#pqc

18 posts · Last used 9d

Excellent research (and very useful FAQ) out on a new RSA attack: forging 1024-bit signatures in “nearly SNFS time” (not polynomial, but somewhat faster than previous number field sieve approaches by a few orders of magnitude). Real-world risk is low because most RSA implementations in practice do not meet one of the attack requirements; however … more ammunition on the need to transition away from RSA (and protocols like TLS moved to elliptic curve quite a while ago, or are moving to ML-KEM and #PQC). https://github.com/ucsd-hacc/NSNFSSSFSFN #cryptography tip o’ the hat to Bruce Schneier’s blog for raising it to my attention
3
2
0
0
Replying to
@darkuncle@infosec.exchange An interesting thing is this: While TLS does not expose a weak mode of using RSA, the majority of X.509 certs on the web are RSA (approx. 2/3). See below for a link to the source for this. But certificates are also used for other things, e.g. code signing, token issuing, etc. And who knows whether any of those use cases will *always* be avoiding the classic RSA padding for signatures. So a move to the more efficient and compact ECDSA or (even (better)) to EdDSA would be appreciated. This move will also more likely level the path towards allowing for better cryptographic agility to adopt hybrid #PQC ciphers in the future. BTW, kudos to Let's Encrypt! There the entire chain is using ECDSA signed certs down to the web site using it. https://ecdsa.com/research #cryptography #RSA #ECC
2
1
1
0
«RSA-Angriff — Forscher fälschen digitale Signaturen ohne Faktorisierung: RSA-Angriff ohne Faktorisierung: Forscher zeigen, wie sich digitale Signaturen fälschen lassen. Moderne RSA-Systeme sind vorerst geschützt.» Ich sag es mal so: Bei neuen Projekten sollte mensch schon länger kein RSA und PKCS#1 mehr einsetzen. Es gibt dafür bereits Post-Quantum kryptografische Standards die eingesetzt werden können. 🔓 https://tarnkappe.info/artikel/it-sicherheit/rsa-angriff-digitale-signaturen-ohne-faktorisierung-333812.html #rsa #pkcs1 #itsicherheit #pqc #signatur #privacypass #captcha
5
1
4
0
«Claude Mythos — Anthropic-KI knackt Verschlüsselungsstandard - was das bedeutet: Die Anthropic-KI Claude #Mythos Preview soll Schwachstellen in einer - allerdings abgeschwächten - Version des verbreiteten Verschlüsselungsalgorithmus #AES gefunden haben. Akut besteht keine Gefahr. Langfristig könnte der #Hack aber Folgen haben.» Ich bin der Meinung, dass dies vor allem #Marketing von #Anthropic ist und keine wirkliche #PQC-Gefahr da die nicht wirklich darauf eingehen. 🔐 https://t3n.de/news/mythos-knackt-verschluesselung-1755434/
2
2
1
0
Claude Mythos demonstrates that LLMs can find new, working attacks on cryptographic algorithms. Cryptographers and security experts have welcomed the LLM-driven results as a fresh set of eyes, especially as the world moves toward quantum-safe cryptography. https://www.databreachtoday.com/claude-mythos-finds-new-cryptographic-algorithm-attacks-a-32360 #PQC
0
0
0
0
Can't migrate everything to PQC at once. Which layer first? TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario. https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/ #PQC #TLS #IPsec #infosec #cryptography
0
0
3
0
After the White House quantum summit, I tested the claim that America built "every layer of the quantum stack." Eight layers. Named researchers. Primary sources. Quick scorecard: The PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) that NIST standardized and that EO 14412 mandates for federal systems? Designed almost entirely by Europeans and Canadians. CWI (Netherlands), Bochum (Germany), IBM Zurich (Switzerland), ENS Lyon (France), Waterloo (Canada). NIST ran the process — that's a real institutional win. But the algorithmic content is international. The enabling infrastructure is even more striking. Dilution refrigerators from Finland (Bluefors) and UK (Oxford Instruments) dominate the market that cools US superconducting quantum computers. Domestic manufacturing exists (Maybell in Denver, Bluefors's Syracuse operation) but the US remains substantially dependent on European-headquartered suppliers. Control electronics from Switzerland (Zurich Instruments), Israel (Quantum Machines), Germany (Rohde & Schwarz). The CHIPS Act quantum investments are partly a response to these dependencies. On the science side: Josephson junction predicted at Cambridge (1962). First superconducting qubit demonstrated at NEC Japan (1999). Surface code traces to Kitaev (Russia). Steane code from Oxford. qLDPC codes from French and Russian mathematicians. The US built the strongest commercial integration and scaling layer. That is a real and hard-won capability. It is not the same as sole authorship of the entire stack. Policy implication: "we built everything" leads to different supply chain decisions than "we built the best integration layer, and it depends on allied supply chains." The second framing is more accurate and produces better policy. Full article with every claim sourced: https://postquantum.com/quantum-sovereignty/who-built-the-quantum-stack/ #quantum #PQC #infosec #cryptography #postquantum #supplysecurity #quantumcomputing #cybersecurity
12
2
7
0
Już nie rok 2030. Microsoft przyspiesza prace nad wdrażaniem rozwiązań postkwantowych. Nowym punktem granicznym jest 2029 r. Spekulacji związanych z rozwojem komputerów kwantowych jest wiele. Jedni uważają, że urządzenie zdolne do złamania współczesnych algorytmów kryptograficznych nigdy nie powstanie, a prowadzone w tej dziedzinie badania naukowe są tylko teoretycznymi rozważaniami. Są jednak i tacy, którzy z niepokojem śledzą najnowsze doniesienia z laboratoriów, zwłaszcza te dotyczące postępów w tworzeniu... #WBiegu #Microsoft #Pqc #Quantum https://sekurak.pl/juz-nie-rok-2030-microsoft-przyspiesza-prace-nad-wdrazaniem-rozwiazan-postkwantowych-nowym-punktem-granicznym-jest-2029-r/
0
0
0
0
RE: https://mas.to/@nemo/116864001224955528 NSA involved in "off the rails" warrant-less mass surveillance. This (and the fact that their chain of command was purged by the Trump regime) should be factored into the debate around the IETF relying on the NSA's input. If your position is that a simple RFC is "not a big deal" then IDK why you're making a big deal out of people like @djb@mastodon.cr.yp.to being against it. #FISA #crypto #ietf #tls #pqc #privacy #surveillance
1
0
2
0
Heading to Munich for CODE 2026 at the @UniBw Campus! 🇩🇪 Catch us at the @FORTRESS booth for live SCA demos on #PQC algorithms. 🎙️ Plus: We'll be giving a talk on PQC security validation & joining a panel on hybrid secure boot challenges.
0
0
0
0

A few notes on Post-Quantum Certificates:

  • Yes, Merkle-Tree Certificates (MTCs) are smaller than ML-DSA certs, but still pretty large
  • MTCs come in two flavors: standalone and landmark-relative; servers will need to support both
  • clients need to update landmarks frequently; how will non-browsers handle that?
  • web-PKI (MTCs) and private PKI (ML-DSA) are diverging

Things are getting more complex...

https://www.netmeister.org/blog/pqc-certs.html

#pqc #mtc #cryptography

15
0
12
1
great little writeup from @dangoodin@infosec.exchange here (feat. @sophieschmieg@infosec.exchange and @filippo@abyssdomain.expert ); the wrinkle about how Grover's performance falls off as you parallelize it was a new one for me, and I'm adjusting my messaging accordingly. This is why it's important to keep close to professional cryptographers in broader discussions about change and adoption for #PQC. https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in-a-post-quantum-world/
10
0
12
0
You've seen all posts