Hacker News new | ask | show | jobs
by loup-vaillant 24 days ago
> recent changes in direction from large Internet providers about quantum computing risks.

Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers? To me this is more about the end of the NIST contest, and that one has no bearing on actual advances in quantum computing.

> The rest of the article is predicated on "these companies' risk assessment turns out to be correct".

Err, where did you wrote that? I can’t find it in your last two articles.

> You are extrapolating from […]

I exptrapolate mostly from this:

"I generally prefer hybrid KEMs–not out of any practical concern over ML-KEM’s security (or any other PQ KEMs, generally), but for reasons I’ll explain later in this blog post."

And this:

"Hybrid KEMs are an easier sell to people who are not cryptography experts than pure post-quantum KEMs for reasons that are mostly related to psychological safety than cryptographic safety."

https://soatok.blog/2026/04/13/hybrid-constructions-the-post...

Sorry if I’m misinterpreting, but as you can see I’m not the only one.

---

Anyway, good article on threat models.

2 comments

> Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers?

Yes.

Both have internal global security orgs that are constantly communicating with other large companies and governments. If they are accelerating (as are others), it is a signal.

The reliability of that signal is up to the reader to determine.

https://www.microsoft.com/en-us/security/blog/2026/06/30/mic...

> Advances in quantum research and development have shifted the risk horizon. We believe cryptographically relevant quantum computers could arrive sooner than previously expected

Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

> Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

You're thinking like this is an academic release, it is not.

This is more like a caution signal given by multiple global corporations with close ties to intelligence agencies, in some cases being State actors for intelligence. NSA and CIA release products, but they try not to leak their methods and sources. Same applies.

> Err, where did you wrote that? I can’t find it in your last two articles.

Just now. In an HN comment.

I write in conversational English. I'm not always going to meticulously write everything like a formal argument might.

If you didn't understand that what I wrote later in a blog post was predicated on an assumption established in the intro, but would have if I wrote an explicit transitional sentence, that's useful feedback. But if you're treating an informal blog post like a court filing, you might be setting yourself up for disappointment.

> I write in conversational English.

Fair enough.

When I write an article (and to a lesser extent even a comment like here), I tend to agonise over every sentence. I’m guessing I’m kinda assuming others do the same. Except of course they don’t.

It depends what I'm doing.

My dayjob involves a lot of code review and protocol cryptanalysis, so I agonize quite a bit there.

My blog would be less fun if I maintained the same level of rigor. If that makes any sense. ^^;

It does :-)