logoalt Hacker News

libeclipselast Wednesday at 12:46 PM2 repliesview on HN

Why don't we use hybrid RSA and ECC then? Or hybrid AES and ChaCha20?

Software bugs is a weak argument for a new hybrid standard, and doesn't justify the additional complexity.


Replies

dhxtoday at 4:45 AM

djb provided a link in his blog post to a long history of ECDSA side channel vulnerabilities in ECDSA implementations.[1] It's not that RSA implementations weren't prone to side channel vulnerabilities either[2], but more with EdDSA/X25519, side channel vulnerabilities have finally been largely addressed through design and standardisation, and now PQC proponents are reversing this gain and repeating the mistakes of ECDSA and ignoring side channel vulnerabilities in design and standards.

What's more likely right now:

- Your cryptosystem is compromised at some point in the future if/when quantum computers exist and can effectively attack EdDSA/X25519. Something no one has yet demonstrated or come close to demonstrating.

- Someone implementing PQC in a library/software/hardware follows the standard which does not care at all about side channel resistant implementation of critical algorithms, resulting in your private keys being leaked. Demonstrated repeatedly over 20+ years.

[1] https://cr.yp.to/papers/safecurves-20240809.pdf#chronology

[2] https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf

show 1 reply
pona-alast Wednesday at 2:17 PM

In his defense, ECC is unusually fast compared to both RSA and current PQ

show 1 reply