Bas Westerbaan

@bwesterb.bsky.social

post quantum @cloudflare

I'm seeing folks draw the wrong conclusion (in good faith or not) from the HAWK attack. HAWK is a scheme that 1. cryptographers were suspicious of and 2. was still in the assessment process. A break is GOOD. It means the process is useful, and it INCREASES confidence in the selected algorithms.

Every year we write about the exciting developments in post-quantum signatures. Last year didn't disappoint. But it's too late. As ekr wrote in 2024 "You go to war with the algorithms you have, not the ones you wish you had." ML-DSA will have to do for now. blog.cloudflare.com/ml-dsa-will-...

Why we cannot wait for better post-quantum signature algorithms

NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and sh...

blog.cloudflare.com

There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.

words.filippo.io

Last year, I thought we still had time to design PQ auth systems. Now, based on the pace of progress and on statements like Google's, I believe 1. we need to finish rolling out PQ kex yesterday 2. we need to start rolling out PQ auth now 3. it's too late to ship any new non-PQ design or system

Quantum frontiers may be closer than they appear

An overview of how Google is accelerating its timeline for post-quantum cryptography migration.

blog.google

"Lack of scalability is enough for us to disqualify QKD outright: if a technology can’t bring security to the whole Internet, we’re not going to spend much time on it." Quantum Key Distribution (as opposed to post-quantum cryptography) has many problems, but this succinctly captures the core issue.

You don’t need quantum hardware for post-quantum security

Post-quantum cryptography protects against quantum threats using today’s hardware. Quantum tech like QKD may sound appealing, but it isn’t necessary or sufficient to secure organizations.

blog.cloudflare.com