Elektrine lite

← Feed

@djb@mastodon.cr.yp.to

Post #3517835

2026-06-29 11:59 UTC

@Savagejen@mastodon.social Looking at the whole attack surface makes even more obvious that solo PQ damages security. We've already seen exploitable bugs and timing attacks for Dilithium (ML-DSA) and Kyber (ML-KEM)! Check out https://cr.yp.to/papers/mldsa-20260601.pdf#breakable-keys for a graph of the estimated number of ML-DSA keys that will be broken because of predictable software vulnerabilities even if there are _no_ breaks of the ML-DSA spec. For ML-KEM a similar calculation shows an even bigger disaster.

Replies (1)

  • @cazabon@mindly.social 2026-07-01 02:18

    @djb@mastodon.cr.yp.to You're not kidding about the NSA-backed participants' bad-faith support for specifying PQ-only rather than a belt-and-braces approach. There's an argument on the list right now, and the NSA shill is arguing based on the (unspoken but obvious) assumption that being cracked by quantum computers is the only threat you need to base your decision on. "If that happens, ECC won't help you". Sheesh.

    Open ##3517834