Cipher Preferences Ignored for Kyber keys?

Jakob Bohm jb-gnumlists at wisemo.com
Tue Jul 28 13:37:45 CEST 2026


On 27/07/2026 19:56, Robert J. Hansen via Gnupg-users wrote:
>> Elgamal signatures were added because ... I am unaware of the case for
>> including these. It was widely regarded as a mistake.
> Patent claims and fear of NSA-designed algorithms, that was the drive
> for Elgamal signatures, now I remember. Sorry for the oversight.
Also, El Gamal's DH-based signature algorithm was an independently
designed predecessor of DSA,specifically because: 1. The DSA
simplification to reduce some fields to the hash size (notnecessarily
160 bits!) was a later optimization of ElGamal by NSA.  2. The RSA
security conjecture had not yet accumulated enough evidence to be
trusted, specifically there was no hard evidencethat breaking an RSA
key was as NP-hard as the discrete logarithm problem.

>> And Ukrainian. DSTU-7456.
> DSTU-7564, sorry. Commonly called Kupyna/Купина outside of government
> service, I think.
>
For long term security, having at least two sets of up to date algorithms
is considered good practice because attacks always get stronger, never
weaker (except of cause the cost of hardware, which is now increasing).

Enjoy

Jakob
-- 
Jakob Bohm, CIO, Partner, WiseMo A/S.  https://www.wisemo.com
Transformervej 29, 2860 Søborg, Denmark.  Direct +45 31 13 16 10
This public discussion message is non-binding and may contain errors.
WiseMo - Remote Service Management for PCs, Phones and Embedded




More information about the Gnupg-users mailing list