A bet on whether ML-KEM-768 or X25519 will break first

55 points by figsoda


bitshift

It's always fun to see friendly public bets like this.

If neither is broken [by the end of 2040], the main wager is a push and no donation is made.

Personally, I think that's the most likely outcome, maybe about a 60% chance no money changes hands? Interested to hear what other folks think.

How I made up that number:

Filippo Valsorda buys Matthew Green a reasonable round of drinks if, by the deadline, ML-KEM-512 is no longer considered secure for new deployments.

I kind of want to see this happen—just to force the issue of what constitutes a "reasonable" round!

romen

The fact that implementation-level defects are excluded sidesteps the main motivating factor for the advocates of “only-hybrids everywhere”: all implementations of PQC are quite novel compared to ECC implementations, in addition to the fact that new defects in new or existing ECC implementations are not unheard of either.

We want hybrids because while their cost is negligible, it requires the attacker to exploit vulnerabilities in 2 implementations at the same time, providing an extra layer of security for everyone.