Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please add checks for quantum-resistant hybrid cryptography in browser and server scans #938

Open
rhardy613 opened this issue Aug 19, 2023 · 1 comment

Comments

@rhardy613
Copy link

Please add checks for quantum-resistant hybrid cryptography in browser and server scans. For many the Quantum encryption Apocalypse is like a big pink elephant no wants to admit exists. While many most are still under the impression this a distant future issue, it's already an active security issue now. We need to be doing what we can to allow movement to and detect support for NIST Post-Quantum Cryptography Standardization.
Please reference pq.cloudflareresearch.com Google released first quantum-resilient FIDO2 key implementation and the more specifically relevant Protecting Chrome Traffic with Hybrid Kyber KEM .
Both Chrome and Brave (and possibly other Chromium based browsers) support it. Firefox appears to be slowly moving towards implementation ETA unknown. The obvious next step was to figure out server support and do security scans. That last part appears to be missing at the moment.

@lilyanatia
Copy link

The obvious next step was to figure out server support and do security scans. That last part appears to be missing at the moment.

you can use oqs-provider to add support for it to OpenSSL.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants