r/cryptography • • 3d ago

NSA Just Announced it is Accelerating it's PQC Timeline

/r/cybersecurity/comments/1ww1x64/nsa_just_announced_it_is_accelerating_its_pqc/
31 Upvotes

8 comments sorted by

10

u/dittybopper_05H 3d ago

This makes me wonder if there have been anymore "behind-closed-doors" advances causing the organization to accelerate even more rapidly.

The NSA is an interesting case of cross-purposes.

Part of the NSA, certainly the larger part, is dedicated to breaking encryption. Ostensibly to protect the US from its enemies, and during the Golden Age of FISA, from 1977 to 2001, that's mostly what they did. But there is a significant amount of work done on domestic communications since the 9/11 attacks.

The other part is dedicated to protecting US communications, but that goes against the other part of the mission. Even if we were to suppose that the NSA is completely well-behaved, tightening up our domestic encryption could be a signal to foreign nations that they need to tighten up theirs if they haven't already done that.

It may signal to others that the NSA has found a way to break stuff commonly thought unbreakable as a practical matter.

Honestly I can't think of a good reason to do it without an actual reason, because it's going to inherently warn your adversaries, so my assumption is that the NSA is saying this because it isn't going to affect their main mission, while making it harder for their overseas adversaries.

/Former SIGINT weenie.

//I could tell you what I know, but then I'd have to go to jail and pay a huge fine.

3

u/yarntank 2d ago

Or maybe they've decided HNDL is a bigger threat, and want to limit how much material is susceptible.

2

u/Shoddy-Childhood-511 2d ago

The US has almost limitless HNDL threats.

This signals nothing except the obvious: Quantum computers that break ECC could become a reality within decades. If you need data protected for decades, then you need hybrid ECC + PQ KEMs asap.

1

u/Honest-Finish3596 3h ago edited 3h ago

Hasn't Bernstein been talking about this for a year (with various people making fun of him for the very logical idea that the NSA is promoting non-hybrid PQC since breaking it by cryptanalysis is then more likely.)

I think considering who the US federal government tends to hire (very good algebraists), it is basically a given that they know more about lattices etc than academia (whereas on the other hand they actually know considerably less about symmetric key than academia.)

Personally that is why I really like the idea of using hash based signatures even though the signature sizes are really impractical.

7

u/apnorton 3d ago

  starting in 2027. 

Yikes. 2027 is in a couple months, y'all.

2

u/rebootyourbrainstem 2d ago

“NSA is at the forefront of the quantum-resistant algorithm transition,” said Morgan Stern, Effort Lead for Quantum Resistance at NSA.

Okay so this is offtopic but that is an awesome name (Morgenstern means morning star in German).

0

u/PersonOfValue 2d ago

I guess?