Skip to content
DevMeme
5837 of 7590
Cryptography Post #6393 · source on Telegram

Deprecation Timeline for ECDSA, EdDSA, and RSA Due to Quantum Vulnerability

Description

This image displays 'Table 2: Quantum-vulnerable digital signature algorithms'. It's a clean, black-and-white table with three columns: 'Digital Signature Algorithm Family', 'Parameters', and 'Transition'. The table lists the algorithm families ECDSA, EdDSA, and RSA, along with their corresponding security strength parameters (e.g., 112 bits, >= 128 bits). The 'Transition' column provides specific deadlines, indicating that the weaker versions of ECDSA and RSA are 'Deprecated after 2030' and all listed algorithms are 'Disallowed after 2035'. This is not a meme but a critical piece of technical documentation. It provides the specific, actionable details for the cryptographic migration mandated by the US government's post-quantum strategy. For senior engineers and architects, this table is a direct warning that the foundational pillars of current internet security have a clear expiration date, necessitating long-term planning for a complex and mandatory migration to quantum-resistant alternatives

Comments

7
Anonymous ★ Top Pick I'm not saying this migration will be painful, but I'm stocking up on project manager apology templates now. 'We've encountered some unforeseen cryptographic challenges in our sprint to defy quantum physics.'
  1. Anonymous ★ Top Pick

    I'm not saying this migration will be painful, but I'm stocking up on project manager apology templates now. 'We've encountered some unforeseen cryptographic challenges in our sprint to defy quantum physics.'

  2. Anonymous

    NIST just scheduled RSA, ECDSA, and EdDSA for retirement by 2035 - meanwhile our change-control board still hasn’t approved SHA-1 removal, so odds are Shor’s algorithm will finish the migration before we do

  3. Anonymous

    Just found out my RSA keys expire in 2035, which coincidentally is also when I planned to finally migrate that legacy system to microservices

  4. Anonymous

    Nothing says 'job security' quite like a cryptographic deprecation table with a 10+ year runway - plenty of time to migrate those legacy systems you've been meaning to refactor since 2015, right? By 2035, we'll finally have an excuse to touch that ancient authentication service that's been running untouched in production since the Obama administration, assuming quantum computers don't break it first and assuming you can still find someone who remembers why ECDSA with 112-bit keys seemed like a good idea back then

  5. Anonymous

    112 bits of security? Quantum computers will Shor-ten that to zero by 2035 - time to PQC or bust

  6. Anonymous

    ‘Disallowed after 2035’ sounds far away until you factor HSM firmware lead times and root‑CA rollover windows - start the Dilithium migration before procurement finishes the NDA

  7. Anonymous

    NIST says “disallowed after 2035”; our crypto‑agility plan says “start discovery in 2034 and find an RSA key baked into a million bootloaders.”

Use J and K for navigation