Re: LUKS and quantum computing

Arno Wagner <[email protected]> Tue, 26 Nov 2024 09:39:01 +0100
Newsgroups dev.linux.lists.cryptsetup
Message-ID <[email protected]>
No idea. And frankly, I have stopped caring. "Quantum Computing" is
a Fata Morgana that does not amount to anything practical at this 
time (after 50 years of resarch) and may well never amount to anything.  
It will certainly not be a real treat in the foreseeable future.

Here is what Peter Gitman thinks of the topic, and I think it
is spot on: https://www.cs.auckland.ac.nz/~pgut001/pubs/bollocks.pdf

Regards,
Arno


On Mon, Nov 25, 2024 at 23:13:17 CET, Patrick Callaghan wrote:
> If we use LUKS encryption with SHA-256 configured (i.e.  the default), is
> this considered safe against attacks by quantum computers? 
> 
> I ask because NIST suggests SHA512 in general for quantum safe algorithms
> (see "old Q17" in
> https://csrc.nist.gov/projects/post-quantum-cryptography/faqs) and we want
> to be LUKS quantum safe now and for several years to come, even if no
> practical attacks currently exist.
> 
> Note, the cipher we use is "aes-xts-plain64" so we have no question about
> this as AES with 256-bit keys is considered quantum safe. 
> 
> Thank you.

-- 
Arno Wagner,     Dr. sc. techn., Dipl. Inform.,    Email: [email protected]
GnuPG: ID: CB5D9718  FP: 12D6 C03B 1B30 33BB 13CF  B774 E35C 5FA1 CB5D 9718
----
A good decision is based on knowledge and not on numbers. -- Plato

If it's in the news, don't worry about it.  The very definition of 
"news" is "something that hardly ever happens." -- Bruce Schneier