Security and cryptography digest, 2026-10-04
GnuPG maintainers answered a gpg.fail retrospective while NIST advanced FN-DSA plans and a claimed quasipolynomial break on Classic McEliece drew heated debate. A separate comment also questioned proof assumptions for two additional signature candidates.
GnuPG maintainers respond to gpg.fail retrospective
Authors of the gpg.fail work posted a retrospective to oss-security covering claimed remote code execution, a printf bug, and broader PGP format problems. GnuPG maintainers replied with technical positions on those claims. The exchange clarifies exploitability and format limits for anyone relying on OpenPGP implementations.
NIST proposes fixed-point FN-DSA for FIPS 206
NIST outlined a fixed-point FN-DSA specification destined for FIPS 206, complete with exact-match known-answer tests and component tests, after recent Falcon implementation papers. The change aims to lock down the Falcon-derived signature design for standardization. Implementers need the revised test regime as the draft solidifies.
Quasipolynomial claims against Classic McEliece
A new eprint asserts a quasipolynomial distinguisher and heuristic decryption method for Classic McEliece, sparking a long, heated pqc-forum thread that also contains a disclosure dispute involving Apon. Participants scrutinized practical impact and the claim's validity. The debate bears on remaining confidence in code-based KEMs still under evaluation or deployment.
Ideal-cipher assumption flagged for SDitH and MQOM
A single official comment on the pqc-forum noted a non-conservative ideal-cipher assumption in the SDitH and MQOM security proofs, citing AES related-key attacks. The remark questions proof tightness for these round-3 additional signature candidates. Reviewers of the schemes must weigh that modeling choice against the referenced AES results.