Post #3517836
2026-06-29 11:49 UTC
@djb@mastodon.cr.yp.to Using both allows you to fall back on the old standard if the math on the new one is wrong, but I'm guessing this is less about the actual math and more about attack surface. The only thing I can think is that they are worried about something akin to a parser attack and are using this push for solo-pq as an excuse because they can't say that.
Replies (1)
-
@djb@mastodon.cr.yp.to 2026-06-29 11:59
@Savagejen@mastodon.social Looking at the whole attack surface makes even more obvious that solo PQ damages security. We've already seen exploitable bugs and timing attacks for Dilithium (ML-DSA) and Kyber (ML-KEM)! Check out https://cr.yp.to/papers/mldsa-20260601.pdf#breakable-keys for a graph of the estimated number of ML-DSA keys that will be broken because of predictable software vulnerabilities even if there are _no_ breaks of the ML-DSA spec. For ML-KEM a similar calculation shows an even bigger disaster.