@matthewdgreen.bsky.social@bsky.brid.gy
Post #3477185
2026-06-29 20:20 UTC
This is fine for long-term needs like encryption. It’s silly for short-term stuff like authentication. As long as there’s an upgrade path, your signature scheme or ZKP isn’t going to get smacked by someone’s secret quantum computer. You’ll see the quantum computers coming and upgrade.
Replies (1)
-
@SteveBellovin@infosec.exchange 2026-06-29 20:34
@matthewdgreen.bsky.social Up to a point, you're right. There's exactly no need now to switch algorithms. However… Certificates are often used for both, and for some digital signature uses you want the validity to be good for 20+ years. More seriously, if you've never needed a second algorithm, your protocol may not support it when you do need to convert; see, e.g., https://www.cs.columbia.edu/~smb/papers/new-hash.pdf, by myself and @ekr@infosec.exchange, when it was suddenly time to move on from MD5 and SHA-1.