Elektrine lite

← Feed

@gregprice@sfba.social

Post #1710981

2026-04-18 05:58 UTC

@djb I don't understand why these folks say that the motivation for hybrid schemes is about "harvest now, decrypt later". Seems a lot more straightforward than that: if you deploy a new PQ scheme on its own, and then someone has a break in that scheme, that's bad! That's bad if it means they can forge signatures, just like it's bad if it means they can decrypt messages. Whereas if instead you deployed a hybrid with a non-broken scheme, then you're still secure. Are they… assuming that if there is such a break, everyone will just switch right back to a proven scheme? That seems confused in all sorts of ways (not least because the break might not be public). But that's the closest I'm coming up with to a rationale for that story.

Replies (2)

  • @Elliptickiwi@ioc.exchange 2026-04-19 06:01

    @gregprice @djb my understanding of their logic is that they actually believe quantum computing is just around the corner and that ECC is already essentially worthless. This is not my opinion. More generally, I think it is poor risk management to not consider a wider range of possible futures.

    Open ##1710982

  • @omnicore@ieji.de 2026-04-19 06:48

    @gregprice @djb Using hybrid ECC+PQ is a no brainer. Everything else is at least "strange".

    Open ##1710986