Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
some_furry
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
some_furry
4mo ago
Sure, but that's a composite scheme, and I dislike those. :P
62.
▲
by
some_furry
4mo ago
They can't address it because nobody knows the answer yet. That's why their plans https://letsencrypt.org/2026/06/03/pq-certs#our-plans are to work with experts to solve the engineering challenges i
63.
▲
by
some_furry
4mo ago
> nsa & eu pushing for something to change proven algorithms makes me personally automatically distrustful as both are highly rotten bad actors. Who do you trust, then? > i have no knowledge, nor time to eval. (and probably few pe
64.
▲
by
some_furry
4mo ago
https://soatok.blog/2026/04/13/hybrid-constructions-the-post... I wrote this in April. Many folks' misconceptions about post-quantum cryptography and "hybrid" constructions are answerable with
65.
▲
by
some_furry
4mo ago
> and very likely backdoored post-quantum algorithms Citation needed Here's mine: https://keymaterial.net/2025/11/27/ml-kem-mythbusting/
66.
▲
by
some_furry
4mo ago
There's an IETF RFC draft for mldsa-44 keys for OpenSSH. https://datatracker.ietf.org/doc/draft-rpe-ssh-mldsa I'm not aware if it has any real traction, but that's what I found with a quick search.
67.
▲
by
some_furry
4mo ago
Sorry, I did entirely misread your words.
68.
▲
by
some_furry
4mo ago
> I think the folks who know this ought to remember the lay person perspective That's fair. I hold Hacker News to a higher bar of technical proficiency than a general audience. My hope with insisting on correct framing is to nudge o
69.
▲
by
some_furry
4mo ago
> signing should adopt ML-DSA/SLH-DSA at the same time as ML-KEM I know you mean well, but this proposal maximizes the downsides of PQ signatures. Both ML-DSA and SLH-DSA have enormous keys. SLH-DSA is also very slow, while ML-DSA i
70.
▲
by
some_furry
4mo ago
A better idea is to do this: # You kind of have to define this since most libraries don't have it def classic_kem(pk): [eph_sk, eph_pk] = classic_keygen() d = classic_shared_secret(eph_sk, pk) return hash(d + eph_pk +
71.
▲
by
some_furry
4mo ago
> Are you saying that a "hybrid KEM" is different in theoretical risk from chaining two KEMs? No, I'm saying that "hybrid KEM" or "chaining two KEMs" is very distinct from "encrypt twice". Con
72.
▲
by
some_furry
4mo ago
> Refreshing! Not wanting to be the "told you so" guy, > This is a problem that I have met so many times talking with people: they parrot the "Harvest-Now-Decrypt-Later is the only urgent problem, signatures can wait&qu
73.
▲
by
some_furry
4mo ago
The thing is: Quantum computers don't break AES-GCM, ChaCha20-Poly1305, or any other modern authenticated cipher. Layering encryption or doing cipher cascades is pointless. The thing a cryptography-relevant quantum computer does is b
74.
▲
by
some_furry
4mo ago
If you encrypt your data twice (taken very literally): c1 = E1(p, k1) c2 = E2(p, k2) If we assume E1() is broken by a quantum computer, E2 doesn't matter to protect p. What you do instead is to use multiple KEMs and combine
75.
▲
by
some_furry
4mo ago
The international standardization effort that led to ML-KEM and ML-DSA focused both on classical attacks (regular computers) and quantum attacks. There were 5 levels being considered for each submission. Level 1 - at least as difficult to
76.
▲
by
some_furry
4mo ago
> You use both a quantum-safe algorithm and a classical algorithm, encrypting your data twice and remaining secure if either one is broken. No. Don't do that. If you encrypt your data twice, and one of them is broken by a quantum co
77.
▲
by
some_furry
5mo ago
Imagine you have two web pages. One is a recipe for apple fritters, and the other is an informal ranking of apples by flavor. Let's say your apple fritter recipe links to your apple ranking list. Later, you discover someone copied your
78.
▲
by
some_furry
5mo ago
I can't speak to the larger trend of AI boosters, as I don't go out of my way to pay attention to them, but the practice of being vocally self-critical and openly discussing the flaws found in one's own software (whether fr
79.
▲
by
some_furry
5mo ago
Disappointing but not surprising. This is what happens when you're a billion dollar company and your ethical bone is tied to "we fully comply with the law". You get compliance by default , even if doing so would exacerbate h
80.
▲
by
some_furry
5mo ago
No. It's fraud.
81.
▲
by
some_furry
5mo ago
Can't you just, wire your agent into a Python script and have it infinitely check its own work? That would hit the metrics, but do nothing useful. Hell, throw a Tarot reading in the middle of the loop so the agent has non-deterministic
82.
▲
by
some_furry
5mo ago
Ever heard of killedbygoogle.com?
83.
▲
by
some_furry
5mo ago
Right, but since that's the world we have today, our threat models should all account for it until we can meaningfully change things.
84.
▲
by
some_furry
6mo ago
> It seems like alot of scientific advancements occurred by someone applying technique X from one field to problem Y in another. Yeah, you should look into the Langlands project sometime
85.
▲
by
some_furry
6mo ago
Yeah, why actually engage with moral issues when we can just defer to a status quo that happens to benefit me?
86.
▲
by
some_furry
6mo ago
Yes there was! But, thousand yard stare it was the version for the FIPS patches to 1.0.2.
87.
▲
Hybrid Constructions: The Post-Quantum Safety Blanket
(soatok.blog)
2 points
by
some_furry
6mo ago
|
0 comments
88.
▲
Show HN: Age-PHP: a PHP implementation of age encryption (post-quantum)
(github.com)
6 points
by
some_furry
6mo ago
|
1 comments
89.
▲
by
some_furry
6mo ago
Can you add a "tech-savvy user" mode, off-by-default, that opts out of these sort of reminders? I think we're capable of finding it ourselves if you do.
90.
▲
by
some_furry
6mo ago
Yes, I do. See my review of Signal for more: https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...
More ›