[saag] Re: [nasr] Re: Re: Re: Initial thoughts on NASR

"Meiling Chen" <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hi Stephen,


 
From: Stephen Farrell
Date: 2025-03-15 22:22
To: Michael Richardson; Christian Huitema; IETF SAAG
CC: nasr
Subject: [nasr] Re: [saag] Re: Re: Initial thoughts on NASR
 
(Also without expressing a broader opinion on NASR yet...)
 
On 15/03/2025 12:04, Michael Richardson wrote:
> 2) Capture Now, Decrypt after the CRQC concerns.  Some of this might be FUD,
>     but some of the concern is real.  Some of this has made into national
>     regulators.  Yes, this includes Traffic Analysis attacks.
>     So keep the "bad guys" from collecting the traffic in the first place.
 
The place it makes sense to try address this attack is at the same
place where the classical encryption is being done via the kinds of
hybrid KEM/KEX work already well underway for TLS, SSH, OpenPGP, etc.
 
Trying to address this specific threat at a different layer from the
classical encryption seems bogus to me - you'd never know whether or
not you've solved the problem as the classic ciphertext might appear
somewhere else to be recorded.

[Meiling] Indeed, ciphertext can appear elsewhere and be recorded,
but I think the ciphertext being known by N people is different from being known by one person, right?
Which type of risk is higher is obvious.
 
So this issue should be scratched as a justification in this context.
 
Cheers,
S.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.