19 ms·
So the argument boils down to 1. A mathematical attack against the PQC candidates would also break ECC (I have no ability to judge this claim). 2. Implementat
by ls612 3mo ago
So the argument boils down to
1. A mathematical attack against the PQC candidates would also break ECC (I have no ability to judge this claim).
2. Implementation bugs also exist in classical implementations.
#2 seems questionable to me unless you think the same implementation bugs will exist in Curve25519 and whatever PQC algorithm you are using. If the concern is side-channel attacks then that is irrelevant to a HNDL attack. But for most communications the cost of a HNDL attack being executed several years minimum from now is far lower than the cost of an implementation bug in ML-KEM breaking their security today. Whereas Curve25519 is very well tested in its standard implementations.
- some_furry 3mo agoYou mostly got it, yeah. Point 1, ECC is only also broken after Q-Day. Hybrids obviously help if you believe Q-Day is far into the future, or never coming. But if you take Q-Day happening as possible in our lifetime, the HNDL threat means data being encrypted today depends entirely on PQ security in the long run (since breaking EC with a Quantum Computer has an attack cost of like 2^30 or so instead of 2^120 or so).
- ls612 3mo agoSo it seems like it comes down to a question of risk and cost. If your threat model is that it is much more costly for your communications to be decrypted today vs in 10 years then hybrid is a good strategy.