Live data from Hacker News

Cloudflare targets 2029 for full post-quantum security

blog.cloudflare.com

81–90 of 120 posts

Re: Cloudflare targets 2029 for full post-quantum security

#81
post #78
post #42

Earlier quoted context omitted.

The whole point of the competition is to see if anybody can cryptanalyze the contestants. I think part of what's happening here is that people have put all PQC constructions in bucket, as if they shared an underlying technology or theory, so that a break in one calls all of them into question. That is in fact not at all the case. PQC is not a "kind" of cryptography. It's a functional attribute of many different kinds…

Yeah I get that, what I am really asking is that I know in my field, I can quickly get a vibe as to whether certain new work is good or not so good, and where any bugaboos are likely to be. For those who know PQC like I know economics, do they believe at this point that the algorithms have been analyzed successfully to a level comparable to DH or RSA? Or is this really gonna be a rush job under the gun because we hav…

Lattice cryptography was a contender alongside curves as a successor to RSA. It's not new. The specific lattice constructions we looked at during NIST PQC were new iterations on it, but so was Curve25519 when it was introduced. It's extremely not a rush job.

The elephant in the room in these conversations is Daniel Bernstein and the shade he has been casting on MLKEM for the last few years. The things I think you should remember about that particular elephant are (1) that he's cited SIDH as a reason to be suspicious of MLKEM, which indicates that he thinks you're an idiot, and (2) that he himself participated in the NIST PQC KEM contest with a lattice construction.

Re: Cloudflare targets 2029 for full post-quantum security

#82
Tangential question...

Seen that many are already moving to QC-resistant cryptography and that more are shifting by the day... I've got a question: what are the implications of quantum computers going to be if we consider that the entirety of cryptography will have moved to quantum-resistant cryptography?

In other words: I only ever read about quantum computing when it's to talk about breaking cryptography. But what if all cryptography moves to quantum-resistant scheme, all of it... Then what are the uses of quantum computing? Protein folding? Logistics?

Basically, so far, quantum computing research has the effect of many companies and projects adding quantum-resistant cryptographic schemes.

If, say, we've got a $10 million quantum computer that can break one 256 bit elliptic curve key in an hour... Great, EC is broken. But what if browsers, SSH, auth, etc. just about everything moves to PQ schemes...

Then what are those quantum computers useful for?

I understand that breaking even a single EC 256 bit key in a few hours on a $$$ machine is a very big deal.

But what else are they going to be useful for? For breaking ECC doesn't help humanity. It doesn't bring anything. It only destroys.

EDIT: for example I read stuff like: "Estimates are about three years to break a single 256 bit EC key on a 10 000 qbits quantum computer". What's a 10 000 qbits quantum computer going to be used for when everybody shall have moved to quantum-resistant algos?

Re: Cloudflare targets 2029 for full post-quantum security

#83
post #76

Does this mean we should be migrating our SSH keys to post-quantum crypto right now?

OpenSSH has supported post-quantum key agreement since 2022, and since 10.1 (October 2025) you'll get a warning if your connection isn't using it. It doesn't require rotating your keys, just upgrading the software on both sides.

Post-quantum signatures will require rotating your keys, but that's less urgent.

Re: Cloudflare targets 2029 for full post-quantum security

#84
Yet, the same Cloudflare wants to control entire internet traffic single-handedly.

The Internet was not created for this.

One could argue that 'but they are very good at preventing DDoS attacks' — yes they are; however, they have always loved control and kept their technology proprietary to lock their customers into their systems. And one day, a single line of code disrupted many services on the web.

Centralization and monopolies are much bigger threats to the future of the internet, IMHO. (Which always follows the same pattern: give your customers free or unbelievably cheaper services, even at a loss, lock them in, then jack up the price.)

Re: Cloudflare targets 2029 for full post-quantum security

#85

Earlier quoted context omitted.

If any kind of proof about serious quantum computers comes to light, browsers can force most websites' hand by marking non-PQ ciphers as insecure. Maybe it'll require TLS 1.4/QUIC 2, with no changes but the cipher specifications, but it can happen in two or three years. Certificates themselves don't last longer than a year anyway. Corporations running ancient software that doesn't support PQ TLS will have the same co…

No need for a TLS 1.4. Leaf certificates don't last long, but root CAs do. An attacker can just mint new certs from a broken root key. Hopefully many devices can be upgraded to PQ security with a firmware update. Worse than not receiving updates, is receiving malicious firmware updates, which you can't really prevent without upgrading to something safe first.

[deleted]

Re: Cloudflare targets 2029 for full post-quantum security

#86
post #69

Earlier quoted context omitted.

Interesting. I'd like to learn more about this - where can I find info about it?

they're almost assuredly talking about two things (maybe 3 if they really know what they're talking about, but the third is something that people making this argument like to pretend doesn't exist). 1. the main "eye catching" attack was the [attack on SIDH]( https://eprint.iacr.org/2022/975.pdf ). it was very much a "thought to be entirely secure" to "broken in 5 minutes with a Sage (python variant) implementation" w…

For whatever it's worth I think I cosign all of this.

Re: Cloudflare targets 2029 for full post-quantum security

#87
post #42
post #37

Earlier quoted context omitted.

Didn't one of the PQC candidates get found to have a fatal classical vulnerability? Are we confident we won't find any future oopsies like that with the current PQC candidates?

The whole point of the competition is to see if anybody can cryptanalyze the contestants. I think part of what's happening here is that people have put all PQC constructions in bucket, as if they shared an underlying technology or theory, so that a break in one calls all of them into question. That is in fact not at all the case. PQC is not a "kind" of cryptography. It's a functional attribute of many different kinds…

SIKE made it all the way to round 3. It failed spectacularly, but it happened rather abruptly. In one sense it wasn't surprising because of its novelty, but the actual attack was somewhat surprising--nobody was predicting it would crumble so thoroughly so quickly. Notably, the approach undergirding it is still thought secure; it was the particular details that caused it to fail.

It's hubris to say there are no questions, especially for key exchange. The general classes of mathematical problems for PQC seem robust, but that's generally not how crypto systems fail. They fail in the details, both algorithmically and in implementation gotchas.

From a security engineering perspective, there's no persuasive reason to avoid general adoption of, e.g., the NIST selections and related approaches. But when people suggest not to use hybrid schemes because the PQC selections are clearly robust on their own, well then reasonable people can disagree. Because, again, the devil is in the details.

The need to proclaim "no questions" feels more like a reaction to lay skepticism and potential FUD, for fear it will slow the adoption of PQC. But that's a social issue, and imbibing that urge may cause security engineers to let their guard down.

Re: Cloudflare targets 2029 for full post-quantum security

#88
post #53

Earlier quoted context omitted.

It's theory. The concern is for avoiding a (likely, IMO) scenario where the only real indication that someone cracked QC is one or more teams of researchers in the field going dark because they got pulled into some tight-lipped NSA project. If we wait until we have an unambiguous path to QC, it might well be too late. To avoid the scenario where for a prolonged period of time the intelligence community has secret acc…

> one or more teams of researchers in the field going dark If the intelligence community is going to nab the first team that has a quantum computing breakthrough, does it actually help the public to speed up research? It seems like an arms race the public is destined to lose because the winning team will be subsumed no matter what.

> It seems like an arms race the public is destined to lose ...

By what margin? An active push can minimize the gap.

However I think you're confusing the existence of a CRQC with adoption of PQC algorithms. The latter can be done in the absence of the former.

Re: Cloudflare targets 2029 for full post-quantum security

#89

> news.ycombinator.com:443 is using X25519, which is not post-quantum secure. This is the result of Cloudflare's test "Check if a host supports post-quantum TLS key exchange" offered on https://radar.cloudflare.com/post-quantum . Hoping there is already a migration plan. Fortunately many modern tools make it easy to switch to PQ, maybe someone knows which stack HN is running and if it would be possible.

Wow that’s a lot better browser support than expected

Re: Cloudflare targets 2029 for full post-quantum security

#90
post #81
post #78

Earlier quoted context omitted.

Yeah I get that, what I am really asking is that I know in my field, I can quickly get a vibe as to whether certain new work is good or not so good, and where any bugaboos are likely to be. For those who know PQC like I know economics, do they believe at this point that the algorithms have been analyzed successfully to a level comparable to DH or RSA? Or is this really gonna be a rush job under the gun because we hav…

Lattice cryptography was a contender alongside curves as a successor to RSA. It's not new. The specific lattice constructions we looked at during NIST PQC were new iterations on it, but so was Curve25519 when it was introduced. It's extremely not a rush job. The elephant in the room in these conversations is Daniel Bernstein and the shade he has been casting on MLKEM for the last few years. The things I think you sho…

Bernstein's ego is at a level where he thinks most other people are idiots (not without some justification), that's been clear for decades. What are you hinting at?
Post reply on HN