Live data from Hacker News

Cloudflare targets 2029 for full post-quantum security

blog.cloudflare.com

31–40 of 120 posts

Re: Cloudflare targets 2029 for full post-quantum security

#31
post #29

Earlier quoted context omitted.

tbf - since we still don't know if p != np, there are still questions about if the current algorithms are secure also.

Fair, but recently several PQ algorithms have been shown to in fact not be secure, with known attacks, so I wouldn’t equate them

Interesting. I'd like to learn more about this - where can I find info about it?

Re: Cloudflare targets 2029 for full post-quantum security

#33
post #9

Is this still theory or are there working Quantum systems that have broken anything yet?

Among cryptography engineers there was a sharp vibe shift over the last 2 months; there are papers supporting that vibe shift, but there's also a rumor mill behind it too. The field has basically aligned fully in a way it hadn't before that this is an urgent concern. The simplest way to put it is that everyone's timeline for a real-world CRQC has shortened. Not everyone has the same timeline, but all those timelines are now shorter, and for some important (based on industry and academic position) practitioners, it's down to "imminent".

Re: Cloudflare targets 2029 for full post-quantum security

#34
post #14
post #9

Is this still theory or are there working Quantum systems that have broken anything yet?

Theory. And afaik there are still questions as to if the PQ algorithms are actually secure.

There are not in fact meaningful questions about whether the settled-on PQC constructions are secure, in the sense of "within the bounds of our current understanding of QC".

Re: Cloudflare targets 2029 for full post-quantum security

#35
post #29

Earlier quoted context omitted.

tbf - since we still don't know if p != np, there are still questions about if the current algorithms are secure also.

Fair, but recently several PQ algorithms have been shown to in fact not be secure, with known attacks, so I wouldn’t equate them

Which PQ algorithms would you be referring to here?

Re: Cloudflare targets 2029 for full post-quantum security

#36
post #4
post #2

The secrecy around this is precisely the opposite of what we saw in the 90s when it started to become clear DES needed to go. Yet another sign that the global powers are preparing for war.

What do you mean? For as long as I remember (back to late 1994) people understood DES to be inadequate; we used DES-EDE and IDEA (and later RC4) instead. What "secrecy" would there have been? The feasibility of breaking DES given a plausible budget goes all the way back to the late 1970s. The first prize given for demonstrating a DES break was only $10,000.

People were willing to explicitly explain why it was inadequate rather than keep it secret. That is the difference.

Re: Cloudflare targets 2029 for full post-quantum security

#37
post #34
post #14

Earlier quoted context omitted.

Theory. And afaik there are still questions as to if the PQ algorithms are actually secure.

There are not in fact meaningful questions about whether the settled-on PQC constructions are secure, in the sense of "within the bounds of our current understanding of QC".

Didn't one of the PQC candidates get found to have a fatal classical vulnerability? Are we confident we won't find any future oopsies like that with the current PQC candidates?

Re: Cloudflare targets 2029 for full post-quantum security

#38
post #37
post #34

Earlier quoted context omitted.

There are not in fact meaningful questions about whether the settled-on PQC constructions are secure, in the sense of "within the bounds of our current understanding of QC".

Didn't one of the PQC candidates get found to have a fatal classical vulnerability? Are we confident we won't find any future oopsies like that with the current PQC candidates?

It's the same situation with classical encryption. It's not uncommon for a candidate algorithm [to be discovered ] to be broken during the selection process.

Re: Cloudflare targets 2029 for full post-quantum security

#39
post #20
post #9

Is this still theory or are there working Quantum systems that have broken anything yet?

Nothing has been broken yet, however data can be collected now and be cracked when the time comes, hence why there is a push.

[dead]

Re: Cloudflare targets 2029 for full post-quantum security

#40
post #9

Is this still theory or are there working Quantum systems that have broken anything yet?

still theory, but there seems to be an emerging consensus that quantum systems capable of real-world attacks are closer to fruition than most people generally assumed.

Filippo Valsorda (maintainer of Golang's crypto packages, among other things) published a summary yesterday [0] targeted at relative laypeople, with the same "we need to target 2029" bottom line.

0: https://words.filippo.io/crqc-timeline/

Post reply on HN