News: 1664821358

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

It's 2058. A quantum computer is just another decade away. Still, you curse Cloudflare

(2022/10/03)


Cloudflare is the first major internet infrastructure provider to support post-quantum cryptography for all customers, which, in theory, should protect data if quantum computing ever manages to break today's encryption technologies.

Starting today all websites and APIs served through Cloudflare support post-quantum TLS based on the Kyber hybrid key agreement. Specifically, the new beta service supports the X25519Kyber512Draft00 and X25519Kyber768Draft00 key agreements using TLS identifiers 0xfe30 and 0xfe31, respectively.

The service is free, and it's on by default — so no need for customers to opt in. It's a [1]hybrid key agreement in that it combines [2]X25519 , which is used in TLS 1.3 but still vulnerable to future quantum attacks, and the new, post-quantym Kyber512 and Kyber768.

[3]

"That means that even if Kyber turns out to be insecure, the connection remains as secure as X25519," Cloudflare researchers Bas Westerbaan and Cefan Daniel Rubin [4]explained .

[5]

[6]

Kyber, so far, is the only key agreement that the US National Institute of Standards and Technology (NIST) has [7]officially selected for standardization. NIST plans to finalize this standardization in 2024, and there may be new standards to come.

This, in part, is why Cloudflare is only offering this as a beta service: Kyber will likely change in backwards-incompatible ways before it's finalized, and the integration with TLS hasn't been finalized by the TLS working group, either.

[8]

In their blog post, Westerbaan and Rubin pledged to post updates on Cloudflare's post-quantum key agreement support on [9]pq.cloudflareresearch.com and announce it on the [10]IETF PQC mailing list .

Carry on up the Kyber

While quantum computers' ability to crack classic cryptography is still years away — from 15 to 40 years

[11]PDF

in the future to [12]possibly never , depending on who you believe — when and if these machines become powerful enough to decrypt anything on the Internet they will be able to expose state secrets in seconds.

Some infosec and technology consultants have warned that China and others are [13]stealing data now to decrypt later , when quantum computing matures enough to do so.

However, as Cloudflare's researchers outline, deploying post-quantum cryptography comes with risks, too. For starters, it's brand-new cryptography, and sometimes new things that haven't been tested for years break. Case in point: the [14]roll-out of TLS 1.3 , which didn't go as smoothly as planned.

"Even though the protocols used to secure the Internet are designed to allow smooth transitions like this, in reality there is a lot of buggy code out there: trying to create a post-quantum secure connection might fail for many reasons — for example a middlebox being confused about the larger post-quantum keys and other reasons we have yet to observe because these post-quantum key agreements are brand new," Westerbaan and Rubin said.

[15]

"It's because of these issues that we feel it is important to deploy post-quantum cryptography early, so that together with browsers and other clients we can find and work around these issues," they added.

[16]Actual quantum computers don't exist yet. The cryptography to defeat them may already be here

[17]Post-quantum crypto cracked in an hour with one core of an ancient Xeon

[18]Protecting data now as the quantum era approaches

[19]NSA: We 'don't know when or even if' a quantum computer will ever be able to break today's public-key encryption

By deploying well ahead of 2024, Cloudflare and others should have sufficient time to work out any kinks and protect data from quantum attacks, we're told.

Gartner's Mark Horvath, a senior director with the analyst firm, said the move is a "big help" to the industry, "and a great step forward for moving toward a quantum-safe future."

"Post-quantum encryption is expected to have a huge impact on infrastructure, operations and data security over the next decade, and testing protocols like TLS at realistic speeds and volumes helps the industry move forward in a smooth way," Horvath told The Register .

"While dual-signed certificates and other support for post-quantum operations have been introduced occasionally in the past, it's only now that the NIST contest is reaching the standardization phase that we have real tools to work with on issues like protocols that have a huge future impact." ®

Get our [20]Tech Resources



[1] https://datatracker.ietf.org/doc/draft-stebila-tls-hybrid-design/

[2] https://www.rfc-editor.org/rfc/rfc8410

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YztbeaZNN74azz13@bFZvgAAAMU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://blog.cloudflare.com/post-quantum-for-all/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YztbeaZNN74azz13@bFZvgAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YztbeaZNN74azz13@bFZvgAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/07/05/nist_quantum_resistant_algorithms/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YztbeaZNN74azz13@bFZvgAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] http://pq.cloudflareresearch.com/

[10] https://www.ietf.org/mailman/listinfo/Pqc

[11] https://globalriskinstitute.org/download/quantum-threat-timeline-report-2021-full-report/

[12] https://www.theregister.com/2021/09/01/nsa_quantum_computing_faq/

[13] https://www.theregister.com/2021/11/29/china_quantum_ai_offensive/

[14] https://blog.cloudflare.com/why-tls-1-3-isnt-in-browsers-yet/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YztbeaZNN74azz13@bFZvgAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://www.theregister.com/2022/07/05/nist_quantum_resistant_algorithms/

[17] https://www.theregister.com/2022/08/03/nist_quantum_resistant_crypto_cracked/

[18] https://www.theregister.com/2022/05/20/quantum-security-qusecure/

[19] https://www.theregister.com/2021/09/01/nsa_quantum_computing_faq/

[20] https://whitepapers.theregister.com/



China and others are stealing data now to decrypt later

that one in the corner

"and others" being absolutely everyone who can get of the traffic. But make sure to deflect notice from the "Good" (?) guys by only naming the Big Bad du jour.

The Seventh Edition licensing procedures are, I suppose, still in effect,
though I doubt that tapes are available from AT&T. At any rate, whatever
restrictions the license imposes still exist. These restrictions were and
are reasonable for places that just want to run the system, but don't allow
many of the things that Minix was written for, like study of the source in
classes, or by individuals not in a university or company.

I've always thought that Minix was a fine idea, and competently done.

As for the size of v7, wc -l /usr/sys/*/*.[chs] is 19271.

-- Dennis Ritchie, 1989