Ask HN: TLS 1.3 and Post-Quantum Encryption for HN?
15 points| Azerty9999 | 1 year ago
Cloudflare is beginning to implement it: https://pq.cloudflareresearch.com (See cloudflare blog posts about it, too for many more details)..
15 points| Azerty9999 | 1 year ago
Cloudflare is beginning to implement it: https://pq.cloudflareresearch.com (See cloudflare blog posts about it, too for many more details)..
theandrewbailey|1 year ago
That said, HN could use an update in configuration (disable TLS 1.0 and 1.1 and CBC ciphers, enable TLS 1.3): https://www.ssllabs.com/ssltest/analyze.html?d=news.ycombina...
I get it, new crypto algorithms are cool, but these just aren't widely implemented in browsers or servers yet, and we're still several years out from a quantum computer breaking 2048 bit RSA or 256 bit ECDSA.
Azerty9999|1 year ago
ggm|1 year ago
Maybe the cert issuing chain needs to be looked at for its risks but I can't see the site certificate itself being at risk.
I mean I am glad cloudflare and others are showing capability but my highly broken foot gun of futurology says to me, this is a fools errand. I've been wrong many many times.
theandrewbailey|1 year ago
HN is using Let's Encrypt, and so are about a third to half the sites on the internet at this point. If there's an issue with Let's Encrypt, the people on/running this site would know.
userbinator|1 year ago
Azerty9999|1 year ago
Worth a read: https://blog.cloudflare.com/nists-first-post-quantum-standar...
Google: https://cloud.google.com/security/resources/post-quantum-cry...
Various interesting Cloudflare blog posts here: https://blog.cloudflare.com/tag/post-quantum/