Live data from Hacker News

Cloudflare targets 2029 for full post-quantum security

blog.cloudflare.com

41–50 of 120 posts

Re: Cloudflare targets 2029 for full post-quantum security

#42
post #37
post #34

Earlier quoted context omitted.

There are not in fact meaningful questions about whether the settled-on PQC constructions are secure, in the sense of "within the bounds of our current understanding of QC".

Didn't one of the PQC candidates get found to have a fatal classical vulnerability? Are we confident we won't find any future oopsies like that with the current PQC candidates?

The whole point of the competition is to see if anybody can cryptanalyze the contestants. I think part of what's happening here is that people have put all PQC constructions in bucket, as if they shared an underlying technology or theory, so that a break in one calls all of them into question. That is in fact not at all the case. PQC is not a "kind" of cryptography. It's a functional attribute of many different kinds of cryptography.

The algorithm everyone tends to be thinking of when they bring this up has literally nothing to do with any cryptography used anywhere ever; it was wildly novel, and it was interesting only because it (1) had really nice ergonomics and (2) failed spectacularly.

Re: Cloudflare targets 2029 for full post-quantum security

#43

[flagged]

https://news.ycombinator.com/item?id=47677483

I noticed this, too. valeriozen, can you explain what happened here?

Context, two nearly identical comments from different users.

hackerman70000 at 16:09 https://news.ycombinator.com/item?id=47677483 :

> Cloudflare pushing PQ by default is probably the single most impactful thing that can happen for adotpion. Most developers will never voluntarily migrate their TLS config. Making it the default at the CDN layer means millions of sites get upgraded without anyone making a decision

valeriozen at 16:17 https://news.ycombinator.com/item?id=47677615 :

> cloudflare making pq the default is the only way we get real adoption. most devs are never going to mess with their tls settings unless they absolutely have to. having it happen at the cdn level is the perfect silent upgrade for millions of sites without the owners needing to do anything

Re: Cloudflare targets 2029 for full post-quantum security

#44
post #36
post #4

Earlier quoted context omitted.

What do you mean? For as long as I remember (back to late 1994) people understood DES to be inadequate; we used DES-EDE and IDEA (and later RC4) instead. What "secrecy" would there have been? The feasibility of breaking DES given a plausible budget goes all the way back to the late 1970s. The first prize given for demonstrating a DES break was only $10,000.

People were willing to explicitly explain why it was inadequate rather than keep it secret. That is the difference.

What was to explain? It had a 56-bit key.

Re: Cloudflare targets 2029 for full post-quantum security

#45
> news.ycombinator.com:443 is using X25519, which is not post-quantum secure.

This is the result of Cloudflare's test "Check if a host supports post-quantum TLS key exchange" offered on https://radar.cloudflare.com/post-quantum.

Hoping there is already a migration plan. Fortunately many modern tools make it easy to switch to PQ, maybe someone knows which stack HN is running and if it would be possible.

Re: Cloudflare targets 2029 for full post-quantum security

#46
post #10

Earlier quoted context omitted.

What is "it" that you're referring to?

> mitigating harvest-now/decrypt-later attacks. Most likely the NSA or someone else is ahead of the game and already has a quantum computer. If the tech news rumors are to true the NSA has a facility in Utah that can gather large swaths of the internet and process the data.

This?: https://nsa.gov1.info/utah-data-center/

Re: Cloudflare targets 2029 for full post-quantum security

#49
post #2

The secrecy around this is precisely the opposite of what we saw in the 90s when it started to become clear DES needed to go. Yet another sign that the global powers are preparing for war.

My read of the recent google blog post is that they framed it as cryptocurrency related stuff just so they don't say the silent thing out loud. But lots of people "in the know" / working on this are taking it much more seriously than just cryptobros go broke. So my hunch is that there's more to it and they didn't want to say it / couldn't / weren't allowed to.

I will bring this up at the next meeting of the secret cryptographer cabal where we decide what information to reveal to non-cryptographers.
Post reply on HN