home.social

#pqc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.

fetched live
  1. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  2. I've used GSMA material in telco consulting for decades. And in my previous roles as telco CTO and CISO. So when the GSMA Foundry published a Quantum Computing Implementation Playbook for operators in July, I downloaded it the same day and expected to write a short, positive piece about it.

    Instead I spent three weeks deciding whether to take it apart in public, and then did.

    Here is the short version. Figure 2 stars telecom for highest near-term impact citing McKinsey. McKinsey puts it at lowest near-term value tier.

    Figure 14 is a vendor roadmap table with three consecutive rows labelled IBM. Row two describes Google's Willow and Quantum Echoes. Row three describes Rigetti's Ankaa-3.

    And so on.

    The security angle is footnote 7 on page 9, where PQC and the quantum threat go "not within the scope." GSMA Intelligence's own operator survey puts network security first among quantum priorities, ahead of network efficiency.

    On methodology, Section 5 is genuinely good, and it defines five evaluation dimensions, names scalability as the most informative signal in the NISQ era, and tells operators to benchmark against the strongest realistic classical alternative. Section 6 then presents four validated use cases and three of them without the classical alternative comparison.

    The document is vendor-contributed, vendor-evidenced, vendor-benchmarked, and commercially downstream of a 16-week programme the same vendor runs. That isn't the problem. The problem is the GSMA badge and the fact that operators will quote it in board papers because GSMA said so.

    Full review with page numbers for both PDFs, so you can check me. postquantum.com/quantum-comput

    #infosec #quantum #PQC #postquantum #telecom #cryptography #GSMA

  3. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity

  4. Next generation e-mail with PQC built in, how?

    Because I'm always thinking about designing and building a newer, better e-mail system, I was looking at how Proton and Tuta do their encryption.

    I thought they had both developed something new, but it turns out that what Proton calls "zero-access encryption", is exactly the same as what I implemented at work, 25 years ago, to prevent our boss from browsing through our e-mail boxes in his spare (?) time 😂

    (Long read about e-mail, encryption and PGP) View article View summary I thought they had both developed something new, but it turns out that what Proton calls "zero-access encryption, is exactly the same as what I implemented at work, 25 years ago, to prevent our boss from browsing through our e-mail boxes in his spare (?) time 😂

    I had also put up a Squid proxy server that we used for surfing, to prevent him from checking what websites we visited. I bet @Koen de Jonge - SynQ knows exactly who I mean 😏

    I've been concerned with privacy pretty much all my life, you can ask my brother @Erik van Zijst 😄

    PGP: Pretty Good Privacy

    Can't come as a surprise then that I know PGP pretty good 😇 And because teaching others is also something I like, I explained what PGP did, 30 years ago. And it's still valid today: if you have no idea of what PGP is or how to use it, read what I wrote on my first ever website (thank you so much, @internetarchive 🙏):

    #^https://web.archive.org/web/19970807080205/http://www.hzeeland.nl/~hzijst/pinf_en.htm

    (You non-Dutchies won't know the names that I used in that text, and neither will the younger generation Dutchies, I expect. They're from an old TV show for little kids, and I got my nickname, Woefdram, from it. Given to me by a classmate/friend when I was 15 or so.)

    So this latest design (which isn't very concrete yet) must also implement the latest and greatest in post-quantum encryption, PQC. And apparently GnuPG is about to support PQC.

    Of course everything I use is FOSS, so GnuPG is what I'll use. Once a user has a decent configuration and keyring, plugging it into Thunderbird is pretty easy. I wrote about that in "How to use GnuPG in Thunderbird".

    Users and their responsibility for their keys

    But the big challenge will be key management. I know how to handle key material, I've done that for a long time, and I like to call myself "professionally paranoid" 😏

    But not everybody knows, and my personal—often frustrating—experience is that the vast majority of people don't even want to know.

    They want to click a button, maybe enter a password and know that their message is safe (if even that); they don't want to learn about generating keys, how crucially important a really long password is and what is takes to keep all of that safe, secure, up-to-date and available when needed...

    So, how do I offer my users a place where they can keep their keyring without me having access to it? Users who know their way around in e-mail and PGP can do it the correct way, but for Joe Average something much easier is necessary.

    Guess I'll need something like Hashicorp Vault to allow those who want/need it, to securely store their keys on the server.

    #BigTech #privacy #FOSS #OpenSource #email #encryption #PQC
  5. @malb thanks for reporting, I feel I'm aging faster whenever results like this appear.

    Now, how about eprint.iacr.org/2026/1630 ? Sigh...

    #pqc #cryptography #crypto #quantum

  6. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. Justin Drake called it the end of an eight year, eight figure rabbit hole. I tried to understand what actually happened, and the short version is that nobody broke anything.

    The Foundation paused its $992,000 Poseidon1 collision prize on August 1, twelve days before the announcement. Two years of funded cryptanalysis, roughly $1.36M in announced ceilings, produced exactly what such programs should. Reduced-round results, a partial collision tier claimed in April, and no break on any parameter set that matters.

    What changed was the proving side. Binius at EUROCRYPT 2025 and then Flock this June made bit-oriented hashes cheap inside binary-field SNARKs. Flock proves 660k+ BLAKE3 compressions per second on ten M4 Max cores at under 250x native cost. Poseidon existed to make hashing affordable in prime-field circuits, and that problem dissolved.

    Two details the coverage missed. Buterin publicly refused a Poseidon precompile in February. The program had found Poseidon2 issues needing extra rounds or a reversion to Poseidon1, and enshrining one version meant a dangling precompile forever. And Anthropic's July release, the one that broke HAWK, also pointed Mythos at Poseidon and got under 10x, a mildly reassuring data point almost nobody registered.

    For this audience the RC4 parallel will make sense. AES-NI shipped in 2010, RC4 hung on through BEAST era workarounds, and RFC 7465 only killed it in 2015. Same shape here, except Ethereum's dependency was still in a research roadmap instead of a billion endpoints. The rest of us have the harder version.

    Full analysis, including the four things the announcement doesn't say and the caveat that the binary-field provers doing this are young software. Full analysis:

    postquantum.com/security-pqc/e

    #PostQuantum #Cryptography #Ethereum #PQC

  7. Cryptanalysts are using AI models now, openly and on live claims. So what does "independently confirmed" mean? Less than it meant two years ago, and two events this summer show why.

    April 2024 is the baseline. Yilei Chen posted a claimed polynomial-time quantum algorithm for LWE on the first day of the NIST PQC Standardization Conference. Eight days later he withdrew it, with an acknowledgment thanking Hongxun Wu and, independently, Thomas Vidick for finding the bug in Step 9. That parenthetical is the whole quality control mechanism of the field. Two experts, reasoning separately, converged on the same defect. Neither had seen the other's reading.

    July 23, 2026. Ananth and Sahai at UCSB and UCLA posted a proof of efficient unclonable encryption at 10:35 Pacific. Seyoon Ragavan at MIT posted the same result three hours and eighteen minutes later. Both credited GPT-5.6 Sol Ultra with the core ideas. Both traced to the same Simons Institute talk. Neither knew the other was working on it. Ragavan drove the model in supervised two-hour stretches; Ananth and Sahai used a self-critiquing UCLA harness. Two workflows about as different as two workflows get, one construction, one working day.

    August 2026. Daniel Simon's claimed polynomial-time algorithm for the Dihedral Coset Problem is being adjudicated right now on ePrint and Discord, in days rather than months, with Bernstein and Kirshanova among the people reading it. Several of the substantive responses were produced by humans working with models. One lists two language models on its byline. Disclosure across the documents is uneven: some name the model and version, some say only "AI assistance."

    The mechanism cryptanalysis depends on is not expertise. It is decorrelated failure. Two humans with similar training still make different mistakes, at different points, for different reasons, and their errors decorrelate even when their education does not. The risk with shared tooling is not sampling correlation. It is common-cause error, where shared weights, training data, post-training and retrieval reproduce the same blind spot across operators who have no way of noticing they share it.

    I am not claiming three model-assisted reviews reduce to one. I am claiming we currently lack the provenance to know how much independent weight they deserve.

    The fix is cheap. Every cryptanalysis note that circulates before peer review should end with two sections: who found what, and what was checked by whom, with what, and how hard. Ragavan's paper already does most of it, and ships a Lean 4 formalization that states which claims it does not cover. A kernel shares no weights with anything.

    IACR has barred models from bylines since May 2025. That rule governs formal submission. It does not reach the circulating notes where Simon is actually being adjudicated.

    (This post was edited by AI, but the points are mine. If anyone else wrote the same thing around the same time, blame it on ChatGPT)

    postquantum.com/post-quantum/i

    #infosec #cryptography #cryptanalysis #PQC #postquantum #formalmethods

  8. TechAptitude brings you the weekly "Weekend Reading".

    NIST is playing a central role in building standards for Quantum Computing and in this post we review the current status of NIST's efforts and their recent release of the first 3 standards. Enjoy, and please tell your friends to check this post out, and visit TechAptitude here: techaptitude.substack.com/

    techaptitude.substack.com/p/qu #NIST #Quantum #QuantumComputing #Standards #FIPS203 #FIPS204 #FIPS205 #PQC

  9. With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.

    Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.

    Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.

    The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:

    - Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?

    - Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?

    - Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?

    - Why would a European buyer accept "we cannot comment" as a tender answer?

    - Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?

    - Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?

    - Why would an allied service share access with a partner whose contractors may be on the same box?

    - How does a US prosecutor explain the next indictment of a Chinese contractor hacker?

    - What does Washington say when Beijing runs the same program and calls it law enforcement?

    Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.

    postquantum.com/cyber-kinetic-

    #Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC

  10. CW: llm producing genuinely impressive cryptographic result

    I was looking at the NIST-competition for further signatures at work today and noticed that HAWK has been withdrawn...

    (Context: NIST wasn't exactly enthusiastic about any signature scheme in the previous pqc competition and started a new one that is now in round three with only a few schemes left. HAWK was the only remaining lattice based scheme with the claim to fame being that it is basically FALCON (in standardization by NIST as FN-DSA) without the need for floating point arithmetic.)

    Now it turns out that Anthropic has an LLM that managed to find a severe enough attack to require enough of an adjustment to the parameters, that HAWK would become noncompetitive.

    This was genuinely new, clearly found by AI, on a very high profile target that lots of humans actively tried to break unsuccessfully, and clearly important that it was found...

    They also managed to improve the cryptanalysis on a round reduced version of AES, another VERY impressive feat!

    There is a genuine argument now that AI is competitive with the best human cryptanalysts and I am not yet sure what to make of that...
    😐

    #crypto #cryptography #pqc

  11. Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.

    Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.

    Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.

    So I try to explain the change.

    postquantum.com/security-pqc/g

    #PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity

  12. Oracle's plans for backporting PQC algorithms (ML-DSA and ML-KEM) and TLS 1.3 Post-Quantum Hybrid Key Exchange to current LTS JDK releases:

    blogs.oracle.com/java/post-qua

    #java #security #crypto #tls #pqc

  13. We published our #PQC roadmap for #GoogleCloud aiming for an ambitious 2029 completion timeline. It’s been quite a ride to get commitments from product teams all over the organization to become quantum safe by 2029. cloud.google.com/blog/products

  14. Sí señor!

    Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!

    Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!

    Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu

    Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)

    #UbuConLA #pqc #postquantum #cybersecurity #infosec

  15. Viele Unternehmen unterschätzen #PQC. Die EU erwartet bis 2026 Migrationspläne – Umsetzung bis 2030/2035. Das ist kein Forschungsthema mehr, sondern Governance.

    Sebastian Hempel analysiert, was konkret zu tun ist: javapro.io/de/pqc-es-ist-zeit-

    #Compliance #CyberSecurity @Cloudflare

  16. Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.

    Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.

    Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.

    But this is the third event this summer hitting PQC from a different angle.

    Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.

    Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.

    And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.

    Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.

    If the lesson were just "lattice math is fragile," one event would suffice.

    The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.

    SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.

    Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:

    postquantum.com/security-pqc/s

    #infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility

  17. How to read a quantum vendor's fidelity claim: demand the protocol (RB, XEB, and GST measure different things), the median rather than the hero pair, simultaneous operation, the readout/SPAM/leakage figures alongside the gate number, and the duration it held. Five answers is engineering; one is a press release. Full methodology plus mid-2026 numbers for every modality: postquantum.com/quantum-comput #infosec #quantum #PQC #benchmarking

  18. Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.

    postquantum.com/security-pqc/m

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore

  19. For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.

    TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.

    The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.

    TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.

    Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.

    My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:

    postquantum.com/security-pqc/t

    #infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum

  20. Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.

    Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.

    Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.

    postquantum.com/industry-news/

    #infosec #PQC #postquantum #cryptography #NIST #cybersecurity