TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Mullvad's usage of Kyber is not affected by KyberSlash

33 点作者 amirmasoudabdol超过 1 年前

2 条评论

nusl超过 1 年前
I’m very surprised that folks are still building critical security software like this while making elementary mistakes like not using constant time operations. This is a class of vulnerability almost as old as I can remember.
评论 #38881262 未加载
timenova超过 1 年前
There was a post a few days ago about how the NSA is wrong in not recommending hybrid quantum+classical cryptography algorithms [0].<p>And here is Mullvad, using two quantum algorithms together, presumably on top of classical cryptography.<p>&gt; We use two quantum-secure key encapsulation mechanisms (Kyber and Classic McEliece) and mix the secrets from both. This means that both algorithms must have exploitable vulnerabilities before the security of the VPN tunnel can become affected.<p>[0] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38844117">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38844117</a>
评论 #38899847 未加载
评论 #38881215 未加载