4 ms·
We are making [NTRU Prime + x25519 key exchange the default] now (i.e. ahead of cryptographically-relevant quantum computers) to prevent "capture now, decrypt l
by sigil 5y ago
We are making [NTRU Prime + x25519 key exchange the default] now (i.e. ahead of cryptographically-relevant quantum computers) to prevent "capture now, decrypt later" attacks where an adversary who can record and store SSH session ciphertext would be able to decrypt it once a sufficiently advanced quantum computer is available.
- unixhero 5y agoVery future proof! So it is quantum brute force crack proof?
- zaarn 5y agoIt isn't, you can always brute force the symmetric key used for traffic if you wanted. The handshake itself can also in theory be brute forced if you know all input parameters except the input key.
- chasil 5y agoThis situation is actually more complex than the summary implies. NIST is conducting a competition for post-quantum key exchange and signature algorithms. NTRU Prime did not make the cut as a key exchange finalist. It appears that NTRU Prime is going ahead in OpenSSH, without any formal endorsement from NIST. In the notes listing NTRU Prime as an alternate (and rejection as a finalist), Daniel J. Bernstein filed a complaint with his experience at NIST: https://csrc.nist.gov/Projects/post-quantum-cryptography/round-3-submissions https://csrc.nist.gov/Projects/post-quantum-cryptography/rou... "Formal complaint regarding 8 June 2021 incident - 2021.06.15, Daniel J. Bernstein..." "Executive summary. A week ago Dr. Daniel Apon from NIST publicly accused me of professional misconduct. Specifically, he accused me of initiating private contact with NIST so as to provide false information to NIST regarding the timing of an upcoming announcement relevant to NIST’s ongoing decisions..." It is unfortunate that this disfunction has a practical impact upon OpenSSH.
- mike_d 5y agoIt is well accepted that djb is more trustworthy than NIST, with the latter assisting the NSA to insert kleptographic backdoors into standards.
- trillic 5y agoThe feds don't like DJB, he sued them and won to allow us all to publish fun stuff like this.
- nullc 5y agoLooks like Daniel Apon no longer works for NIST, FWIW.
- tjalfi 5y agoThe text of the complaint is available at [0]. [0] https://03283664099418252878.googlegroups.com/attach/6f5422d4f193d/complaint-re-apon.pdf?part=0.0.1&vt=ANaJVrEKL6bOebF3Zos4ZeIGsTPZZAelDp9EPc9bSuNlK6xbSDqb0BJDKJwqUoEKzK81pEB4fAM-69Mty_gcCYl2Va5UueLFw7Tqnl_ZwA-5krbTKUMr6KE https://03283664099418252878.googlegroups.com/attach/6f5422d...
- 0xdeadb00f 5y agoIs there anywhere I can learn (or learn to learn) about NTRU Prime? I have a fairly decent knowledge of x25519 but in know nothing about lattice-based cryptography. I tried reading the NTRUP paper but most of it goes over my head.