4 ms·
> In your PQ safety blanket article https://soatok.blog/2026/04/13/hybrid-constructions-the-post-quantum-safety-blanket/ https://soatok.blog/2026/04/13/hybrid-c
by some_furry 3mo ago
> In your PQ safety blanket article https://soatok.blog/2026/04/13/hybrid-constructions-the-post-quantum-safety-blanket/ https://soatok.blog/2026/04/13/hybrid-constructions-the-post... you make it pretty clear the reason you support hybrid is tactical, not cryptographic.
What does it matter that my public arguments are tactical? Hybrid gets us to PQ faster, which makes progress on plugging up the HNDL risk.
> Your wording ("Once Q-Day happens") strongly suggests Q-Day will happen, like, it’s so certain you don’t even need to state it explicitly, you can just assume it will.
The literal opening section is talking about recent changes in direction from large Internet providers about quantum computing risks.
The rest of the article is predicated on "these companies' risk assessment turns out to be correct".
Separately, in https://soatok.blog/2024/09/13/e2ee-for-the-fediverse-update-were-going-post-quantum/ https://soatok.blog/2024/09/13/e2ee-for-the-fediverse-update... I wrote more about my actual beliefs about the likelihood of Q-Day.
> It’s pretty clear from there that you think ECDH is now technically useless, and the only real justification for hybrid schemes (as opposed to pure PQ), is to reassure the people still unsure about the likes of ML-KEM. Sure you still do recommend going hybrid, but from what I can tell, you would have preferred a world where we go pure PQ right away.
You are extrapolating from the subsidiary clause of an if statement whose truth value I do not claim to know.
> And so would I to be honest (if ECC is a bust): one algorithm is simpler and faster than two.
Sure.
- loup-vaillant 3mo ago> recent changes in direction from large Internet providers about quantum computing risks. Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers? To me this is more about the end of the NIST contest, and that one has no bearing on actual advances in quantum computing. > The rest of the article is predicated on "these companies' risk assessment turns out to be correct". Err, where did you wrote that? I can’t find it in your last two articles. > You are extrapolating from […] I exptrapolate mostly from this: "I generally prefer hybrid KEMs–not out of any practical concern over ML-KEM’s security (or any other PQ KEMs, generally), but for reasons I’ll explain later in this blog post." And this: "Hybrid KEMs are an easier sell to people who are not cryptography experts than pure post-quantum KEMs for reasons that are mostly related to psychological safety than cryptographic safety." https://soatok.blog/2026/04/13/hybrid-constructions-the-post-quantum-safety-blanket/ https://soatok.blog/2026/04/13/hybrid-constructions-the-post... Sorry if I’m misinterpreting, but as you can see I’m not the only one. --- Anyway, good article on threat models.
- some_furry 3mo ago> Err, where did you wrote that? I can’t find it in your last two articles. Just now. In an HN comment. I write in conversational English. I'm not always going to meticulously write everything like a formal argument might. If you didn't understand that what I wrote later in a blog post was predicated on an assumption established in the intro, but would have if I wrote an explicit transitional sentence, that's useful feedback. But if you're treating an informal blog post like a court filing, you might be setting yourself up for disappointment.
- loup-vaillant 3mo ago> I write in conversational English. Fair enough. When I write an article (and to a lesser extent even a comment like here), I tend to agonise over every sentence. I’m guessing I’m kinda assuming others do the same. Except of course they don’t.
- some_furry 3mo agoIt depends what I'm doing. My dayjob involves a lot of code review and protocol cryptanalysis, so I agonize quite a bit there. My blog would be less fun if I maintained the same level of rigor. If that makes any sense. ^^;
- loup-vaillant 3mo agoIt does :-)
- esseph 3mo ago> Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers? Yes. Both have internal global security orgs that are constantly communicating with other large companies and governments. If they are accelerating (as are others), it is a signal. The reliability of that signal is up to the reader to determine. https://www.microsoft.com/en-us/security/blog/2026/06/30/microsoft-advances-quantum-safe-security-as-the-risk-timeline-shifts/ https://www.microsoft.com/en-us/security/blog/2026/06/30/mic...