14 ms·
128 bits of symmetric keys are enough for post-quantum security. See https://words.filippo.io/post-quantum-age/ https://words.filippo.io/post-quantum-age/. The
by FiloSottile 11mo ago
128 bits of symmetric keys are enough for post-quantum security. See https://words.filippo.io/post-quantum-age/ https://words.filippo.io/post-quantum-age/.
The public key algorithm has been frustratingly blocked on the IETF and CFRG, which are taking more than 15 months since FIPS 203 to stabilize a simple hash-based hybrid combiner.
- knorker 11mo agoGlad to hear about 128bit. I still stand by that one should not migrate to vanilla `age` until the public key part is PQ, or one will need to do two migrations. The incremental improvement from going GPG to age seems pointless given the timelines. If PQ compliance is urgent, then sure, migrate to age+PQ plugins. Yes I share the frustration about how long it's taking, so in the mean time for PQ requirements I can't get into, I did for some installations need to migrate to a temporary pre-standard (but still holding up) PQ layer. And I'm itching to migrate to something standard (or at least de facto standard) when it comes. Frustrating, but understandable, that many people are making excuses that they are focusing on key exchange, not communication over time.