LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-26-2021, 09:20 PM   #1
mtdew3q
Member
 
Registered: Mar 2006
Location: the next town over from siberia
Distribution: xubuntu
Posts: 481

Rep: Reputation: 18
gnupgp post quantum keys


Hi-

Once they make a standard for one of the algorithms being considered for post quantum cryptography, will we be able to use the same clients like kleopatra, SSH, etc. to use like a lattice key instead of RSA?

I just read on zdnet that one of the questions surrounding verizon's quantum VPN was the delivering keys (securely) to endpoints. Won't the programs I just mentioned run into the same issue?

thanks,
roboloki
 
Old 08-26-2021, 10:33 PM   #2
mtdew3q
Member
 
Registered: Mar 2006
Location: the next town over from siberia
Distribution: xubuntu
Posts: 481

Original Poster
Rep: Reputation: 18
Hi -
I just recalled that like in ssh the private key never goes to the to other host.

I don't know what the guy at the zdnet article is talking about. It says VPN on google is asymmetric.

Quote:
For example, Verizon still relied on standard mechanisms in its trial to deliver quantum-proof keys to the VPN end-points. This might be a sticking point, if it turns out that this phase of the process is not invulnerable to quantum attack.
Why does he/she care if the key is securely transmitted if it is just a public key?

thanks
roboloki

Last edited by mtdew3q; 08-26-2021 at 11:02 PM. Reason: ??
 
Old 08-27-2021, 06:41 AM   #3
gouttegd
Member
 
Registered: Nov 2019
Location: London, UK
Distribution: Slackware
Posts: 93

Rep: Reputation: 161Reputation: 161
Quote:
Once they make a standard for one of the algorithms being considered for post quantum cryptography, will we be able to use the same clients like kleopatra, SSH, etc. to use like a lattice key instead of RSA?
First, post-quantum algorithms have to be standardized by bodies such as the NIST or the IRTF Crypto Forum Research Group. That alone may take a while.

Then, for each application the corresponding IETF standards need to be updated to allow the use of whatever PQC algorithms are available. In the case of OpenPGP for example, the working group is already aware of that, but there’s nothing much they can do for now until the first step has been completed.

Then, it will be up to the developers to actually implement the thing.

Quote:
Quote:
For example, Verizon still relied on standard mechanisms in its trial to deliver quantum-proof keys to the VPN end-points. This might be a sticking point, if it turns out that this phase of the process is not invulnerable to quantum attack.
Why does he/she care if the key is securely transmitted if it is just a public key?
From what I understand, for the purpose of this test they generated all the keys for both sides at a single site, then sent one of the key pairs to the distant site. This is an artificial situation – I am not sure why they did it that way, and the article is poor on details ; maybe the distant site somehow lacked the capability of generating the keys? – in normal usage, both sides would generate a key pair independently.

Of course the problem of authenticating the public key of the peer – to be sure that you’re talking to who you think you are talking to – remains. As far as I know, this is nowhere near solved by post-quantum cryptography (which is not the silver bullet that some people sometimes believe it is). Likewise, PQC will also not solve the problem known as "Adi Shamir’s Law", which states that "cryptography is bypassed, not penetrated".
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
export private key to cellphone needs latest gnupgp v2 fsauer Slackware 1 02-15-2017 03:13 PM
LXer: Experimenting with Post-Quantum Cryptography LXer Syndicated Linux News 0 07-12-2016 04:13 PM
LXer: NIST readies 'post-quantum' crypto competition LXer Syndicated Linux News 0 05-04-2016 08:41 AM
gnuPGP coolb Linux - Security 1 08-14-2006 11:29 AM
gnupgp.conf permissions question ironwalker Linux - Software 0 10-20-2005 02:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration