3 ms·
Are any of these algorithms suited for PGP signing replacements? I'm interested in being able to make long term claims based on web-of-trust models, and I've b
by epaulson 10y ago
Are any of these algorithms suited for PGP signing replacements?
I'm interested in being able to make long term claims based on web-of-trust models, and I've been nervous about basing it around RSA/DSA key pairs.
In that sort of world, what do the keys actually look like? Is it comparable to being able to distribute a single public root key?
- zmanian 10y agoWe do not currently have good options for small Post Quantum signatures. Hash Based signatures in a web of trust would result in enormous amounts of signature data for each public key. A stateful hash based signing protocol like XMSS might be more suitable. Hopefully a Post Quantum small signature alternative appears.
- hannob 10y agoyou may want to have a look at sphincs. its security is based on hash-functions, therefore unlike most other postquantum schemes it can be considered very reliable (good hash functions are a solved problem these days). Downside: signatures are big (~40k). For TLS this is unworkable, for a PGP-like system this is doable. https://sphincs.cr.yp.to/ https://sphincs.cr.yp.to/