nrw.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Wir sind eine freundliche Mastodon Instanz aus Nordrhein-Westfalen. Ob NRW'ler oder NRW-Sympathifanten, jeder ist hier willkommen.

Serverstatistik:

2,9 Tsd.
aktive Profile

#PQC

2 Beiträge2 Beteiligte0 Beiträge heute
Fortgeführter Thread

This is undoubtedly the most promising Post-Quantum TLS deployment situation I have seen for #Tor since we started discussing it more actively in the team. Very exciting!

I hope that OpenSSL 3.5, when released, will make it into #Debian Trixie. That would make deployment of this so much more snappy and easy for the Tor network to upgrade, but that may be dreaming. The timelines here look quite difficult for that to happen, but let's hope.

Fortgeführter Thread

Lo and behold, #OpenSSL 3.5 (their upcoming LTS release) will come out here at the beginning of April, and it does indeed support some of these hybrid PQC schemes. Their recent beta2 announcement can be read here: openssl-library.org/post/2025- and their roadmap is at openssl-library.org/roadmap/in

Very excited by this work. Big kudos to the OpenSSL Team here! 🥳🎉 Already planning on giving this a spin with the C implementation of #Tor later this week to see how it goes!

OpenSSL Library · OpenSSL 3.5 Beta Release AnnouncementThe OpenSSL Project is pleased to announce that OpenSSL 3.5 Beta1 pre-release is released and adding significant new functionality to the OpenSSL Library.
Fortgeführter Thread

🧵 …ja und nein und vor allem ist es Marketing durch Angstmacherei. Quantenkomputer sind noch nicht wirklich einsetzbar obwohl es viele als solches gerne vermarkten.

»Quantenschlüssel aus der Sicht des CISO:
Quantentechnologien – ein Sicherheitsrisiko oder das Mittel der Wahl gegen Cyberangriffe? Warum, für wen und wo es wichtig ist, die Integration von Quantentechnologien zu starten.«

⚛️ csoonline.com/article/3846875/

CSO OnlineQuantenschlüssel aus der Sicht des CISOQuantentechnologien: ein Sicherheitsrisiko oder das Mittel der Wahl gegen Cyberangriffe? Warum, für wen und wo es wichtig ist, die Integration von Quantentechnologien zu starten.

»The Quantum Apocalypse Is Coming. Be Very Afraid:
What happens when quantum computers can finally crack encryption and break into the world’s best-kept secrets? It’s called Q-Day—the worst holiday maybe ever.«

Since this is very much for us, I cannot deny it, but I see it as a marketing propaganda. To scare is also a marketing strategy.

👾 wired.com/story/q-day-apocalyp

WIRED · The Quantum Apocalypse Is Coming. Be Very AfraidVon Amit Katwala
Fortgeführter Thread

Out of the top 100K domains, roughly 28K negotiate a quantum safe key exchange.

Almost all of those support both x25519_kyber768 and X25519MLKEM758; only 129 sites support SecP256r1MLKEM768. There are _no_ sites that support pure #PQC via e.g., mlkem768.

The overwhelming majority of sites that support PQC do so by way of Cloudflare. That percentage matches Cloudflare's overall coverage of the top 1M domains.

🧵 …neben dem vorhin erwähnten Marketing bezüglich des Post-Quantom Kryptografie ist darauf hin auch wieder die Angsmacherei davon. Das die mal angewendet wird ist klar aber wie ist die Frage.

»Ihre Passwörter sind bald wertlos: Quantencomputer knacken alles!
Quantencomputer revolutionieren die Rechenleistung. Sie lösen hochkomplexe Aufgaben in Sekundenschnelle. Doch die Technologie birgt auch Gefahren.«

⚛️ telepolis.de/features/Ihre-Pas

heise online · Ihre Passwörter sind bald wertlos: Quantencomputer knacken alles!Von Christoph Jehle
Fortgeführter Thread

I have written a new white-paper for Far Phase, where I analysed the most popular Australian banking websites (18 in all) and found that **none** of them protected people from quantum threats. This is despite bank interactions being 99% via websites and apps, and banks holding some of the most sensitive, long-lived data. Yet, nearly 40% of global secure web traffic is protected from quantum threats, and even the Google search engine offers this protection. Australians would not expect that a search engine offers better post-quantum protection for their sensitive data than Australia's biggest banks. With technology enablers making this easier to implement in the next couple of months, Australian banks should urgently update their websites to protect their users.
farphase.com/white-paper-on-au
#quantum #pqc #australia #banking #cybersecurity #farphase #whitepaper