Here's something counterintuitive to non-practitioners: curve P-521 is often less secure in practice than curve P-256.

The latter is more popular, and so better tested. The risk of implementation bugs dwarfs the risk of partial cryptanalysis of ECC, so picking P-521 optimizes for the wrong thing.

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://abyssdomain.expert/users/filippo/statuses/114433800777057700 on your instance and quote it. (Note that quoting is not supported in Mastodon.)