Cloudflare targets 2029 for full post-quantum security
91–100 of 120 posts
Re: Cloudflare targets 2029 for full post-quantum security
#92Earlier quoted context omitted.
The whole point of the competition is to see if anybody can cryptanalyze the contestants. I think part of what's happening here is that people have put all PQC constructions in bucket, as if they shared an underlying technology or theory, so that a break in one calls all of them into question. That is in fact not at all the case. PQC is not a "kind" of cryptography. It's a functional attribute of many different kinds…
SIKE made it all the way to round 3. It failed spectacularly, but it happened rather abruptly. In one sense it wasn't surprising because of its novelty, but the actual attack was somewhat surprising--nobody was predicting it would crumble so thoroughly so quickly. Notably, the approach undergirding it is still thought secure; it was the particular details that caused it to fail. It's hubris to say there are no questi…
SIKE: not lattices. Literally moon math. Do you understand how SIKE/SIDH works? It's fucking wild.
I'm going to keep saying this: you know the discussion is fully off the rails when people bring SIKE/SIDH into it as evidence against MLKEM.
Re: Cloudflare targets 2029 for full post-quantum security
#93Earlier quoted context omitted.
Interesting. I'd like to learn more about this - where can I find info about it?
they're almost assuredly talking about two things (maybe 3 if they really know what they're talking about, but the third is something that people making this argument like to pretend doesn't exist). 1. the main "eye catching" attack was the [attack on SIDH]( https://eprint.iacr.org/2022/975.pdf ). it was very much a "thought to be entirely secure" to "broken in 5 minutes with a Sage (python variant) implementation" w…
Re: Cloudflare targets 2029 for full post-quantum security
#94Earlier quoted context omitted.
they're almost assuredly talking about two things (maybe 3 if they really know what they're talking about, but the third is something that people making this argument like to pretend doesn't exist). 1. the main "eye catching" attack was the [attack on SIDH]( https://eprint.iacr.org/2022/975.pdf ). it was very much a "thought to be entirely secure" to "broken in 5 minutes with a Sage (python variant) implementation" w…
For whatever it's worth I think I cosign all of this.
Re: Cloudflare targets 2029 for full post-quantum security
#95Earlier quoted context omitted.
For whatever it's worth I think I cosign all of this.
In the context of: a green username offering some salacious/conspiratorial things about djb around a topic I'm only a little familiar with... Its worth a lot. Its the difference between me writing it off as (at best) a poorly informed misunderstanding of a complex topic, and me choosing to spend some time learning more. Ty
Re: Cloudflare targets 2029 for full post-quantum security
#96Earlier quoted context omitted.
SIKE made it all the way to round 3. It failed spectacularly, but it happened rather abruptly. In one sense it wasn't surprising because of its novelty, but the actual attack was somewhat surprising--nobody was predicting it would crumble so thoroughly so quickly. Notably, the approach undergirding it is still thought secure; it was the particular details that caused it to fail. It's hubris to say there are no questi…
What's your point? SIKE has literally nothing to do with MLKEM. There is no relationship between the algorithms. Essentially everybody working on PQC, including Bernstein himself, have converged on lattices, which, again, were a competitor to curves as a successor to RSA --- they are old . SIKE: not lattices. Literally moon math. Do you understand how SIKE/SIDH works? It's fucking wild. I'm going to keep saying this:…
DJB himself seems to prefer hybrid over non-hybrid precisely over concern about the unknowns: https://blog.cr.yp.to/20260219-obaa.html
These doubts may not be the kind curious onlookers have in mind, but to say there are no doubts among researchers and practitioners is a misrepresentation. In fact, you're flatly contradicting what DJB has said on the matter:
> SIKE is not an isolated example: https://cr.yp.to/papers.html#qrcsp shows that 48% of the 69 round-1 submissions to the NIST competition have been broken by now.
https://archive.cr.yp.to/2026-02-21/18:04:14/o2UJA4Um1j0ursy...
Unqualified assurances is what you hear from a salesman. You're trying to sell people on PQC. There's no reason to believe ML-KEM is a lemon, but you're effectively saying, "it's the last KEX scheme we'll ever need", and that's just not honest from an engineering point of view, even if it's what people need to hear.
Re: Cloudflare targets 2029 for full post-quantum security
#97Earlier quoted context omitted.
In the context of: a green username offering some salacious/conspiratorial things about djb around a topic I'm only a little familiar with... Its worth a lot. Its the difference between me writing it off as (at best) a poorly informed misunderstanding of a complex topic, and me choosing to spend some time learning more. Ty
None of this is really salacious or conspiratorial. I don't know how big a deal the attacks they're citing are. But this is directionally mostly stuff I've heard from lots of cryptography engineers over the last couple years. I know the comment is off comparing attacks on classical NTRU to SNTRUP though!
> anyway, someone popular among some people in tech (the cryptographer Dan Bernstein) has been trying (successfully) to slow the PQC transition for ~10 years
Sounds enough like throwing shade to make me doubt it's value, in absence of other signals.
My point was your history of posting knowledgeably about security and cryptography provides the credibility for me to go do more reading about the stuff in mswphd's post.
Re: Cloudflare targets 2029 for full post-quantum security
#98Earlier quoted context omitted.
None of this is really salacious or conspiratorial. I don't know how big a deal the attacks they're citing are. But this is directionally mostly stuff I've heard from lots of cryptography engineers over the last couple years. I know the comment is off comparing attacks on classical NTRU to SNTRUP though!
As someone way out of the loop on pqc, this bit: > anyway, someone popular among some people in tech (the cryptographer Dan Bernstein) has been trying (successfully) to slow the PQC transition for ~10 years Sounds enough like throwing shade to make me doubt it's value, in absence of other signals. My point was your history of posting knowledgeably about security and cryptography provides the credibility for me to go…
Re: Cloudflare targets 2029 for full post-quantum security
#99Is this still theory or are there working Quantum systems that have broken anything yet?
Re: Cloudflare targets 2029 for full post-quantum security
#100Earlier quoted context omitted.
What's your point? SIKE has literally nothing to do with MLKEM. There is no relationship between the algorithms. Essentially everybody working on PQC, including Bernstein himself, have converged on lattices, which, again, were a competitor to curves as a successor to RSA --- they are old . SIKE: not lattices. Literally moon math. Do you understand how SIKE/SIDH works? It's fucking wild. I'm going to keep saying this:…
You may not have any questions about the security of ML-KEM, but many people do . See, for example, DJB's compilation of such doubts from the IETF WG: https://blog.cr.yp.to/20260221-structure.html DJB himself seems to prefer hybrid over non-hybrid precisely over concern about the unknowns: https://blog.cr.yp.to/20260219-obaa.html These doubts may not be the kind curious onlookers have in mind, but to say there are no…
And, if we're on the subject of how trustworthy Bernstein's concerns are, I'll note again: in his own writing about the potential frailty of MLKEM, he cites SIKE, because, again, he thinks you're too dumb to understand the difference between a module lattice and a generic lattice.
Finally, I'm going to keep saying this until I don't have to say it anymore: PQC is not a "kind" of cryptography. It doesn't mean anything that N% of the Round 1 submissions to the NIST PQC Contest were cryptanalyzed. Multivariate quadratic equation cryptography, supersingular isogeny cryptography, and F_2^128 code-based cryptography are not related to each other. The point of the contest was for that to happen.