Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The classical cipher component is additonal complexity in the protocol and maybe some meaningful amount of additonal time to compute and key data to store/transmit, is it not? I can see why we'd like to avoid effectively encrypting the same data twice with different protocols, one of which is known to be vulnerable to quantum computer based attacks.


Classic ciphers are damn fast and small compared to PQC. If you're doing PQC anyway, doing classical cryptography at the same time has negligible cost.

That makes attempts to push PQC-only modes super suspicious to me. Smells like Dual_EC_DRBG.


I recommend reading https://keymaterial.net/2025/11/27/ml-kem-mythbusting/, which explains (1) why it's not possible for ML-KEM (the thing most people are using for post-quantum encryption) to be backdoored the way Dual_EC_DRBG was, and (2) some of the reasons some people don't like hybrids, not all of which are good but none of which should serve to undermine confidence in ML-KEM's security.


good thing quantum computers that can factor numbers have never been built. No number was ever really factored without cheating, the actual shor's algorithm has never been implemented. And we're not really any closer to


That last sentence is not true; we have gotten much closer to building a quantum computer that can run Shor's algorithm. Organizations like Google and Cloudflare have declared a 2029 deadline to completely stop depending on the security of pre-quantum algorithms; hitting that deadline is going to cost a lot of engineering resources, but they're paying that cost because they think there's too great a chance that nation-state adversaries will have scalable quantum computers by then. See https://words.filippo.io/crqc-timeline/ and the various posts linked therein, including from the aforementioned companies.


I don't trust promises from the ones who stand to gain from people believing them before they are delivered. Yes they claim it's jsut a couple of years out... we'll see then


Are you saying we shouldn't trust cryptographers, because there'll be more demand for their services if we need to urgently migrate to post-quantum algorithms? That seems a very radically-skeptic perspective that makes it hard to know anything, and I doubt any serious engineer applies it in the general case. Or were you talking about someone else?

In any rate, nobody (or at least none of the people I've heard from) is claiming we'll definitely have CRQCs by 2029. They're saying there's a real chance that we will, and that that means now's the time to pull the trigger on post-quantum migrations; if we wait for certainty, it'll be too late. Quoting Valsorda from the post I linked above (which I strongly recommend reading in full):

> If you are thinking “well, this could be bad, or it could be nothing!” I need you to recognize how immediately dispositive that is. The bet is not “are you 100% sure a CRQC will exist in 2030?”, the bet is “are you 100% sure a CRQC will NOT exist in 2030?” I simply don’t see how a non-expert can look at what the experts are saying, and decide “I know better, there is in fact < 1% chance.” Remember that you are betting with your users’ lives.

> Put another way, even if the most likely outcome was no CRQC in our lifetimes, that would be completely irrelevant, because our users don’t want just better-than-even odds of being secure.


i don't trust google


The above post cites a number of people and organizations other than Google.


Have they factored 21 yet? That metric hasn't changed for some time.


That's not a very useful benchmark if the thing you care about is CRQC timelines. See https://bas.westerbaan.name/notes/2026/04/02/factoring.html (which the above post links to) for an explanation of why.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: