RSA is dead: Why you should migrate to elliptic curve cryptography today
I still see RSA keys everywhere. On servers I get handed to audit, in CI pipelines, in authorized_keys files that have not been touched since 2018. People generate RSA-4096 keys and feel good about it. "Four thousand and ninety six bits," they tell themselves, "that should be enough."
It is not enough. Or rather, it is enough security-wise for now, but it is the wrong algorithm entirely. Elliptic curve cryptography does everything RSA does, with smaller keys, faster operations, and better security per bit. There is no good reason to generate an RSA key in 2026.