Skip to content
DevMeme
5836 of 7590
Cryptography Post #6394 · source on Telegram

Quantum Vulnerability and Deprecation of Key-Establishment Schemes

Description

This image presents 'Table 4: Quantum-vulnerable key-establishment schemes'. It is a structured, black-and-white table with three columns: 'Key Establishment Scheme', 'Parameters', and 'Transition'. The table identifies three major key establishment schemes as vulnerable: 'Finite Field DH and MQV', 'Elliptic Curve DH and MQC', and 'RSA'. For each scheme, it specifies security strength parameters (112 bits and >= 128 bits) and provides a clear transition plan: 'Deprecated after 2030' and 'Disallowed after 2035'. This is a highly significant piece of technical documentation, not a meme. It outlines the official end-of-life for the cryptographic handshake protocols that currently secure a vast majority of internet traffic (e.g., TLS). For senior engineers and system architects, this is a direct mandate to plan the migration of critical network infrastructure away from these foundational, but soon-to-be-insecure, standards

Comments

7
Anonymous ★ Top Pick The year is 2034. A junior dev asks, 'Hey, did we ever get around to replacing that old Diffie-Hellman key exchange on the legacy billing server?' The silence that follows is deafening
  1. Anonymous ★ Top Pick

    The year is 2034. A junior dev asks, 'Hey, did we ever get around to replacing that old Diffie-Hellman key exchange on the legacy billing server?' The silence that follows is deafening

  2. Anonymous

    NIST says RSA is disallowed after 2035 - perfect, that’s exactly how long our architecture board needs to bike-shed the namespace for our “PostQuantumCryptoFactoryProviderImpl.”

  3. Anonymous

    "2035: The year we finally deprecate RSA and that one legacy service still using RC4 somehow achieves quantum supremacy through sheer technical debt."

  4. Anonymous

    When your RSA keys have a longer deprecation timeline than most JavaScript frameworks have lifespans, but quantum computers are still giving them an existential crisis. At least we have until 2035 to migrate - plenty of time to add it to the backlog, right after that Y2K remediation ticket

  5. Anonymous

    NIST's 2030 deprecation: five years to migrate keys - enough time for one enterprise RFP cycle and zero actual progress

  6. Anonymous

    Perfect - NIST gives us until 2035; that’s exactly how long it’ll take to inventory every TLS endpoint still doing ECDH/RSA behind a forgotten load balancer, wedge in X25519+Kyber on the HSMs, and renegotiate all the partner contracts

  7. Anonymous

    Enterprises read “disallowed after 2035” as “start a PoC in 2034,” then discover their PKI, HSM, and TLS stack treat ‘DH or RSA’ as a boolean

Use J and K for navigation