logoalt Hacker News

throw0101c • yesterday at 8:40 PM • 3 replies • view on HN

> It was a mistake to assume a fixed algorithm in the repository format and client-server protocol.

See also perhaps Wireguard, which touts itself as not having "cryptographic agility" because they wanted to avoid all (perceived) problems and complications of IPsec. But now that PQC is (allegedly) approaching there's no easy to update things because (AIUI) there's no negotiation possible in the protocol; you're basically standing up a 'Wireguard 2.0' that runs separately than the original.


Replies

computerfriend • today at 4:45 AM

Wireguard is secure against a quantum computer though, via an additional pre-shared key.

> If an additional layer of symmetric-key crypto is required (for, say, post-quantum resistance), WireGuard also supports an optional pre-shared key that is mixed into the public key cryptography.

(From https://www.wireguard.com/protocol/.)

akerl_ • today at 1:18 AM

That is in fact the idea, and was on purpose.

someonebaggy • today at 4:15 AM

Which is fine, for wireguard which only encrypts things ephemerally.