#pqc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.
-
@malb thanks for reporting, I feel I'm aging faster whenever results like this appear.
Now, how about https://eprint.iacr.org/2026/1630 ? Sigh...
-
The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. Justin Drake called it the end of an eight year, eight figure rabbit hole. I tried to understand what actually happened, and the short version is that nobody broke anything.
The Foundation paused its $992,000 Poseidon1 collision prize on August 1, twelve days before the announcement. Two years of funded cryptanalysis, roughly $1.36M in announced ceilings, produced exactly what such programs should. Reduced-round results, a partial collision tier claimed in April, and no break on any parameter set that matters.
What changed was the proving side. Binius at EUROCRYPT 2025 and then Flock this June made bit-oriented hashes cheap inside binary-field SNARKs. Flock proves 660k+ BLAKE3 compressions per second on ten M4 Max cores at under 250x native cost. Poseidon existed to make hashing affordable in prime-field circuits, and that problem dissolved.
Two details the coverage missed. Buterin publicly refused a Poseidon precompile in February. The program had found Poseidon2 issues needing extra rounds or a reversion to Poseidon1, and enshrining one version meant a dangling precompile forever. And Anthropic's July release, the one that broke HAWK, also pointed Mythos at Poseidon and got under 10x, a mildly reassuring data point almost nobody registered.
For this audience the RC4 parallel will make sense. AES-NI shipped in 2010, RC4 hung on through BEAST era workarounds, and RFC 7465 only killed it in 2015. Same shape here, except Ethereum's dependency was still in a research roadmap instead of a billion endpoints. The rest of us have the harder version.
Full analysis, including the four things the announcement doesn't say and the caveat that the binary-field provers doing this are young software. Full analysis:
https://postquantum.com/security-pqc/ethereum-roadmap-drops-poseidon/
-
Cryptanalysts are using AI models now, openly and on live claims. So what does "independently confirmed" mean? Less than it meant two years ago, and two events this summer show why.
April 2024 is the baseline. Yilei Chen posted a claimed polynomial-time quantum algorithm for LWE on the first day of the NIST PQC Standardization Conference. Eight days later he withdrew it, with an acknowledgment thanking Hongxun Wu and, independently, Thomas Vidick for finding the bug in Step 9. That parenthetical is the whole quality control mechanism of the field. Two experts, reasoning separately, converged on the same defect. Neither had seen the other's reading.
July 23, 2026. Ananth and Sahai at UCSB and UCLA posted a proof of efficient unclonable encryption at 10:35 Pacific. Seyoon Ragavan at MIT posted the same result three hours and eighteen minutes later. Both credited GPT-5.6 Sol Ultra with the core ideas. Both traced to the same Simons Institute talk. Neither knew the other was working on it. Ragavan drove the model in supervised two-hour stretches; Ananth and Sahai used a self-critiquing UCLA harness. Two workflows about as different as two workflows get, one construction, one working day.
August 2026. Daniel Simon's claimed polynomial-time algorithm for the Dihedral Coset Problem is being adjudicated right now on ePrint and Discord, in days rather than months, with Bernstein and Kirshanova among the people reading it. Several of the substantive responses were produced by humans working with models. One lists two language models on its byline. Disclosure across the documents is uneven: some name the model and version, some say only "AI assistance."
The mechanism cryptanalysis depends on is not expertise. It is decorrelated failure. Two humans with similar training still make different mistakes, at different points, for different reasons, and their errors decorrelate even when their education does not. The risk with shared tooling is not sampling correlation. It is common-cause error, where shared weights, training data, post-training and retrieval reproduce the same blind spot across operators who have no way of noticing they share it.
I am not claiming three model-assisted reviews reduce to one. I am claiming we currently lack the provenance to know how much independent weight they deserve.
The fix is cheap. Every cryptanalysis note that circulates before peer review should end with two sections: who found what, and what was checked by whom, with what, and how hard. Ragavan's paper already does most of it, and ships a Lean 4 formalization that states which claims it does not cover. A kernel shares no weights with anything.
IACR has barred models from bylines since May 2025. That rule governs formal submission. It does not reach the circulating notes where Simon is actually being adjudicated.
(This post was edited by AI, but the points are mine. If anyone else wrote the same thing around the same time, blame it on ChatGPT)
https://postquantum.com/post-quantum/independence-problem-ai-cryptanalysis/
#infosec #cryptography #cryptanalysis #PQC #postquantum #formalmethods
-
TechAptitude brings you the weekly "Weekend Reading".
NIST is playing a central role in building standards for Quantum Computing and in this post we review the current status of NIST's efforts and their recent release of the first 3 standards. Enjoy, and please tell your friends to check this post out, and visit TechAptitude here: https://techaptitude.substack.com/
https://techaptitude.substack.com/p/quantum-technologies-nist-drives #NIST #Quantum #QuantumComputing #Standards #FIPS203 #FIPS204 #FIPS205 #PQC
-
With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.
Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.
Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.
The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:
- Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?
- Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?
- Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?
- Why would a European buyer accept "we cannot comment" as a tender answer?
- Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?
- Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?
- Why would an allied service share access with a partner whose contractors may be on the same box?
- How does a US prosecutor explain the next indictment of a Chinese contractor hacker?
- What does Washington say when Beijing runs the same program and calls it law enforcement?
Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.
https://postquantum.com/cyber-kinetic-security/cyber-privateers-what-breaks/
#Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC
-
CW: llm producing genuinely impressive cryptographic result
I was looking at the NIST-competition for further signatures at work today and noticed that HAWK has been withdrawn...
(Context: NIST wasn't exactly enthusiastic about any signature scheme in the previous pqc competition and started a new one that is now in round three with only a few schemes left. HAWK was the only remaining lattice based scheme with the claim to fame being that it is basically FALCON (in standardization by NIST as FN-DSA) without the need for floating point arithmetic.)
Now it turns out that Anthropic has an LLM that managed to find a severe enough attack to require enough of an adjustment to the parameters, that HAWK would become noncompetitive.
This was genuinely new, clearly found by AI, on a very high profile target that lots of humans actively tried to break unsuccessfully, and clearly important that it was found...
They also managed to improve the cryptanalysis on a round reduced version of AES, another VERY impressive feat!
There is a genuine argument now that AI is competitive with the best human cryptanalysts and I am not yet sure what to make of that... 😐
#crypto #cryptography #pqc -
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
El lado del mal - Claude Mythos Preview debilita los algoritmos criptográficos PQC HAWK y AES con nuevos ataques https://www.elladodelmal.com/2026/08/claude-mythos-preview-debilita-los.html #Criptografía #PQC #Hawk #Mythos #Claude #AES #IA #AI #Criptoanalisis
-
Oracle's plans for backporting PQC algorithms (ML-DSA and ML-KEM) and TLS 1.3 Post-Quantum Hybrid Key Exchange to current LTS JDK releases:
https://blogs.oracle.com/java/post-quantum-cryptography-in-long-term-support-jdk-releases
-
We published our #PQC roadmap for #GoogleCloud aiming for an ambitious 2029 completion timeline. It’s been quite a ride to get commitments from product teams all over the organization to become quantum safe by 2029. https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap
-
Sí señor!
Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!
Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!
Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu
Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)
-
Viele Unternehmen unterschätzen #PQC. Die EU erwartet bis 2026 Migrationspläne – Umsetzung bis 2030/2035. Das ist kein Forschungsthema mehr, sondern Governance.
Sebastian Hempel analysiert, was konkret zu tun ist: https://javapro.io/de/pqc-es-ist-zeit-zu-handeln/
#Compliance #CyberSecurity @Cloudflare
-
This Week in Security: Claude Gets Hacking, Hotel WiFi, and NPM Compromised Again
-
Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.
Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.
Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.
But this is the third event this summer hitting PQC from a different angle.
Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.
Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.
And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.
Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.
If the lesson were just "lattice math is fragile," one event would suffice.
The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.
SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.
Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:
https://postquantum.com/security-pqc/simon-quantum-algorithm-lattice-pqc/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility
-
Uh-oh... https://eprint.iacr.org/2026/1591
Potentially worrying. Has anyone looked into it already?
#cryptography #pqc #crypto #quantum #quantsec #postquantum #lattice
-
How to read a quantum vendor's fidelity claim: demand the protocol (RB, XEB, and GST measure different things), the median rather than the hero pair, simultaneous operation, the readout/SPAM/leakage figures alongside the gate number, and the duration it held. Five answers is engineering; one is a press release. Full methodology plus mid-2026 numbers for every modality: https://postquantum.com/quantum-computing/fidelity-quantum-computing/ #infosec #quantum #PQC #benchmarking
-
Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.
https://postquantum.com/security-pqc/mas-quantum-resilience-supervisory-expectations/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore
-
For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.
TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.
The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.
TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.
Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.
My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:
https://postquantum.com/security-pqc/trustasia-mtc-chrome-test-root/
#infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.
UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.
IBM packaged three evidence levels as one.
https://postquantum.com/industry-news/ibm-three-quantum-advantage-papers/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM
-
A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).
The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.
Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.
The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.
For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.
The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.
Full analysis: https://postquantum.com/industry-news/universal-topological-gates-anyons/
#quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological
-
DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.
Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.
Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.
https://postquantum.com/security-pqc/digicert-quantum-readiness-outlook-2026/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography
-
Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ?
Until now, I haven’t.
-
HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.
The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.
The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.
FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.
What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.
Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.
Full analysis: https://postquantum.com/security-pqc/hkma-banks-quantum-readiness-2-3/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA