• @LWD@lemm.ee
    link
    fedilink
    282 months ago

    This is way more of a self-promo blog post than an article, but it’s also along the lines of Signal or Apple announcing their own successes in cryptography.

    BTW, this was my favorite part of the post

    Why encryption is even allowed?

    Daniel J Bernstein

    They’re not wrong, either.

    I also appreciate their clarification that post-quantum encryption is a guess, not a sure thing. Actually, they’re much more blunt than that:

    post-quantum cryptography can be compared with a remedy against the illness that nobody has, without any guarantee that it will work. The closest analogy in the history of medicine is snake oil.

    Good on them for saying that.

    But then on expounding with minimal jargon… At least, as far as explaining cryptography can be done that way.

    • Arthur BesseOPA
      link
      English
      10
      edit-2
      2 months ago

      post-quantum cryptography can be compared with a remedy against the illness that nobody has, without any guarantee that it will work. The closest analogy in the history of medicine is snake oil.

      Good on them for saying that.

      A “remedy against the illness that nobody has” is a good analogy, but it is important to note that it’s an illness which there is a consensus we are likely to eventually have and a remedy that there is good reason to believe will be effective.

      It isn’t a certainty that there will ever be a cryptographically relevant post-quantum computer, and it also isn’t a certainty that any of the post-quantum algorithms (as with most classical cryptography) which exist today won’t turn out to be breakable even by yesterday’s computers. The latter point is why it’s best to deploy post-quantum cryptography in a hybrid construction such that the system remains secure even if one of the primitives turns out to be breakable.

      That said, I think it is totally wrong to call PQC snake oil because that term in the context of cryptography specifically means that a system is making dishonest claims: https://en.wikipedia.org/wiki/Snake_oil_(cryptography)

      • @LWD@lemm.ee
        link
        fedilink
        4
        edit-2
        2 months ago

        I didn’t post the part after the “snake oil” quote because my post was getting a bit long but yeah, they basically agree with you. I also get mild ESL vibes (the phrasing on the title is a little off, and I believe a couple of the developers are Russian-born) so I don’t think they were trying to be too inaccurate.

        • Arthur BesseOPA
          link
          English
          42 months ago

          they basically agree with you

          yes, I realize :)

          I should’ve made clear in my comment that, aside from a bit of imperfect English and incorrect use of the term snake oil, I think this is an excellent blog post.

    • @Coasting0942@reddthat.com
      link
      fedilink
      82 months ago

      Thanks for highlighting that part of history.

      The guy literally printed the algorithm in a book to show that the first amendment protects encryption math. Luckily the justices at the time were definitely pro first amendment. Unlucky that they used first amendment to justify citizens United

    • The Doctor
      link
      fedilink
      English
      3
      edit-2
      2 months ago

      That’s djb?

      Whoa. I never knew what he looked like.