Re: Plans for Post-Quantum Cryptography in GnuPG

Werner Koch via Gnupg-users <[email protected]> Mon, 13 Apr 2026 11:20:19 +0200
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
On Sun, 12 Apr 2026 22:37, Robert J. Hansen said:

> IMO, the necessary algorithms for PQC signing/certifying are not yet
> ready for primetime. Dilithium is obviously the biggest component of a

Right.  Experience from 30 years showed that deploying a stable and
secure signing system is much more challenging than an encryption
system.  Given that the claimed threat is store-now-maybe-decrypt-later
the deployment of signatures is not yet not needed.

Further, a new signing algorithm must we widely deployed before it can
be used.  The migration path for encryption is much easier: Add a Kyber
Subkey and implementations supporting this will encrypt using Kyber.
That is actually how we migrated to cv25519.


Shalom-Salam,

   Werner



#include <standard.pqc.disclamer.h>
/* https://www.cs.auckland.ac.nz/~pgut001/pubs/bollocks.pdf
 * https://media.gnupg.org/misc/Peter_Gutmann-Why_Quantum_Cryptanalysis_is_Bollocks-2025-11.mp4  */

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users
openpgp-digital-signature.asc (application/pgp-signature, 284 B)
-----BEGIN PGP SIGNATURE-----

iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCady1UxsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMSwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQeidOAQCE
i7qRpjstP23F2tP1nNksSq3J4Bsx3ri+j2dL6i9/iQD+KmKZ3C1KgKLPbgdWUc4o
ejr9q61H7Mi/PeebcQ7lzw4=
=JR+r
-----END PGP SIGNATURE-----