4 ms·
Hi, I'm the author of this blog post! > there is also the likelihood that Q-Day never arrives, either because something we don't know prevents the construction
by some_furry 3mo ago
Hi, I'm the author of this blog post!
> there is also the likelihood that Q-Day never arrives, either because something we don't know prevents the construction of sufficiently large quantum computers (eg. quantum gravity)
That is possible, but given the recent 2029 timelines from large Internet providers, I think it's prudent to prepare for Q-Day even if it never arrives.
> or because the entire field was a scam.
The field is like... a magnet for scams, sure. But it, itself, isn't one.
And, like, the Quantum Village at DEFCON has really failed to establish credibility in my eyes.
https://soatok.blog/2022/08/18/burning-trust-at-the-quantum-village-at-defcon-30/ https://soatok.blog/2022/08/18/burning-trust-at-the-quantum-...
https://soatok.blog/2023/08/20/defcon-quantum-village-2-electric-boogaloo/ https://soatok.blog/2023/08/20/defcon-quantum-village-2-elec...
> in that scenario abandoning ECC would have been pretty stupid.
Not really, no. See https://blog.trailofbits.com/2024/07/01/quantum-is-unimportant-to-post-quantum/ https://blog.trailofbits.com/2024/07/01/quantum-is-unimporta... for a counter-point.
- teravor 3mo ago> That is possible, but given the recent 2029 timelines from large Internet providers, I think it's prudent to prepare for Q-Day even if it never arrives. no one argues we shouldn't. you made the argument that we should abandon ECC by not doing hybrid, in my opinion it's an extremely weak argument because it assumes Q-Day will arrive. don't change goalposts. the article you linked supports my position. > the fear of the quantum doomsayers is based on a completely valid observation: the internet has put nearly all of its cryptographic eggs into the single basket of the hidden subgroup problem. > By the time the next phase of standardization is over, we can expect to have algorithms based on at least three or four different mathematical problems. If one of the selected problems were to fall to advances in quantum or classical algorithms, there are readily-available replacements that are highly unlikely to be affected by attacks on the fallen cryptosystems. in fact, it makes the argument (if not directly) for a concatenation of multiple schemes. I'm all for it, hybrid++.
- some_furry 3mo ago> you made the argument that we should abandon ECC by not doing hybrid, Where did I ever make that argument? In both TFA and my previous blog post, I've made it abundantly clear that I'm pro-hybrid. My argument is simply: 1. The claimed benefits of ECDH hybridization evaporate immediately the moment Q-Day happens. No one disputes this. 2. Harvest Now, Decrypt Later (HNDL) is the primary threat we face today during the uncertain times where we don't know if Q-Day will ever happen. Advocating for PQ+ECC hybrids over PQ is fine. But fear-mongering about PQ in this threat model is self-defeating: Once Q-Day happens, your only source of security is PQ anyway, so if we're going to do hybrids with today's threat model in mind, PQ+PQ is the way you really want to go (and PQ+PQ+EC if you really want EC). The blog post you're commenting on says this explicitly. I'm not anti-hybrid. I'm anti "this is an NSA ploy" bullshit. And the IETF mailing list thread I'm mentioning is stuffed with this kind of irritating conspiracy theory rhetoric. I even link to, and quote, two examples of this.
- teravor 3mo agoin that case my mistake. i always assumed that the `NSA ploy` was strategic bullshit, the sort of thing you say to get support from NSA haters. it wouldn't even occur to me that someone would take time addressing it without being one of those anti-hybrid people.
- yardstick 3mo agoI’m a passive observer on the same list and have been for at least several years. I don’t plan to comment on the WGLC currently going on… but I will be so extremely happy once the subject is done with. It’s like watching a cybersecurity version of Dawsons Creek or The Young and the Restless or… Jerry Springer?! Insane
- tux3 3mo ago>Once Q-Day happens, your only source of security is PQ anyway, so if we're going to do hybrids with today's threat model in mind, PQ+PQ is the way you really want to go I want to broadly agree but I still can't resist arguing :) EC is really cheap on the CPU and I trust that libsodium's X25519 is implemented pretty solidly. After Q day, the $ price to break EC is still not negligible. Whereas PQ+PQ is really expensive. I'm anti PQ+PQ hybrid just on cost. PQ+EC is practically free and still inflicts $'s on attackers after Q day (attacks do get cheaper and you discard the EC at some point, but practically I don't see EC as instantly worthless).
- ls612 3mo agoIs there any downside to hybrid schemes other than using a bit more compute? If so than merely being able to hedge against unknown classical algorithmic flaws in the PQC candidates (which are not nearly as battle tested as ECC) seems like enough of a reason to do it.
- some_furry 3mo agoRead https://soatok.blog/2026/04/13/hybrid-constructions-the-post-quantum-safety-blanket/ https://soatok.blog/2026/04/13/hybrid-constructions-the-post... for a longer explanation. The main thing I want to stress here is: I'm not anti-hybrid. Some people are. They tend to argue that less code / complexity is better, but you'll want to find one of them to ask directly.
- ls612 3mo agoSo the argument boils down to 1. A mathematical attack against the PQC candidates would also break ECC (I have no ability to judge this claim). 2. Implementation bugs also exist in classical implementations. #2 seems questionable to me unless you think the same implementation bugs will exist in Curve25519 and whatever PQC algorithm you are using. If the concern is side-channel attacks then that is irrelevant to a HNDL attack. But for most communications the cost of a HNDL attack being executed several years minimum from now is far lower than the cost of an implementation bug in ML-KEM breaking their security today. Whereas Curve25519 is very well tested in its standard implementations.
- some_furry 3mo agoYou mostly got it, yeah. Point 1, ECC is only also broken after Q-Day. Hybrids obviously help if you believe Q-Day is far into the future, or never coming. But if you take Q-Day happening as possible in our lifetime, the HNDL threat means data being encrypted today depends entirely on PQ security in the long run (since breaking EC with a Quantum Computer has an attack cost of like 2^30 or so instead of 2^120 or so).
- 3mo ago