[saag] Re: post quantum guidance draft

Peter Gutmann <[email protected]> Wed, 3 Dec 2025 14:44:32 +0000
Newsgroups gmane.ietf.saag
Message-ID <ME0P300MB0713948041948353D123EC1EEED9A@ME0P300MB0713.AUSP300.PROD.OUTLOOK.COM>
Nico Williams <[email protected]> writes:

>But it's key agreement where we need this, not signatures.

It's also in key agreement where, after 20 years work and hundreds of millions
of dollars spent, no-one has ever demonstrated how to break the most trivial
value using a quantum physics experiment.  No-one has even tried to claim a
result for a two-bit integer let alone a 2048-bit one (or 256-bit if you're
using ECDH rather than FFDH).  We're debating how to protect against fairies
and unicorns, not actual threats, in which case the draft could advise users
to do things like making sure the connection is anonymous (knowing your real
name gives fae power over you, TLS 1.3 already deals with this), although
other advice like carrying cold iron to deter them may be a bit more difficult
to translate into crypto terms.  Perhaps a new TLS extension could be defined
to deal with this.

Peter.
_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]