Cloudflare targets 2029 for full post-quantum security
11–20 of 120 posts
Re: Cloudflare targets 2029 for full post-quantum security
#12Quantum computing, and the generic term 'quantum' is gearing up to be the next speculative investment hype bubble after AI, so prepare for a lot of these kinds of articles
Re: Cloudflare targets 2029 for full post-quantum security
#13And that changes what?
Re: Cloudflare targets 2029 for full post-quantum security
#14Is this still theory or are there working Quantum systems that have broken anything yet?
Re: Cloudflare targets 2029 for full post-quantum security
#15The secrecy around this is precisely the opposite of what we saw in the 90s when it started to become clear DES needed to go. Yet another sign that the global powers are preparing for war.
What do you mean? For as long as I remember (back to late 1994) people understood DES to be inadequate; we used DES-EDE and IDEA (and later RC4) instead. What "secrecy" would there have been? The feasibility of breaking DES given a plausible budget goes all the way back to the late 1970s. The first prize given for demonstrating a DES break was only $10,000.
So practically immediately after DES was standardized, people realized that NSA had crippled it by limiting the key length to 56 bits, and they started to use workarounds.
Before introducing RC2 and RC4 in 1987, Ronald Rivest had used since 1984 another method of extending the key length of DES, named DESX, which was cheaper than DES-EDE as it used a single block cipher function invocation. However, like also RC4, DESX was kept as a RSA trade secret, until it was leaked, also like RC4, during the mid nineties.
IDEA (1992, after a preliminary version was published in 1991) was the first block cipher function that was more secure than DES and which was also publicly described.
Re: Cloudflare targets 2029 for full post-quantum security
#16Which one do you think is PQ-secure?
Re: Cloudflare targets 2029 for full post-quantum security
#17Re: Cloudflare targets 2029 for full post-quantum security
#18Some browsers and some end user devices get upgraded quickly, so making it easy to make it optionally-PQ on any site, and then as that rollout extends, some specialty sites can make it mandatory, and then browser/device UX can do soft warnings to users (or other activity like downranking), and then at some point something like STS Strict can be exposed, and then largely become a default (and maybe just remove the non-PQ algorithms entirely from many sites).
I definitely was on team "the risks of a rushed upgrade might outweigh the risks of actual quantum breaks" until pretty recently -- rushing to upgrade has lots of problems always and is a great way to introduce new bugs, but based on the latest information, the balance seems to have shifted to doing an upgrade quickly.
Updating websites is going to be so much easier than dealing with other systems (bitcoin probably the worst; data at rest storage systems; hardware).
Re: Cloudflare targets 2029 for full post-quantum security
#19Is this still theory or are there working Quantum systems that have broken anything yet?
Theory. And afaik there are still questions as to if the PQ algorithms are actually secure.
Re: Cloudflare targets 2029 for full post-quantum security
#20Is this still theory or are there working Quantum systems that have broken anything yet?