Re: Post-quantum defaults

"Robert J. Hansen via Gnupg-users" <[email protected]> Wed, 8 Apr 2026 11:05:12 -0400
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
> I think this article recently posted at Cryptography should get more
> attention:

I don't think Ray is a crackpot, let me start with that. His concern is 
real. If I were in his shoes I'd think the same.

But I'm not.

A little-known fact about the National Security Agency is it's also 
responsible for establishing the US Government's computer security 
policies. When it comes to securing classified information at the Top 
Secret level, NSA has established that government agencies must migrate 
to PQC effective immediately, and they're not especially picky about 
which PQC. The official guidance is worth reading:

https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF

My take is that if RSA-2048 is about to be decertified by the USG for 
securing Top Secret data, in favor of Crystals-Kyber and/or 
Crystals-Dilithium, we should take that as a strong hint NSA genuinely 
believes RSA-2048 may soon be threatened by foreign nation-states.

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQR9jsS4W2/t1sENPHkeepTU6H+R1QUCadZuqAUDAAAAAAAKCRAeepTU6H+R1b+k
AP4uV3D+td+t/4W9CB3yNEPNcgtRMj4fyyDu30fWJ0ny9AEAmyKRVMJpXlET9xeL36tFRec9rk3H
TPhlgMuo4g/LNQw=
=NcoW
-----END PGP SIGNATURE-----