Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bwesterb
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
bwesterb
7d ago
There's no store-now/decrypt-later, but DNS is notoriously slow to make any changes. Better start early. We're running probes from our challenge pas to the test zone, so we see how much breaks with these large signatures. If
2.
▲
by
bwesterb
7d ago
I like how an ML-DSA-44 RRSIG ends with a string AAAAAAAAAAAAAAAAAAA... a scream of relief it's finally out.
3.
▲
by
bwesterb
5mo ago
Most approaches have missing "capabilities" that can be tracked. Adam Zalcman lays them out for superconducting qubits here. https://westerbaan.name/~bas/rwpqc2026/adam.pdf For the neutral atoms approach
4.
▲
by
bwesterb
5mo ago
Scott used to be that guy.
5.
▲
by
bwesterb
5mo ago
The abacus thing is pretty funny, but it's dangerously uninformed. https://bas.westerbaan.name/notes/2026/04/02/factoring.html
6.
▲
by
bwesterb
5mo ago
It'll be a 90/10 rule: 90% of the upgrades will be straightforward. It's important the 10% that'll be hard early. For many it's probably already too late.
7.
▲
by
bwesterb
5mo ago
QKD is cool and all, but it just doesn't scale to the whole Internet. https://blog.cloudflare.com/you-dont-need-quantum-hardware/
8.
▲
by
bwesterb
5mo ago
Where available, you can migrate. Even if PQ is not yet available it helps to: 1. Make sure your dependencies are up to date. Move to a recent version of your crypto libraries. 2. Make sure your server can install multiple certificates: you
9.
▲
by
bwesterb
5mo ago
We're almost done countering store-now/decrypt-later, but the biggest part of the job, post-quantum authentication, still remains. Like Google, we target 2029 to be done .
10.
▲
by
bwesterb
5mo ago
SSH is working on a drop-in as we speak. TLS is further along: most stacks already support X25519MLKEM768 (by default!) to counter store-now/decrypt-later. PQ certs are not widely supported yet, but that's being sped up as we spea
11.
▲
Will you heed my warnings now?
(scottaaronson.blog)
89 points
by
bwesterb
5mo ago
|
102 comments
12.
▲
by
bwesterb
5mo ago
When it's real, it's too late.
13.
▲
by
bwesterb
5mo ago
You sure? Defenders get funding if things break—not when they actually did their job.
14.
▲
by
bwesterb
5mo ago
Yeah, it's rough. Important to understand now for each product / system what the business impact is if it's not upgraded in time.
15.
▲
by
bwesterb
5mo ago
They are large, but they're not that slow actually. We've been testing them for almost a decade now. I agree that rushing is bad. That's why we need to start moving now, so that we're not rushing even closer to the deadl
16.
▲
by
bwesterb
5mo ago
Yeah, PQ certificate transparency is crucial for downgrade protection: https://westerbaan.name/~bas/rwpqc2026/bas.pdf
17.
▲
by
bwesterb
5mo ago
> I could also be misremembering our conversation, but I thought you had said something like 2029 or 2030 in our 2020 conversation Think that must've been around 2022. It'd have been me mentioning 2030 regulatory deadlines. So
18.
▲
by
bwesterb
5mo ago
No need for a TLS 1.4. Leaf certificates don't last long, but root CAs do. An attacker can just mint new certs from a broken root key. Hopefully many devices can be upgraded to PQ security with a firmware update. Worse than not receivi
19.
▲
by
bwesterb
5mo ago
Waiting now means rushing even more close to the deadline! We added stats on origin support for post-quantum encryption. Not as much support as browsers of course, but better than I expected. Still a long road (and authentication!). https:
20.
▲
by
bwesterb
5mo ago
If we do our job, it changes nothing. Problem with security generally: no spectacle if it's all correct. :)
21.
▲
by
bwesterb
5mo ago
At least it's time bound: hope to have this job done by 2029!
22.
▲
by
bwesterb
5mo ago
Don't recognise you from your username, but thanks for the respect. (Update: ah, Vitali! Nice to hear from you.) If you look back at my writing from 2025 and earlier, I'm on the conservative end of Q-day estimates: 2035 or later.
23.
▲
by
bwesterb
7mo ago
The key will be 40x larger. Not that bad for the certs. It'll be about 15kB extra. Will depend on your use case if that's bad. For video it's fine. But not all browsing is video. At Cloudflare half of the QUIC connections we
24.
▲
by
bwesterb
7mo ago
Also just now Chrome published https://www.chromium.org/Home/chromium-security/post-quantum...
25.
▲
by
bwesterb
7mo ago
Yeah, filed https://github.com/mozilla/ssl-config-generator/issues/342
26.
▲
by
bwesterb
7mo ago
Merkle Tree Certificates basically uses the same structure as Certificate Transparency today. Merkle Ladder uses a weird variation claimed to be useful to DNSSEC. I think it's rather just to seem novel ( https://datatracker.
27.
▲
by
bwesterb
10mo ago
Client would check perhaps once a day. Similar to how Chrome checks about once a day for urgent revocations.
28.
▲
by
bwesterb
11mo ago
Also MTC is usable for everyone. Perfectly fits an automation-forward webserver like Caddy.
29.
▲
by
bwesterb
11mo ago
Yeah, this is going to take time. That is why we're starting now.
30.
▲
by
bwesterb
11mo ago
AES-128 also can't be cracked by quantum computers.
More ›