Cryptography nerd

Fediverse accounts;
@Natanael@slrpnk.net (main)
@Natanael@infosec.pub
@Natanael@lemmy.zip

@Natanael_L@mastodon.social

Bluesky: natanael.bsky.social

  • 11 Posts
  • 2.43K Comments
Joined 3 years ago
cake
Cake day: August 16th, 2023

help-circle








  • Yeah that’s the thing, quantum key distribution can not prove who is on the other end!

    It fundamentally can not guarantee that the line is intact before you start communicating. You can in theory detect a break that starts after, but one that happened before is effectively invisible.

    Quantum key distribution can not do anything other than key expansion (giving you more secret bits from a few), because the only way to know who is in the other end is to have agreed to a method of validation, such as a signature algorithm (but if you trust signatures you won’t care about quantum key distribution) or a shared secret (an authentication tag key). But if you have a large enough secret key, you can just use a regular symmetric encryption algorithm. Some might want forward secrecy from the quantum line, but you can get that with symmetric key ratchets like Signal uses where the ONLY benefit of quantum key distribution is that you avoid key management (but instead you maintain physical infrastructure)







  • If you don’t have strong consumer rights enforcement you have to do a lot of research in advance. Even then you can be hit by companies changing model later.

    In B2B, if you’re in charge you need to negotiate in terms to be able to break the contract if the other side don’t deliver what they promised. If you’re just an employee, you can’t do much about your bosses making stupid decisions. They might have thought they would save money, or gotten kickbacks, and you’re stuck with the consequences.

    And yes, dishonest people should be filtered out.