mullvad / mullvadvpn-app

The Mullvad VPN client app for desktop and mobile
https://mullvad.net/
GNU General Public License v3.0
5.03k stars 337 forks source link

We may need at least triple AES256 #5578

Closed ghost closed 10 months ago

ghost commented 10 months ago

Mullvad added post-quantum ciphers Kyber and McEliece, https://www.ambit.inc/pdf/KyberDrive.pdf It says "Kyber-1024 is known to have 254 bits of classical security and 230 bits of quantum security (core-SVP hardness)." For quantum computers, it requires at least triple 256-bit AES to get about 256-bit quantum security.

raksooo commented 10 months ago

Thanks for the feedback. This is a question better directed at our support team (support@mullvad.net) since the app is only a small part of the affected infrastructure/code for such a change.