3 ms·
I'm hesitant to build anything load-bearing on AT Protocol given its PQ exposure: https://words.filippo.io/crqc-timeline/ https://words.filippo.io/crqc-timeline
by Croaky 5mo ago
I'm hesitant to build anything load-bearing on AT Protocol given its PQ exposure: https://words.filippo.io/crqc-timeline/ https://words.filippo.io/crqc-timeline/
- tired_star_nrg 5mo agoHow does this impact AT Protocol? I’m just hearing about AT now, so I’m not familiar
- embedding-shape 5mo agoToday, not so much. But once the day is here where we have CRQC, if ATProto hasn't yet started using post-quantum cryptography for identities, users are either vulnerable or a bunch of stuff will break once they push a hotfix to make users not vulnerable. Alternatively, they fix these things now, so once CRQC arrives, it's already not a problem, and no gets compromised nor have to urgently update their software.
- Croaky 5mo agoDIDs are rooted in ECDSA keys (secp256k1). Each user identity is a non-PQ cryptographic commitment. These ecosystems must start migrating very soon because if CRQCs arrive before they're done, they face a choice between user compromise and bricking accounts.
- jerknextdoor 5mo agoI'm not sure it says much, but I met the person who wrote the post you linked to at ATmosphere this year. To me that says that maybe they're not as worried as you about ATProto's PQ exposure. I overheard lots of discussions about the topic, but I'm not an expert so I can't give much more insight than that.
- Kye 5mo agoThey're aware of it. https://bsky.app/profile/bnewbold.net/post/3miufj3cfhs2i https://bsky.app/profile/bnewbold.net/post/3miufj3cfhs2i