Elektrine lite

← Feed

@bartavi@mastodon.nl

Post #1710984

2026-04-20 09:34 UTC

@gregprice @Elliptickiwi @djb if I understand correctly, their argument is that maintaining hybrids is not cheap, given the complexity of hybrid key management and, according to them, the vulnerabilities resulting from that complexity. Add to that that PQC has to work anyway, so they pour all their resources into that. I mean, I can understand that.

Replies (1)

  • @bartavi @gregprice @Elliptickiwi @djb But really you just do the same stuff with two different algorithms, there is no substantial complexity in the combination step. And if say your implementation has a timing attack in one of the algorithms, that is still only good for breaking that part. The redundancy is actually a shield against lots of different attack vectors that have nothing to with quantum stuff.

    Open ##1710985