Elektrine lite

← Feed

@filippo@abyssdomain.expert

Post #949760

2026-03-26 15:43 UTC

Last year, my position was that we still had time to design PQ authentication mechanisms. Now, based on the pace of progress and on statements like Google's, I believe: 1. we need to finish rolling out PQ key exchange yesterday 2. we need to start rolling out PQ auth now 3. it's too late to ship any new non-PQ design or system https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/

Replies (6)

  • @filippo I like their aggressive timeline, but I'm not sure there's any specific argument or reason that explains why it should be expedited. Am I missing something?

    Open ##1074195

  • @fay59@tech.lgbt 2026-03-26 15:53

    @filippo too late forever or too late for initial deployments?

    Open ##1074196

  • @ikke@ipv6.social 2026-03-26 16:07

    @filippo Interesting, I just cam across https://infosec.exchange/@mttaggart/116163107290977793 the other day, basically saying that it won't be feasible any time soon.

    Open ##1074197

  • @Ciantic@twit.social 2026-03-26 16:21

    @filippo You got me interested to know what it would look like in authorized_keys, and can it be this short! Looks neat. ssh-mldsa44-ed25519 434f4d505349472d4d4c44534134342d456432353531392d534841353132 https://datatracker.ietf.org/doc/draft-sun-ssh-composite-sigs/02/

    Open ##1074199

  • @alxndr@tech.lgbt 2026-03-27 16:45

    @filippo Oh, did Google announce their intent to buy 40% of the world's 8-bit home computers and/or dogs?

    Open ##1074200

  • @flux@mastodon.unwi.re 2026-04-06 17:46

    @filippo @cryptohagen are you following this? :)

    Open ##1074205