Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Signal
@signalapp@mastodon.world  ·  activity timestamp 7 hours ago

In 2023, Signal was the first mainstream messenger to enable post-quantum cryptography. We’re still ahead of the (elliptical) curve, implementing a new hybrid PQ ratchet ensuring Forward Secrecy & Post-Compromise Security even in a post-quantum world. https://signal.org/blog/spqr/

Signal Messenger

Signal Protocol and Post-Quantum Ratchets

We are excited to announce a significant advancement in the security of the Signal Protocol: the introduction of the Sparse Post Quantum Ratchet (SPQR). This new ratchet enhances the Signal Protocol’s resilience against future quantum computing threats while maintaining our existing security guar...
  • Copy link
  • Flag this post
  • Block
Josh Conway :donor:
@crankylinuxuser@infosec.exchange replied  ·  activity timestamp 2 minutes ago

@signalapp

And you still require a fucking phone number to make an account.

"Whoop doop we're post quantum encryption but you still have your phone number and give away ALL your metadata and who you call!"

  • Copy link
  • Flag this comment
  • Block
TagHunt
@TagHunt@infosec.exchange replied  ·  activity timestamp 2 hours ago

@signalapp
Amazing work you guys are doing!

Though I'd like to see some community oriented features like spaces and/or moderation tools

Still my most favorite messenger
Keep up the good work!

  • Copy link
  • Flag this comment
  • Block
stony kark
@aapis@mastodon.world replied  ·  activity timestamp 2 hours ago

@signalapp @Em0nM4stodon I mean yay, but you say that like quantum computing isn’t a complete waste of time and money

  • Copy link
  • Flag this comment
  • Block
Nicola
@nicolaborsetto@mastodon.uno replied  ·  activity timestamp 4 hours ago

@signalapp wow 😲

  • Copy link
  • Flag this comment
  • Block
Patrick
@pu@ieji.de replied  ·  activity timestamp 4 hours ago

@signalapp Fascinating! Thanks for the great work, you make the world a safer place.

  • Copy link
  • Flag this comment
  • Block
L29Ah@qoto.org
@L29Ah@qoto.org replied  ·  activity timestamp 5 hours ago

@signalapp > ML-KEM 768
https://blog.cr.yp.to/20231125-kyber.html this one, right?

  • Copy link
  • Flag this comment
  • Block
Póg mo Joan 🏳️‍🌈🏳️‍⚧️😷
@clickhere@mastodon.ie replied  ·  activity timestamp 4 hours ago

@benroyce

Thank you for this!

(I read the original post, and all I could think was: "I like cake.")

@erikcats @signalapp

  • Copy link
  • Flag this comment
  • Block
SteveJB
@SteveJB@mastodon.social replied  ·  activity timestamp 4 hours ago

@benroyce @erikcats @signalapp Michael Chrichton wrote about this (Prey? maybe). One of the (fictional) points he made was that brute force had been pushed to high levels using quantum computing. But the Gov't continued to push the idea that they couldn't decode high level encryption so that 'bad players' would continue to use encryption that had been compromised.

  • Copy link
  • Flag this comment
  • Block
Ben Royce 🇺🇦
@benroyce@mastodon.social replied  ·  activity timestamp 4 hours ago

@vnikolov @jwcph @erikcats @signalapp

the great weakness of all fascists is their arrogance and hubris. when they surround themselves with yes men and push lies over truth, they fall for their own bullshit about "superiority"

  • Copy link
  • Flag this comment
  • Block
Vassil Nikolov | Васил Николов
@vnikolov@ieji.de replied  ·  activity timestamp 5 hours ago

Possible, but maybe far from certain.

Breaking the Enigma wasn't really smooth sailing.
It had its ups and downs during the most critical years,
but those can't be summarized in 100 words.
Also the Germans helped by overestimating the strength of the Enigma and thus neglecting some measures that would have been in their interest.

The Venona project is also instructive.
It achieved a lot and yet decrypted a small part of all intercepted messages.

@benroyce @jwcph @erikcats @signalapp

  • Copy link
  • Flag this comment
  • Block
Ben Royce 🇺🇦
@benroyce@mastodon.social replied  ·  activity timestamp 5 hours ago

@gbargoud @erikcats @signalapp 🤮

  • Copy link
  • Flag this comment
  • Block
George B
@gbargoud@masto.nyc replied  ·  activity timestamp 5 hours ago

@benroyce @erikcats @signalapp

I really really do not want to see a picture of his dick. I'm certain that's in like half of them.

  • Copy link
  • Flag this comment
  • Block
Ben Royce 🇺🇦
@benroyce@mastodon.social replied  ·  activity timestamp 5 hours ago

@gbargoud @erikcats @signalapp

OOOOH

all those trump land encrypted messages will be seen in the future

that's a great bit of news

  • Copy link
  • Flag this comment
  • Block
George B
@gbargoud@masto.nyc replied  ·  activity timestamp 5 hours ago

@benroyce @erikcats @signalapp

As mentioned elsewhere, we don't have quantum computing but one big issue is that some people are banking on it existing in the future and are hoovering up encrypted data that they will later be able to crack if they are correct.

  • Copy link
  • Flag this comment
  • Block
rhempel
@rhempel@mstdn.ca replied  ·  activity timestamp 5 hours ago

@mkj @benroyce @erikcats @signalapp is there an actual example of a current quantum computer breaking even a simple rot13 encryption?

  • Copy link
  • Flag this comment
  • Block
Ben Royce 🇺🇦
@benroyce@mastodon.social replied  ·  activity timestamp 5 hours ago

@mkj @erikcats @signalapp

yeah that's my understanding as well

"you can break this but you need a bank of 1 billion computers operating for 1 billion years, so..."

{quantum computing enters the chat}

"oops"

so you just change the method to something that is not so vulnerable to quantum computing

  • Copy link
  • Flag this comment
  • Block
mkj
@mkj@social.mkj.earth replied  ·  activity timestamp 5 hours ago

Bottom line, I guess, is that there are plenty of nuances here which I am happy to let people who know the stuff much better than I do handle; but it's not quite as clear-cut as "the whole world will break" as it is sometimes presented.

There's a number of detail assumptions which may or may not turn out to be true which impact the actual result. But taking a cautionary stance, we do know that the risk is non-trivial and thus taking mitigative steps is good.

@benroyce @erikcats @signalapp

  • Copy link
  • Flag this comment
  • Block
mkj
@mkj@social.mkj.earth replied  ·  activity timestamp 5 hours ago

@benroyce I'm not an expert either. My understanding is that for example modular multiplication math (which is used for almost all classical public key cryptographic algorithms, both encryption and signing) is potentially highly impacted by QC; but much math used for symmetric-key encryption and for hashing is significantly less affected. E.g., the effective security of AES-256 is reduced to ~ AES-128, BUT that also assumes QC operations are similar to classical operations.

@erikcats @signalapp

  • Copy link
  • Flag this comment
  • Block
Ben Royce 🇺🇦
@benroyce@mastodon.social replied  ·  activity timestamp 6 hours ago

@mkj @erikcats @signalapp

is it Winternitz One-Time Signatures/ Lamport signatures?

i'm not a cryptographer but this stuff fascinates me

https://en.wikipedia.org/wiki/Lamport_signature

  • Copy link
  • Flag this comment
  • Block
Charo del Genio
@paraw@mathstodon.xyz replied  ·  activity timestamp 6 hours ago

@benroyce @jwcph @erikcats @signalapp well, one of the problems is making sure the errors stay within certain limits of acceptability (stay "bounded", as we say). There are also other issues, such as hardware scalability, but these will become less important as technology progresses. Just think how much computers have advanced in the last 40 years!

  • Copy link
  • Flag this comment
  • Block
Log in

Open Science

We are a network of scientists, developers and organizations building the next generation of digital spaces for open science.

Open Science: About · Code of conduct · Privacy · Users · Instances
Bonfire open science · 1.0.0-rc.2.35 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login