@mikaeleiman

there”s RAM and CPU on small embedded devices.

This. You can think of attesting just KDC with ML signature, likely, on some bigger silicon, but not on a half of coming cheap STM lines for example.

Time to study rfc4120 and siblings :(

@filippo

I’d like to ask whether migrating Ed25519 to Ed448 makes any sense? At least temporarily. Setting aside all that owful implementation disadvantages of Ed448.