Elektrine lite

← Feed

@djb@mastodon.cr.yp.to

Post #1387835

2026-04-18 05:01 UTC

"Safety blanket" in https://web.archive.org/web/20260414114106/https://soatok.blog/2026/04/13/hybrid-constructions-the-post-quantum-safety-blanket/ and https://web.archive.org/web/20260418021002/https://symbolic.software/blog/2026-04-13-hybrid-constructions/ tells typical readers: using ECC+PQ, not just PQ, is for familiarity, not security. Huh? Millions of sessions used CECPQ2b=ECC+SIKE. ECC is the _only_ reason those weren't instantly exposed to the SIKE break.

Replies (3)

  • @omnicore@ieji.de 2026-04-18 05:15

    @djb Hybrid ECC+PQ is quite obviously the only way forward even if a quantum computer exists it would still add to the computational burden a few days or hours. These are resources and consequently money. The push for pure PQC rings all kinds of bells.

    Open ##1710978

  • @gregprice@sfba.social 2026-04-18 05:58

    @djb I don't understand why these folks say that the motivation for hybrid schemes is about "harvest now, decrypt later". Seems a lot more straightforward than that: if you deploy a new PQ scheme on its own, and then someone has a break in that scheme, that's bad! That's bad if it means they can forge signatures, just like it's bad if it means they can decrypt messages. Whereas if instead you deployed a hybrid with a non-broken scheme, then you're still secure. Are they… assuming that if there is such a break, everyone will just switch right back to a proven scheme? That seems confused in all sorts of ways (not least because the break might not be public). But that's the closest I'm coming up with to a rationale for that story.

    Open ##1710981

  • @djb Interesting. I didn't read their posts as making familiarity arguments at all (beyond the prior research time comparison), rather as background for complexity comparisons. I'll forward this to non-involved entities and ask them how they read this

    Open ##1710987