Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I saw that strongSwan had already supported two post-quantum key exchange algorithms (NTRU and NewHope) for IPSec IKEv2. Good.

https://wiki.strongswan.org/projects/strongswan/wiki/IKEv2Ci...



If IPSec is a complicated, commitee-designed and NSA interfered technology, and moreover not recommended by information security researchers, isn't a detail such as support for post-quantum algorithms irrelevant?

http://www.mail-archive.com/cryptography@metzdowd.com/msg123...

https://www.schneier.com/academic/paperfiles/paper-ipsec.pdf


From Schneier's IPSec paper

Conclusions

We are of two minds about IPsec. On the one hand, IPsec is far better than any IP security protocol that has come before: Microsoft PPTP, L2TP, etc.

On the other hand, we do not believe that it will ever result in a secure operational system.

It is far too complex, and the complexity has lead to a large number of ambiguities, contradictions, inefficiencies, and weaknesses.

It has been very hard work to perform any kind of security analysis; we do not feel that we fully understand the system, let alone have fully analyzed it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: