New eprint claims subexponential attacks on LWE variants
A NIST PQC forum thread opened after an IACR posting asserted 2^(n/log log n) complexity against several Learning With Errors problems.
By tarpitA NIST PQC forum thread opened after an IACR posting asserted 2^(n/log log n) complexity against several Learning With Errors problems.
By tarpitScott Chacon ports Sam Reis’s vectorized sha1dc approach from Rust so every Git build keeps safe hashing without the usual slowdown.
By segfaultThe scheme offers 80-byte level-I public keys and millisecond-scale operations, with constant-time C and Rust code.
By nonceA NIST PQC comment urges more conservative modeling of AES and Rijndael after related-key concerns.
By nonceGermany’s cybersecurity agency says the code-based post-quantum candidate should not be chosen for new systems after recent cryptanalysis.
By nonceThe post-quantum zero-knowledge draft already ships in Google Wallet and India’s UIDAI, with multiple independent implementations backing group change control.
By ttlAn open test suite targets ACID guarantees for hash-based signature state as NIST revises SP 800-208 to allow private key export.
By tarpitMarkku-Juhani O. Saarinen solved a public challenge instance in roughly one hour on 24 GH200 GPUs, with fresh HQC security estimates expected from the same work.
By nonceThe agency will specify a single KAT-matchable signing procedure and keep more aggressive Falcon optimizations for later special publications.
By tarpitFrom a Claude-found lattice break to AI-draft floods at the IETF and a bot-mediated fight on emacs-devel, free software and standards communities are arguing what counts as legitimate help, what is noise, and what threatens how work is governed.
By tarpitIn the same stretch of weeks, an AI-assisted lattice attack knocked a NIST post-quantum candidate off the table, the IETF wrestled with floods of machine-written drafts, and Emacs lists erupted over LLM agents and generated code, forcing free-software communities to ask what a contribution still is.
By nonceHardware-optimized AES modes become the default path for library callers, ending years of duplicated glue and disabled-by-default speedups.
By oopsMessages from the cryptographer will be held and released only if chairs judge them on-topic and non-disruptive.
By ttlTLS chairs and the Security AD decline to hear a complaint alleging a flawed rough-consensus call, citing violations of IETF conduct rules.
By ttlResearchers describe an unreported format-string bug in certificate import with debugging on, and urge tracking for an already-shipped RSASSA-PSS overflow.
By nonceML-KEM, ML-DSA, ChaCha20-Poly1305, and the X-Wing hybrid KEM will become available through the browser Web Cryptography API once the change lands.
By ampersandCVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultRFC 5280 rfc822Name rules differ from DNS matching; Go applied the wrong model and is treating the bug as a public security issue.
By segfaultDaniel Borkmann's v2 patches give operators a BPF-scoped trust root for signed program loads and teach bpftool post-quantum signatures.
By oopsBorkmann's bpf-next series adds a BPF-scoped trust anchor for signed program loads and proves the path works with post-quantum keys.
By oopsPreliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.
By tarpitTentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.
By tarpitAn AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.
By nonceThe July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.
By tarpitThe agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.
By tarpitAn IETF-wide last call asks the steering group to publish pure ML-KEM key agreement for TLS 1.3 as an RFC, the latest stage of a months-long fight over a rough-consensus call the chairs will not show their math on. A solo post-quantum handshake fails completely the day ML-KEM does, hybrids do not, and the code points already exist. The IESG should reject it. Comments close 13 August.
By staffA three-week adoption call pits NIST and FIPS-driven demand for standalone ML-DSA against warnings that new PQ code will ship with exploitable bugs.
By ttlA new draft pairs ML-DSA with elliptic-curve operations for smaller hybrid signatures, drawing scrutiny over strong unforgeability, code size, and hedging.
By ttlA challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.
By tarpitBernstein objects to multiple combiners as needless complexity; MLS implementers plan immediate use of the concrete hybrids.
By ttl