Connect with us

Hi, what are you looking for?

Hard News Hard Hitting News Source Global Political News

Cyber Security

OpenSSH 9.0 bakes in post-quantum cryptography to future proof against attacks

Developers of the OpenSSH secure networking utility are ‘future proofing’ the technology by adopting post-quantum cryptography.

The latest OpenSSH 9.0 release defaults to the NTRU Prime algorithm – a scheme designed to resist brute-force attacks that might be enabled by future quantum computers – while supporting the previous default (X25519 ECDH key exchange) as a backstop. In either case, the algorithms are used to negotiate session keys that protect data in transit.

OpenSSH is a widely used open source technology used for applications including enabling the remote login of severs and secure file transfer.

Conventional cryptographic schemes derive their security from the difficulty of solving mathematical problems that current computers are unable to crack.

Quantum computers are still in their infancy but offer the potential to drastically reduce the time and resources needed to break current encryption schemes.

Even though this potential threat only exists in the future, OpenSSH developers said they are making the change now (ahead of cryptographically-relevant quantum computers) “to prevent ‘capture now, decrypt later’ attacks where an adversary who can record and store SSH session ciphertext would be able to decrypt it once a sufficiently advanced quantum computer is available”.

Looking ahead

The switch – detailed in a release note from developers last Friday – guards against the possibility that intel agencies or similarly capable attackers might harvest and store encrypted data protected by OpenSSH exchanges that might be broken in the future as a result of as yet unrealized advances in quantum computing.

Quantum computers rely on the properties of quantum states – such as superposition or entanglement – rather than the simple binary states (0 or 1) of conventional computers.

When combined with quantum algorithms the technology might be expected to solve some mathematical problems, such as integer factorization, in a much shorter amount of time – posing a threat to current encryption schemes.

OpenSSH has embraced the future of post-quantum cryptography ahead of the ratification of future protocols by NIST, a forward thinking move welcomed by at least some specialists in the field.

Duncan Jones, cryptography expert and head of cybersecurity at quantum computing start-up Quantinuum, commented: “The OpenSSH team should be applauded for taking a public stand at a time when most security products are in a holding pattern waiting for the NIST post-quantum process to complete.

“Although the timing of their release is surprising, with major NIST announcements expected in the days to come, it shows they value user security above the potential inconvenience of adjusting algorithms in subsequent releases.”

Source: https://portswigger.net/daily-swig/openssh-9-0-bakes-in-post-quantum-cryptography-to-future-proof-against-attacks

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Cyber Security

The cybercrime group evaded remediation efforts by installing persistent backdoors and deploying “new and novel malware.” A Chinese-linked hacking group that security researchers say...

Cyber Security

Google has announced the first open-source quantum resilient FIDO2 security key implementation, which uses a unique ECC/Dilithium hybrid signature schema co-created with ETH Zurich....

Cyber Security

The administration and its private sector partners announced a slate of new initiatives on Monday aimed at protecting the nation’s school systems and their...

Cyber Security

The plan includes measures for improving cybersecurity knowledge at all levels of education and improving how the federal government attracts, hires and pays cybersecurity...

Copyright © 2023 Hard News Herd Hitting in Your Face News Source | World News | Breaking News | US News | Political News Website by Top Search SEO