mastodon.online is one of the many independent Mastodon servers you can use to participate in the fediverse.
A newer server operated by the Mastodon gGmbH non-profit

Server stats:

11K
active users

#pqc

4 posts4 participants0 posts today
Continued thread

Lo and behold, #OpenSSL 3.5 (their upcoming LTS release) will come out here at the beginning of April, and it does indeed support some of these hybrid PQC schemes. Their recent beta2 announcement can be read here: openssl-library.org/post/2025- and their roadmap is at openssl-library.org/roadmap/in

Very excited by this work. Big kudos to the OpenSSL Team here! 🥳🎉 Already planning on giving this a spin with the C implementation of #Tor later this week to see how it goes!

OpenSSL Library · OpenSSL 3.5 Beta Release AnnouncementThe OpenSSL Project is pleased to announce that OpenSSL 3.5 Beta1 pre-release is released and adding significant new functionality to the OpenSSL Library.

UK urges critical orgs to adopt quantum cryptography by 2035

The UK's National Cyber Security Centre (NCSC) has published specific timelines on migrating to post-quantum cryptography (PQC), dictating that critical organizations should complete migration by 2035.

#PQC #quantum #cryptography #encryption #UK #security #cybersecurity #hacking #infosec

bleepingcomputer.com/news/secu

BleepingComputer · UK urges critical orgs to adopt quantum cryptography by 2035By Bill Toulas

The NCSC’s advisory deadline of 2035 for organisations to introduce quantum-safe algorithms is too late, according to some industry insiders.

The NCSC’s advisory deadline of 2035 for organisations to introduce quantum-safe algorithms is too late, according to some industry insiders.

computing.co.uk/news/2025/secu

www.computing.co.ukNCSC’s quantum safety deadlines too optimistic say industry insiders‘I’d halve all those numbers’
#ncsc#quantum#pqc
Continued thread

🧵 …ja und nein und vor allem ist es Marketing durch Angstmacherei. Quantenkomputer sind noch nicht wirklich einsetzbar obwohl es viele als solches gerne vermarkten.

»Quantenschlüssel aus der Sicht des CISO:
Quantentechnologien – ein Sicherheitsrisiko oder das Mittel der Wahl gegen Cyberangriffe? Warum, für wen und wo es wichtig ist, die Integration von Quantentechnologien zu starten.«

⚛️ csoonline.com/article/3846875/

CSO OnlineQuantenschlüssel aus der Sicht des CISOQuantentechnologien: ein Sicherheitsrisiko oder das Mittel der Wahl gegen Cyberangriffe? Warum, für wen und wo es wichtig ist, die Integration von Quantentechnologien zu starten.

»The Quantum Apocalypse Is Coming. Be Very Afraid:
What happens when quantum computers can finally crack encryption and break into the world’s best-kept secrets? It’s called Q-Day—the worst holiday maybe ever.«

Since this is very much for us, I cannot deny it, but I see it as a marketing propaganda. To scare is also a marketing strategy.

👾 wired.com/story/q-day-apocalyp

WIRED · The Quantum Apocalypse Is Coming. Be Very AfraidBy Amit Katwala
Continued thread

Out of the top 100K domains, roughly 28K negotiate a quantum safe key exchange.

Almost all of those support both x25519_kyber768 and X25519MLKEM758; only 129 sites support SecP256r1MLKEM768. There are _no_ sites that support pure #PQC via e.g., mlkem768.

The overwhelming majority of sites that support PQC do so by way of Cloudflare. That percentage matches Cloudflare's overall coverage of the top 1M domains.

Continued thread

🧵 …neben dem vorhin erwähnten Marketing bezüglich des Post-Quantom Kryptografie ist darauf hin auch wieder die Angsmacherei davon. Das die mal angewendet wird ist klar aber wie ist die Frage.

»Ihre Passwörter sind bald wertlos: Quantencomputer knacken alles!
Quantencomputer revolutionieren die Rechenleistung. Sie lösen hochkomplexe Aufgaben in Sekundenschnelle. Doch die Technologie birgt auch Gefahren.«

⚛️ telepolis.de/features/Ihre-Pas

heise online · Ihre Passwörter sind bald wertlos: Quantencomputer knacken alles!By Christoph Jehle
Continued thread

I have written a new white-paper for Far Phase, where I analysed the most popular Australian banking websites (18 in all) and found that **none** of them protected people from quantum threats. This is despite bank interactions being 99% via websites and apps, and banks holding some of the most sensitive, long-lived data. Yet, nearly 40% of global secure web traffic is protected from quantum threats, and even the Google search engine offers this protection. Australians would not expect that a search engine offers better post-quantum protection for their sensitive data than Australia's biggest banks. With technology enablers making this easier to implement in the next couple of months, Australian banks should urgently update their websites to protect their users.
farphase.com/white-paper-on-au
#quantum #pqc #australia #banking #cybersecurity #farphase #whitepaper

UK cybersecurity agency National Cyber Security Centre is recommending that organisations start replacing existing asymmetric public key cryptosystems with post-quantum cryptography (PQC) alternatives to defend themselves against quantum computers

computing.co.uk/news/2025/secu

www.computing.co.ukQuantum computing is coming for your cryptography, warns NCSCNo need to panic just yet, but plans to move to quantum-safe alternatives should be in place by 2028 at the latest

I was just ranting about #QKD in a chat with someone, when I compared quantum-resiliant cryptography with quantum key distribution like this, and noticed that I really like this summary:

If you want to go 500 meter down the street you can either take your bike or call a helicopter to your place, have it hover over your home, climb up a rope ladder, have it fly you those 500 meters and dis-rope.
Both of these get you to your destination, but one of them is faster, cheaper, less complicated, relying on more established infrastructure, scales better and is just about superior in every relevant regard. And it’s not the helicopter/QKD.

#crypto #cryptography #pqc #quantumcryptography #QuantumKeyDistribution