[saag] Re: [nasr] Re: Re: Re: Initial thoughts on NASR

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CABcZeBMUyg3YKXox-p3DZNvmXYtb5TsXnfHvVPtSwDoO1bDiMQ@mail.gmail.com>
On Sat, Mar 15, 2025 at 7:23 AM Stephen Farrell <[email protected]>
wrote:

>
> (Also without expressing a broader opinion on NASR yet...)
>
> On 15/03/2025 12:04, Michael Richardson wrote:
> > 2) Capture Now, Decrypt after the CRQC concerns.  Some of this might be
> FUD,
> >     but some of the concern is real.  Some of this has made into national
> >     regulators.  Yes, this includes Traffic Analysis attacks.
> >     So keep the "bad guys" from collecting the traffic in the first
> place.
>
> The place it makes sense to try address this attack is at the same
> place where the classical encryption is being done via the kinds of
> hybrid KEM/KEX work already well underway for TLS, SSH, OpenPGP, etc.
>

Precisely.

-Ekr

>
> Trying to address this specific threat at a different layer from the
> classical encryption seems bogus to me - you'd never know whether or
> not you've solved the problem as the classic ciphertext might appear
> somewhere else to be recorded.
>
> So this issue should be scratched as a justification in this context.
>
> Cheers,
> S.
>
> --
> nasr mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.