4 ms·
OP does have a point though, especially with DJB's thoughts (and others) on the matter. https://nitter.net/hashbreaker?lang=en https://nitter.net/hashbreaker?l
by cipherboy 4y ago
OP does have a point though, especially with DJB's thoughts (and others) on the matter.
https://nitter.net/hashbreaker?lang=en https://nitter.net/hashbreaker?lang=en
For FIPS in particular, they've first gotta sunset the traditional algorithms for anyone to strictly need to care (and even then, parallel constructions of PQC+traditional could let other PQC algorithms in -- like the Chrome experiments -- from a FIPS perspective, you can treat the PQC like plaintext). And for them to be useful, adoption needs to occur in the IETF communities (PKIX, TLS, SSH, IKE, ...).
You're probably looking at least 5 years on the adoption window to customers running the lastest updates. NIST's blessing might help some of the IETF conversations that now need to happen. But not listening to DJB, given his track record, likely will anger a subset of IETF contributors and might hinder adoption.
It'll be interesting to see if IETF takes the more conservative approach advocates by DJB or if they continue on with NIST's blessing alone. But I'm just a watcher... :-)
Edit: and for the record, FIPS never mandated Dual EC DRBG but it was still a mistake for NIST to rubber stamp.
- Aachen 4y agoYou've linked the entire profile, I guess you're referring to this tweet list? https://nitter.net/hashbreaker/status/1548359451752640520#m https://nitter.net/hashbreaker/status/1548359451752640520#m
- cipherboy 4y agoAh sorry, correct.
- westurner 4y agoFrom https://news.ycombinator.com/item?id=31995535 https://news.ycombinator.com/item?id=31995535 : > (IDK what the TLS (and FIPS) PQ Algo versioning plans are: 1.4, 2.0?) Kyber, NTRU, {FIPS-140-3}?
- cipherboy 4y agoSorry, reading NIST is worse than reading tea leaves and I don't actively participate in the IETF TLS mailing lists enough to say any more than the next person :-) Just stating that the process (NIST to enterprise customer) takes time for complete PQC adoption across the entire stack.
- westurner 4y agoIt shouldn't take long to change software: how long does it take to add a dependency on an open implementation and add an optional config file const pending a standardized list of algos like TLS 1.3+ and FIPS, and fallback to non-PQ; like DNSSEC (edit: and WPA2+WPA3)? Do mining rig companies that specialize in ASICs and FPGAs yet offer competitively-priced TLS load balancers -- now with PQ -- or are they still more expensive than mainboards?