frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Cloudflare targets 2029 for full post-quantum security

https://blog.cloudflare.com/post-quantum-roadmap/
52•ilreb•2h ago

Comments

ls612•1h ago
The secrecy around this is precisely the opposite of what we saw in the 90s when it started to become clear DES needed to go. Yet another sign that the global powers are preparing for war.
NitpickLawyer•59m ago
My read of the recent google blog post is that they framed it as cryptocurrency related stuff just so they don't say the silent thing out loud. But lots of people "in the know" / working on this are taking it much more seriously than just cryptobros go broke. So my hunch is that there's more to it and they didn't want to say it / couldn't / weren't allowed to.
IncreasePosts•36m ago
What is "it" that you're referring to?
wil421•24m ago
> mitigating harvest-now/decrypt-later attacks.

Most likely the NSA or someone else is ahead of the game and already has a quantum computer. If the tech news rumors are to true the NSA has a facility in Utah that can gather large swaths of the internet and process the data.

adrian_b•31m ago
It should be noted that quantum computers are a threat mainly for interactions between unrelated parties which perform legal activities, e.g. online shopping, online banking, notarized legal documents that use long-term digital signatures.

Quantum computers are not a threat for spies or for communications within private organizations where security is considered very important, where the use of public-key cryptography can easily be completely avoided and authentication and session key exchanges can be handled with pre-shared secret keys used only for that purpose.

tptacek•41m ago
What do you mean? For as long as I remember (back to late 1994) people understood DES to be inadequate; we used DES-EDE and IDEA (and later RC4) instead. What "secrecy" would there have been? The feasibility of breaking DES given a plausible budget goes all the way back to the late 1970s. The first prize given for demonstrating a DES break was only $10,000.
adrian_b•18m ago
Triple-key DES (DES-EDE) had already been proposed by IBM in 1979, in response to the criticism that the 56-bit keys of DES are far too short.

So practically immediately after DES was standardized, people realized that NSA had crippled it by limiting the key length to 56 bits, and they started to use workarounds.

Before introducing RC2 and RC4 in 1987, Ronald Rivest had used since 1984 another method of extending the key length of DES, named DESX, which was cheaper than DES-EDE as it used a single block cipher function invocation. However, like also RC4, DESX was kept as a RSA trade secret, until it was leaked, also like RC4, during the mid nineties.

IDEA (1992, after a preliminary version was published in 1991) was the first block cipher function that was more secure than DES and which was also publicly described.

heliumtera•35m ago
And that changes what?
ezfe•31m ago
It would mean that they're future-proofing their security
bwesterb•19m ago
If we do our job, it changes nothing. Problem with security generally: no spectacle if it's all correct. :)
Bender•27m ago
Is this still theory or are there working Quantum systems that have broken anything yet?
moi2388•18m ago
Theory. And afaik there are still questions as to if the PQ algorithms are actually secure.
sophacles•2m ago
tbf - since we still don't know if p != np, there are still questions about if the current algorithms are secure also.
20k•24m ago
Quantum computing, and the generic term 'quantum' is gearing up to be the next speculative investment hype bubble after AI, so prepare for a lot of these kinds of articles
bwesterb•23m ago
At least it's time bound: hope to have this job done by 2029!
cetinsert•14m ago
You can do PQ queries with us at qi.rt.ht!

Which one do you think is PQ-secure?

https://qi.rt.ht/?pq={api.,}{stripe,paypal}.com

hackerman70000•5m ago
Cloudflare pushing PQ by default is probably the single most impactful thing that can happen for adotpion. Most developers will never voluntarily migrate their TLS config. Making it the default at the CDN layer means millions of sites get upgraded without anyone making a decision
rdl•3m ago
It will be interesting to compare PQ rollout to HTTPS rollout historically (either the "SSL becomes widespread in 2015" thing, or the deprecation SSL 3.0). Cloudflare is in an easy position to do stuff like this because it can decouple end user/browser upgrade cycles from backend upgrade cycles.

Some browsers and some end user devices get upgraded quickly, so making it easy to make it optionally-PQ on any site, and then as that rollout extends, some specialty sites can make it mandatory, and then browser/device UX can do soft warnings to users (or other activity like downranking), and then at some point something like STS Strict can be exposed, and then largely become a default (and maybe just remove the non-PQ algorithms entirely from many sites).

I definitely was on team "the risks of a rushed upgrade might outweigh the risks of actual quantum breaks" until pretty recently -- rushing to upgrade has lots of problems always and is a great way to introduce new bugs, but based on the latest information, the balance seems to have shifted to doing an upgrade quickly.

Updating websites is going to be so much easier than dealing with other systems (bitcoin probably the worst; data at rest storage systems; hardware).

A Pale Blue Dot

https://www.planetary.org/worlds/pale-blue-dot
1•helloworld•13s ago•0 comments

GLM-5.1: Towards Long-Horizon Tasks

https://z.ai/blog/glm-5.1
1•meetpateltech•20s ago•0 comments

DNA polymerases can generate long, complex sequences without templates

https://www.nature.com/articles/s41467-026-69915-x
1•prabal97•27s ago•0 comments

Show HN: A (marginally) useful x86-64 ELF executable in 298 bytes

https://github.com/meribold/btry
1•meribold•56s ago•0 comments

China restricts airspace for 40 days in signal of intense military activity

https://www.msn.com/en-us/news/world/china-restricts-airspace-for-40-days-in-signal-of-intense-mi...
1•petethomas•1m ago•0 comments

Git turns 20: A Q&A with Linus Torvalds (2025)

https://github.blog/open-source/git/git-turns-20-a-qa-with-linus-torvalds/
1•pretext•1m ago•0 comments

"The problem is Sam Altman": OpenAI Insiders don't trust CEO

https://arstechnica.com/tech-policy/2026/04/the-problem-is-sam-altman-openai-insiders-dont-trust-...
1•randycupertino•3m ago•0 comments

The Limits of Integration (2021)

https://muse.jhu.edu/verify?url=%2Fpub%2F17%2Farticle%2F804858&r=2536187
1•Tomte•3m ago•0 comments

Delivery Deadlines Are a Mistake

https://waldo.jaquith.org/blog/2026/04/delivery-deadlines/
1•speckx•4m ago•0 comments

AI Agent Sandboxes Got Security Wrong

https://multikernel.io/2026/04/03/ai-agent-sandboxes-got-security-wrong/
1•wang_cong•4m ago•0 comments

Show HN: Hazmat – I made unrestricted Claude Code safe on macOS

https://github.com/dredozubov/hazmat
1•dredozubov•5m ago•0 comments

You not always need an autonomous team

https://cientifico.net/task-teams-vs-autonomous-teams/
1•cientifico•5m ago•0 comments

Why Japan has such good railways

https://worksinprogress.co/issue/why-japan-has-such-good-railways/
1•zdw•6m ago•0 comments

Impeaching Donald J. Trump for High Crimes and Misdemeanors [pdf]

https://www.congress.gov/119/bills/hres1155/BILLS-119hres1155ih.pdf
3•dmm•6m ago•1 comments

NASA Artemis II Multimedia Resources

https://www.nasa.gov/artemis-ii-multimedia/
1•kklisura•7m ago•0 comments

The Downfall and Enshittification of Microsoft in 2026

https://caio.ca/blog/the-downfall-and-enshittification-of-microsoft.html
1•stock_toaster•8m ago•0 comments

Stop Vibecoding [video]

https://www.youtube.com/shorts/cgD-bTTe20I
1•mooreds•9m ago•0 comments

Ask HN: What's everyone's API billing stack?

2•sigpwned•10m ago•0 comments

Show HN: Ace Influence – Turn your brand into stories people watch

https://aceinfluence.ai
2•SecularVan•11m ago•0 comments

Why NASA flight director Gene Kranz is the gold standard for incident commanders

https://greatcircle.com/blog/2026/04/07/gene-kranz-gold-standard/
1•mooreds•11m ago•0 comments

US Senator Calls Chinese Cars a 'Cancer,' Vowing Stricter Ban

https://insideevs.com/news/791834/chinese-cars-cancer-republican-senator/
1•akyuu•12m ago•0 comments

What History Can Teach Us About Sleep and Dreams

https://cswr.hds.harvard.edu/news/2026/03/30/what-history-can-teach-us-about-sleep-and-dreams
1•apollinaire•12m ago•0 comments

The Hard Problems Nobody Has Solved

https://www.nibzard.com/hard-problems
2•nkko•13m ago•0 comments

Show HN: Managarr – A TUI and CLI for managing *ARR servers, built in Rust

https://github.com/Dark-Alex-17/managarr
1•Dark-Alex-17•14m ago•0 comments

Code Is an Afterthought

https://blog.ignaciobrasca.com/systems/2026/03/01/code-is-an-afterthought.html
1•warkanlock•16m ago•0 comments

MikroORM 7: Unchained

https://mikro-orm.io/blog/mikro-orm-7-released
1•bundie•16m ago•0 comments

Show HN: Bucket Delta – Compute differences between two S3-compatible buckets

https://github.com/nutanix/bucket-delta-cli
1•drstrange14•18m ago•0 comments

Show HN: I built an AI that forgets things when people leave the room

https://takt.chat/
1•mtrifonov•18m ago•1 comments

Local-heatmap-tile-server v1

https://nuxx.net/blog/2026/04/07/local-heatmap-tile-server-v1/
2•c0nsumer•19m ago•0 comments

AI Agent Guardrails: Pre-LLM and Post-LLM Best Practices

https://www.arthur.ai/blog/best-practices-for-building-agents-guardrails
1•pevals•20m ago•1 comments