Damus
Daniel J. Bernstein · 6w
Some energy numbers for breaking a post-quantum proposal, SIKEp751: https://eprint.iacr.org/2023/376 reports 11 seconds to break one key on a mass-market Intel Xeon Gold 6248R. That's a 200-watt CPU; ...
Stephan Neuhaus profile picture
@nprofile1q... These proposals are broken so quickly that it would be a good idea IMO to put the brakes on any attempt at standardising them. But if one absolutely must standardise, then at least standardise hybrids, for crying out loud.
1
Daniel J. Bernstein · 6w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpn3082tr4276sm3jq56f5crdcrtxkm805902a7xc7mut2pw4p6lsdz4nyz Well, the problem with _not_ rolling anything out is that then we're not even _trying_ to deal with the quantum risk. Hybrids (double encryption, double signatures) nicely resolve this ...