Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Alexandre Dulaunoy
Alexandre Dulaunoy
@adulau@infosec.exchange  ·  activity timestamp 2 months ago

I think the best summary until now about Post-quantum cryptography is from Peter Gutmann in the cryptography mailing-list.

Given that after 20 years and hundreds of millions of dollars spent researchers have yet to demonstrate a single legitimate cryptanalysis result using a quantum physics experiment, it's a bit like arguing over which brand of unicorn repellent is the most cromulent.

The current state of things in terms of pure vs. hybrid systems seems to be:

- Governments = Pure: “We’re putting all our eggs in one basket and hoping that the dial stops spinning at ‘not broken’”

- Everyone else = Hybrid: “We trust this new stuff so little that we’re requiring you use the crypto that we claim is broken alongside it”

Peter.

#cryptography #pq #postquantum #postquantumcryptography

https://www.metzdowd.com/pipermail/cryptography/2025-October/039129.html

iang via cryptography <cryptography at metzdowd.com> quotes:

>The problem in a nutshell. Surveillance agency NSA and its partner GCHQ are
>trying to have standards—development organizations endorse weakening ECC+PQ
>down to just PQ.

Given that after 20 years and hundreds of millions of dollars spent
researchers have yet to demonstrate a single legitimate cryptanalysis result
using a quantum physics experiment, it's a bit like arguing over which brand
of unicorn repellent is the most cromulent.

The current state of things in terms of pure vs. hybrid systems seems to be:
Governments = Pure: “We're putting all our eggs in one basket and hoping that
the dial stops spinning at ‘not broken’”

Everyone else = Hybrid: “We trust this new stuff so little that we're
requiring you use the crypto that we claim is broken alongside it”

Peter.
iang via cryptography <cryptography at metzdowd.com> quotes: >The problem in a nutshell. Surveillance agency NSA and its partner GCHQ are >trying to have standards—development organizations endorse weakening ECC+PQ >down to just PQ. Given that after 20 years and hundreds of millions of dollars spent researchers have yet to demonstrate a single legitimate cryptanalysis result using a quantum physics experiment, it's a bit like arguing over which brand of unicorn repellent is the most cromulent. The current state of things in terms of pure vs. hybrid systems seems to be: Governments = Pure: “We're putting all our eggs in one basket and hoping that the dial stops spinning at ‘not broken’” Everyone else = Hybrid: “We trust this new stuff so little that we're requiring you use the crypto that we claim is broken alongside it” Peter.
iang via cryptography <cryptography at metzdowd.com> quotes: >The problem in a nutshell. Surveillance agency NSA and its partner GCHQ are >trying to have standards—development organizations endorse weakening ECC+PQ >down to just PQ. Given that after 20 years and hundreds of millions of dollars spent researchers have yet to demonstrate a single legitimate cryptanalysis result using a quantum physics experiment, it's a bit like arguing over which brand of unicorn repellent is the most cromulent. The current state of things in terms of pure vs. hybrid systems seems to be: Governments = Pure: “We're putting all our eggs in one basket and hoping that the dial stops spinning at ‘not broken’” Everyone else = Hybrid: “We trust this new stuff so little that we're requiring you use the crypto that we claim is broken alongside it” Peter.

[Cryptography] NSA up to their old tricks - stuffing the IETF WGs with their supporters for weakened standards

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct