Earlier quoted context omitted.
tbf - since we still don't know if p != np, there are still questions about if the current algorithms are secure also.
Fair, but recently several PQ algorithms have been shown to in fact not be secure, with known attacks, so I wouldn’t equate them
Cloudflare targets 2029 for full post-quantum security
31–40 of 120 posts
Re: Cloudflare targets 2029 for full post-quantum security
#32You can do PQ queries with us at qi.rt.ht! Which one do you think is PQ-secure? https://qi.rt.ht/?pq={api.,}{stripe,paypal}.com
Re: Cloudflare targets 2029 for full post-quantum security
#33Is this still theory or are there working Quantum systems that have broken anything yet?
Re: Cloudflare targets 2029 for full post-quantum security
#34Is this still theory or are there working Quantum systems that have broken anything yet?
Theory. And afaik there are still questions as to if the PQ algorithms are actually secure.
Re: Cloudflare targets 2029 for full post-quantum security
#35Earlier quoted context omitted.
tbf - since we still don't know if p != np, there are still questions about if the current algorithms are secure also.
Fair, but recently several PQ algorithms have been shown to in fact not be secure, with known attacks, so I wouldn’t equate them
Re: Cloudflare targets 2029 for full post-quantum security
#36The secrecy around this is precisely the opposite of what we saw in the 90s when it started to become clear DES needed to go. Yet another sign that the global powers are preparing for war.
What do you mean? For as long as I remember (back to late 1994) people understood DES to be inadequate; we used DES-EDE and IDEA (and later RC4) instead. What "secrecy" would there have been? The feasibility of breaking DES given a plausible budget goes all the way back to the late 1970s. The first prize given for demonstrating a DES break was only $10,000.
Re: Cloudflare targets 2029 for full post-quantum security
#37Earlier quoted context omitted.
Theory. And afaik there are still questions as to if the PQ algorithms are actually secure.
There are not in fact meaningful questions about whether the settled-on PQC constructions are secure, in the sense of "within the bounds of our current understanding of QC".
Re: Cloudflare targets 2029 for full post-quantum security
#38Earlier quoted context omitted.
There are not in fact meaningful questions about whether the settled-on PQC constructions are secure, in the sense of "within the bounds of our current understanding of QC".
Didn't one of the PQC candidates get found to have a fatal classical vulnerability? Are we confident we won't find any future oopsies like that with the current PQC candidates?
Re: Cloudflare targets 2029 for full post-quantum security
#39Re: Cloudflare targets 2029 for full post-quantum security
#40Is this still theory or are there working Quantum systems that have broken anything yet?
Filippo Valsorda (maintainer of Golang's crypto packages, among other things) published a summary yesterday [0] targeted at relative laypeople, with the same "we need to target 2029" bottom line.