Give how quickly quantum is potentially coming, I wonder if we should/could find some way of using multiple quantum-resistant algorithms simultaneously as a default, in case a fault is found after the limited time we have to verify that there are no faults. Also - should we not be switching over to these algorithms starting like... now? Am I wrong that anyone collecting https traffic now will be able to break it in t…
NIST selects HQC as fifth algorithm for post-quantum encryption
111–120 of 126 posts
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#112Give how quickly quantum is potentially coming, I wonder if we should/could find some way of using multiple quantum-resistant algorithms simultaneously as a default, in case a fault is found after the limited time we have to verify that there are no faults. Also - should we not be switching over to these algorithms starting like... now? Am I wrong that anyone collecting https traffic now will be able to break it in t…
It's not clear whether NIST's recommendations are influenced by their relationship with the NSA (who would have an incentive to pressure NIST to recommend an algorithm which they--and hopefully they alone--can break). So perhaps the reasonable move is to use only one NIST-recommended algorithm and have the other layer be one that they do not recommend.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#113Earlier quoted context omitted.
I agree with you based on my following QC that we're still pretty far away from QC attacks on current crypto. The problem is, this sort of question suffers from a lot of unknown unknowns. How confident are you that we don't see crypto broken by QC in the next 10 years? The next 20? Whatever your confidence, the answer is probably "not confident enough" because the costs of that prediction being wrong are incalculable…
You don’t need any QC attacks if you can far easier find exploits in the same top10 vulns that were used 20 years ago… Industry should first address that very real and serious risk that is present _right now_ before thinking about QC.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#114Earlier quoted context omitted.
It's a mistake to conflate cryptography, with application logic errors. Your argument is akin to, > The problem is that a lot of physicians concentrate on diabetes, or hypertension, when there's people who have been stabed, or shot. Constantly hearing about how heart disease is a big problem is tiring to be honest. Also, I'm not sure what circles you run in, but if you had to ask any of my security friends if they wa…
> any of my security friends if they wanted to spend time on … quantum I commend your friends but many people in these HN threads seem to be ready to implement post-quantum encryption right now to protect against some future threats. > you meant having the qbits to deploy such an attack, right Yes - last time I checked it was like 3 stable qbits. It’s just so far off from being a reality i really can’t take that rese…
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#115Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#116Give how quickly quantum is potentially coming, I wonder if we should/could find some way of using multiple quantum-resistant algorithms simultaneously as a default, in case a fault is found after the limited time we have to verify that there are no faults. Also - should we not be switching over to these algorithms starting like... now? Am I wrong that anyone collecting https traffic now will be able to break it in t…
Correct, KEM's should be replaced ASAP since they are currently vulnerable to store-now-decrypt-later attacks. Digital signature algorithms are less urgent but considering how long it takes to roll out new cryptography standards, they should be preferred for any new designs. That said, the new PQC signatures are much larger than the current 32 byte ed25519 signatures that are most common, and that could end up being…
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#117Earlier quoted context omitted.
Do not! Use a combiner / KDF.
Curious why this is being downvoted.
But the way it was posted is so inappropriately aggressive that I think people were downvoting based on tone alone.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#118Earlier quoted context omitted.
You think someone is going to pretend to be Chris Peikert and submit a backdoored construction as him, and that's going to work? This is the problem with all these modern NIST contest theories. They're not even movie plots. Your last bit, about them paying someone like Peikert off, isn't even coherent; they could do that with or without the contest.
> they could do that with or without the contest Then why does the contest give you any more confidence that the selection isn't backdoored?
People on threads like these are pretending NIST was a shadowy force making secret determinations, but the whole thing happens in the open, and NIST is essentially just proctoring.
A lot of this kind of thing is just people telling on themselves that they don't follow the field and don't trust any cryptography not done by one of the three cryptographers they've ever heard of.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#119Earlier quoted context omitted.
You don’t need any QC attacks if you can far easier find exploits in the same top10 vulns that were used 20 years ago… Industry should first address that very real and serious risk that is present _right now_ before thinking about QC.
It's a fallacy that multiple companies and governments need to be working on one thing at a time. We absolutely should be patching current vulnerabilities and implementing quantum-safe cryptography. There's no conflict between these goals.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#120Don't get me wrong, it's good to be prepared, but what are the chances we'll need these algorithms by 2050?
There are many secrets created 25 years ago that need to be secure now; think of national security secrets.
The C in CNSA 2.0 is for "Commercial".