so happy with the @Cloudflare job, ngl before joining I thought the motto “help build a better internet” was just another mission statement, but ppl genuinely care about it and about transparency, asking themselves “does this help build a better internet?” when designing new features/products, and holding themselves to high ethical standards, loving it 🧡
and PS: really cool announcements coming up next week 🎂
Don't panic. It's not a question whether RSA-1024 is broken, but who is willing to pay the roughly 30m$ for the bragging rights. RSA-2048 is fine... except for the quantum thing.
Don't panic. It's not a question whether RSA-1024 is broken, but who is willing to pay the roughly 30m$ for the bragging rights. RSA-2048 is fine... except for the quantum thing.
636606729769440499166579950236036751749912014371509557713570027508971809534551913252252094954941974952859310861988904737359709200557919
is a factor of RSA-896
saweis.net/posts/rsa-896.htm…
We're happy to announce that we finished version 3 of the FAEST signature scheme, which is our round 3 submission to the NIST Post-Quantum Cryptography: Additional Digital Signature Schemes process.
The lesson here for other infrastructure providers, and digital assets firms in particular: don't assume. Test.
Only by confronting the potential problem empirically can we (a) develop technical solutions and (b) enable a real discussion on tradeoffs.
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale. cfl.re/4xsuOwg
What to do about post-quantum DNSSEC? Can we just shove in ML-DSA-44, do we need to make more systemic changes, or should we start writing a eulogy? There is only one way to find out: 1.1.1.1 now supports checking ML-DSA-44 (alg 18) signatures.
We also set up signed test zones at dnstest.dev. To get data from a diverse set of networks, we're sending probes from Cloudflare challenge pages. Read all about it in this blog post. We'll report back soon with data! blog.cloudflare.com/post-qua…
For the crypto aficionados a nice tidbit: downgrade protection is easier in DNSSEC, than TLS, but it does require validators to go against the recommended behaviour of RFC 6840.
We just made connections to origin servers faster and more secure.
p90 latency improved by 150ms+. 45 billion connections a day now use post-quantum encryption.
and It’s automatic (obviously)!
blog.cloudflare.com/automati…