4 ms·
So which one is better? sntrup761x25519-sha512 or mlkem768x25519-sha256?
by stoltzmann 1y ago
So which one is better? sntrup761x25519-sha512 or mlkem768x25519-sha256?
- ethan_smith 1y agoMLKEM768 offers better performance and smaller keys, while SNTRUP761 has stronger security assumptions and better resilience against potential cryptanalysis.
- tptacek 1y agoNTRU Prime (sntrup) is there mostly as a quirk of history (mlkem wasn't available when SSH went down the road of doing PQ). You can use either, but my guess is using sntrup is going to be a little like how GPG used to default to CAST as its cipher.
- throw0101a 1y ago> NTRU Prime (sntrup) is there mostly as a quirk of history (mlkem wasn't available when SSH went down the road of doing PQ). ML-KEM (originally "CRYSTALS-Kyber") was available, it's just the Tiny/OpenSSH folks decided not to choose that particular algorithm (for reasons beyond my pay grade). NIST announced their competition in 2016 with the submission deadline being in 2017: * https://en.wikipedia.org/wiki/NIST_Post-Quantum_Cryptography_Standardization https://en.wikipedia.org/wiki/NIST_Post-Quantum_Cryptography... TinySSH added SNTRUP in 2018, with OpenSSH following in 2019/2020: * https://blog.josefsson.org/2023/05/12/streamlined-ntru-prime-sntrup761-goes-to-ietf/ https://blog.josefsson.org/2023/05/12/streamlined-ntru-prime... SSH just happened to pick one of the candidates that NIST decided not to go with.
- tptacek 1y agoI'm simply repeating what Damien Miller said. https://news.ycombinator.com/item?id=32366614 https://news.ycombinator.com/item?id=32366614 I'm curious where you got the idea that they had mlkem available to them? They disagree with you.
- throw0101a 1y agoFrom the link: > We (OpenSSH) haven't "disregarded" the winning variants, we added NTRU before the standardisation process was finished and we'll almost certainly add the NIST finalists fairly soon. Nothing in his statements talks about 'availability', just a particular choice (from the ideas floating around at the time). CRYSTALS-Kyber (now ML-KEM) was available at the same time as SNTRUP because they were both candidates in the NIST competition. NTRU (Prime) is listed as round three finalist / alternate (along with CRYSTALS-Kyber): * https://en.wikipedia.org/wiki/NIST_Post-Quantum_Cryptography_Standardization#Finalists https://en.wikipedia.org/wiki/NIST_Post-Quantum_Cryptography... Given that they were both candidates in the same competition, they would have been available at the same time. Tiny/OpenSSH simply chose a candidate that ended up not winning (I'm not criticizing / judging their choice: they made a call, and it happened to be a different call than NIST).
- chasil 1y agoNTRU Prime was written by Dan Bernstein, who also had a strong hand in the creation of ed25519 elliptic curve keys, and the chacha20-poly1305 AEAD cipher. https://news.ycombinator.com/item?id=37520065 https://news.ycombinator.com/item?id=37520065 https://www.metzdowd.com/pipermail/cryptography/2016-March/028824.html https://www.metzdowd.com/pipermail/cryptography/2016-March/0... The first version of NTRU Prime in an SSH server was implemented in TinySSH and later adopted by OpenSSH. Bernstein provided new guidance, and OpenSSH developed an updated algorithm that TinySSH implemented in return. The NIST approval process was fraught, and Bernstein ended up filing a lawsuit over treatment that he received. I don't know how that has progressed. https://news.ycombinator.com/item?id=32360533 https://news.ycombinator.com/item?id=32360533 While Kyber may have been the winning algorithm, there will be great preference in the community for Bernstein's NTRU Prime.
- tptacek 1y agoNo, there won't. The world will standardize on MLKEM, at least until some important new piece of knowledge is uncovered. The process wasn't at all fraught. Who's the highest-profile cryptographer or cryptography engineer you can think of who took Bernstein's claims about the process seriously?
- throw0101a 1y ago> While Kyber may have been the winning algorithm, there will be great preference in the community for Bernstein's NTRU Prime. There's IETF WG drafts for use of Kyber / ML-KEM, but none for NTRU, so I'm not sure about that: * https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/ https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/ * https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/ https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/ * https://datatracker.ietf.org/doc/draft-ietf-tls-hybrid-design/ https://datatracker.ietf.org/doc/draft-ietf-tls-hybrid-desig... * https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/ https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-ml... And given that NTRU made it to the third round, and NTRU Prime is labelled as an alternative, I'm not how strong a claim Bernstein can make to being ill-treated by NIST.
- 1y ago