TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mullvad's usage of Kyber is not affected by KyberSlash

33 pointsby amirmasoudabdolover 1 year ago

2 comments

nuslover 1 year ago
I’m very surprised that folks are still building critical security software like this while making elementary mistakes like not using constant time operations. This is a class of vulnerability almost as old as I can remember.
评论 #38881262 未加载
timenovaover 1 year ago
There was a post a few days ago about how the NSA is wrong in not recommending hybrid quantum+classical cryptography algorithms [0].<p>And here is Mullvad, using two quantum algorithms together, presumably on top of classical cryptography.<p>&gt; We use two quantum-secure key encapsulation mechanisms (Kyber and Classic McEliece) and mix the secrets from both. This means that both algorithms must have exploitable vulnerabilities before the security of the VPN tunnel can become affected.<p>[0] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38844117">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38844117</a>
评论 #38899847 未加载
评论 #38881215 未加载