw I dont think its quite 4kB.  eg bitpay&#39;s looks to be about 1.5kB in der&#xA;&gt; format.  And they contain a 2048-bit RSA server key, and 2048-bit RSA&#xA;&gt; signatures (256byte each right there = 512bytes).  And even 2048 is weaker&#xA;&gt; than 256-bit ECDSA.&#xA;&#xA;&#xA;But you have to chain up to the root.&#xA;&#xA;The only reason more certs aren&#39;t ECC is backwards compatibility. Some old&#xA;browsers don&#39;t know how to handle them. It wasn&#39;t so long ago that Fedora&#xA;and Android were deleting ECC code from upstream libraries before shipping&#xA;them, either for patent reasons for disk space saving measures.&#xA;&#xA;But it&#39;s possible to get ECC certs if you want. For example, Entrust is&#xA;starting to sell them:&#xA;&#xA;http://www.entrust.net/ecc-certs/index.htm&#xA;&#xA;But their intermediate cert is still RSA. My understanding is that ECC&#xA;roots for many CA&#39;s have been submitted and are now included, but of course&#xA;&#34;give up compatibility with lots of users&#34; vs &#34;save a bit of cpu time and a&#xA;handful of bytes&#34; is no real competition so it will be a long time until&#xA;most websites are using ECC certs.&#xA;&#xA;Regardless, it&#39;s all irrelevant. Who knows when we might want to add&#xA;another feature that uses some bytes into PaymentRequests. Stuffing them&#xA;into a QR code will never make much sense IMO - it&#39;s far more sensible to&#xA;just use Bluetooth where the data size constraints are so much easier.&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140321/a4fc4e27/attachment.html&gt;</html></oembed>