[curves] Comparing high-speed / high-security curve implementations

Ben Smith hyperelliptic at gmail.com
Wed Apr 23 13:05:04 PDT 2014

2014-04-23 21:48 GMT+02:00 Trevor Perrin <trevp at trevp.net>:
> I'm not sure I'm comparing apples-to-apples anymore (GLS curves?

GLS curves are nice.  They lack twist-security (by construction)
though, which is relevant in the context of ECDH implementations.

[1] http://safecurves.cr.yp.to/twist.html


You know we all became mathematicians for the same reason: we were lazy.
  --Max Rosenlicht

More information about the Curves mailing list