NSA used to push pretty hard for moving to elliptic curve from RSA. There was some speculation they already knew better factoring methods that worked for breaking RSA.
But then the Dual_EC_DRBG backdoor came to light, so maybe they were just pushing elliptic curve to get their backdoors out there.
These days NSA pushes for post-quantum crypto, but it's not practical yet.
> NSA used to push pretty hard for moving to elliptic curve from RSA. There was some speculation they already knew better factoring methods that worked for breaking RSA.
Just to add a bit more detail...
NSA was pushing EC pretty hard for a bit. Then, after a while, they switched gears and said (and I'm paraphrasing here, obviously), "Actually, don't worry about it. If you've already switched to EC, that's fine, just stick with it. If you're still on RSA, though, just stick with that. There's no need to switch, both are fine (for the time being)."
So who knows WTF they were thinking. Unfortunately, it's impossible to get any real "signal" from their statements since they can no longer be trusted. They could be legitimately looking out for our best interests or they could be trying to get everyone to use less secure algorithms -- and we have no way to know which it is!
(Personally, I've just carried on normally and pretended like they never said anything at all).
You should avoid attempting RSA key exchange because it's too hard to safely do this correctly and even if you do that loses forward secrecy in protocols where that means something.
If you're just doing signatures (so e.g. modern TLS or SSH) then any of the elliptic curve signature schemes are nicer than RSA. However, whether that's practical for you to rely on will depend on whether it's important to let random peers from the public Internet connect with whatever mouldy garbage they're running which may only do RSA.
I still need to be convinced that more than 2048 bit RSA keys are required. There seems to be no rational reason to use longer keys.
There have been no real breakthroughs in breaking RSA for 15-20 years. So if you were playing the odds you would actually prefer RSA over systems invented more recently.