Live data from Hacker News

Ask HN: TLS 1.3 and Post-Quantum Encryption for HN?

news.ycombinator.com

11–13 of 13 posts

Re: Ask HN: TLS 1.3 and Post-Quantum Encryption for HN?

#11
post #10

Earlier quoted context omitted.

lol. Maybe so! :).. but is NIST? Is Cloudflare? Is Google/Apple? Worth a read: https://blog.cloudflare.com/nists-first-post-quantum-standar... Google: https://cloud.google.com/security/resources/post-quantum-cry... Various interesting Cloudflare blog posts here: https://blog.cloudflare.com/tag/post-quantum/

Practical QC is like nuclear fusion. People have been saying we're only a couple decades away for decades. And yes, we have made a lot of progress, but no one really knows for sure how far off we are. There might be a huge breakthrough within a couple years, or progress might stall for decades. I think that it is absolutely worth researching post quantum cryptography, and if you are a high value target, maybe even us…

During a Google podcast below[1] a host (reportedly with a PhD in Quantum Mechanics) expressed a similar opinion as you at first, then started to take the threat more seriously as he heard from an experienced Google colleague.. This was in 2024 before the Google Willow announcement[2]. Thank you for your thoughtful response!

1. https://cloud.withgoogle.com/cloudsecurity/podcast/ep164-qua...

2. https://blog.google/technology/research/google-willow-quantu...

Re: Ask HN: TLS 1.3 and Post-Quantum Encryption for HN?

#12
post #5

Earlier quoted context omitted.

The people who will act are the let's encrypt people, in how they select algorithms for the CA chain. I wouldn't expect this site to have to do very much but I would expect to see some public communications from letsencrypt. Which, I am not seeing. Hence some evidence to back my pqc scepticism. https://community.letsencrypt.org/t/preparing-for-quantum-sa... Like I said, more frequent certificate reissuance probably c…

Let’s Encrypt is focusing on other concerns next year but noted that donations are what funds their ability to progress: https://letsencrypt.org/2024/12/11/eoy-letter-2024/ As with any donation-supported venture, their ability to consider “someday” concerns is directly tied to donations and sponsorships. Reading between the lines of the recent revocation shutdown, I estimate their operating budget does not have room…

What is addressed recently by NIST, Cloudflare, Google, Apple, and others primarily involves potential(?) weaknesses in TLS key exchange & asymmetric cryptography. Let's Encrypt is more about certificates, I think, no?

Re: Ask HN: TLS 1.3 and Post-Quantum Encryption for HN?

#13

Earlier quoted context omitted.

Let’s Encrypt is focusing on other concerns next year but noted that donations are what funds their ability to progress: https://letsencrypt.org/2024/12/11/eoy-letter-2024/ As with any donation-supported venture, their ability to consider “someday” concerns is directly tied to donations and sponsorships. Reading between the lines of the recent revocation shutdown, I estimate their operating budget does not have room…

What is addressed recently by NIST, Cloudflare, Google, Apple, and others primarily involves potential(?) weaknesses in TLS key exchange & asymmetric cryptography. Let's Encrypt is more about certificates, I think, no?

The cert gives assurance the right endpoint has been reached to bootstrap tls. So arguably its part of the attack surface. The tls key exchange may not have direct dependency but it has some indirect? Clearly the on the wire pki used to establish emphemeral session keys would be the main issue and that is down to the webserver and browser not letsencrypt.
Post reply on HN