Hacker News new | ask | show | jobs
by loup-vaillant 24 days ago
In your PQ safety blanket article https://soatok.blog/2026/04/13/hybrid-constructions-the-post... you make it pretty clear the reason you support hybrid is tactical, not cryptographic.

Your wording ("Once Q-Day happens") strongly suggests Q-Day will happen, like, it’s so certain you don’t even need to state it explicitly, you can just assume it will. And your references to the PQ timeline give the impression that you think it will likely happen soon.

It’s pretty clear from there that you think ECDH is now technically useless, and the only real justification for hybrid schemes (as opposed to pure PQ), is to reassure the people still unsure about the likes of ML-KEM. Sure you still do recommend going hybrid, but from what I can tell, you would have preferred a world where we go pure PQ right away.

And so would I to be honest (if ECC is a bust): one algorithm is simpler and faster than two.

1 comments

> In your PQ safety blanket article https://soatok.blog/2026/04/13/hybrid-constructions-the-post... you make it pretty clear the reason you support hybrid is tactical, not cryptographic.

What does it matter that my public arguments are tactical? Hybrid gets us to PQ faster, which makes progress on plugging up the HNDL risk.

> Your wording ("Once Q-Day happens") strongly suggests Q-Day will happen, like, it’s so certain you don’t even need to state it explicitly, you can just assume it will.

The literal opening section is talking about recent changes in direction from large Internet providers about quantum computing risks.

The rest of the article is predicated on "these companies' risk assessment turns out to be correct".

Separately, in https://soatok.blog/2024/09/13/e2ee-for-the-fediverse-update... I wrote more about my actual beliefs about the likelihood of Q-Day.

> It’s pretty clear from there that you think ECDH is now technically useless, and the only real justification for hybrid schemes (as opposed to pure PQ), is to reassure the people still unsure about the likes of ML-KEM. Sure you still do recommend going hybrid, but from what I can tell, you would have preferred a world where we go pure PQ right away.

You are extrapolating from the subsidiary clause of an if statement whose truth value I do not claim to know.

> And so would I to be honest (if ECC is a bust): one algorithm is simpler and faster than two.

Sure.

> recent changes in direction from large Internet providers about quantum computing risks.

Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers? To me this is more about the end of the NIST contest, and that one has no bearing on actual advances in quantum computing.

> The rest of the article is predicated on "these companies' risk assessment turns out to be correct".

Err, where did you wrote that? I can’t find it in your last two articles.

> You are extrapolating from […]

I exptrapolate mostly from this:

"I generally prefer hybrid KEMs–not out of any practical concern over ML-KEM’s security (or any other PQ KEMs, generally), but for reasons I’ll explain later in this blog post."

And this:

"Hybrid KEMs are an easier sell to people who are not cryptography experts than pure post-quantum KEMs for reasons that are mostly related to psychological safety than cryptographic safety."

https://soatok.blog/2026/04/13/hybrid-constructions-the-post...

Sorry if I’m misinterpreting, but as you can see I’m not the only one.

---

Anyway, good article on threat models.

> Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers?

Yes.

Both have internal global security orgs that are constantly communicating with other large companies and governments. If they are accelerating (as are others), it is a signal.

The reliability of that signal is up to the reader to determine.

https://www.microsoft.com/en-us/security/blog/2026/06/30/mic...

> Advances in quantum research and development have shifted the risk horizon. We believe cryptographically relevant quantum computers could arrive sooner than previously expected

Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

> Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

You're thinking like this is an academic release, it is not.

This is more like a caution signal given by multiple global corporations with close ties to intelligence agencies, in some cases being State actors for intelligence. NSA and CIA release products, but they try not to leak their methods and sources. Same applies.

> Err, where did you wrote that? I can’t find it in your last two articles.

Just now. In an HN comment.

I write in conversational English. I'm not always going to meticulously write everything like a formal argument might.

If you didn't understand that what I wrote later in a blog post was predicated on an assumption established in the intro, but would have if I wrote an explicit transitional sentence, that's useful feedback. But if you're treating an informal blog post like a court filing, you might be setting yourself up for disappointment.

> I write in conversational English.

Fair enough.

When I write an article (and to a lesser extent even a comment like here), I tend to agonise over every sentence. I’m guessing I’m kinda assuming others do the same. Except of course they don’t.

It depends what I'm doing.

My dayjob involves a lot of code review and protocol cryptanalysis, so I agonize quite a bit there.

My blog would be less fun if I maintained the same level of rigor. If that makes any sense. ^^;

It does :-)