Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The signatures may be small (344 bits) but the keys are huge (tens to hundreds of kilobytes).


By itself that's a good trade if you need vastly more signatures than keys. I can imagine package management tools would accept much larger keys (maybe you have a dozen keys total in use at any time) for smaller signatures (every single package and metadata update needs signing).

Of course other factors may dominate anyway.


Big keys have significant practical consequences. You cannot distribute them as QR codes, for example.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: