Vincent RAMPAL
My feedback
15 results found
-
31 votes
An error occurred while saving the comment
Vincent RAMPAL
supported this idea
·
-
619 votes
An error occurred while saving the comment
Vincent RAMPAL
commented
Proton should implement post-quantum hybrid TLS both on SMTP and HTTPS.
This has been normalized with https://www.rfc-editor.org/info/rfc10024/
For SMTP TLS is the ONLY layer of defense when exchanging with other servers.
This is not a substitution for post-quantum end-to-end encryption but another important layer.
Vincent RAMPAL
supported this idea
·
-
447 votes
An error occurred while saving the comment
Vincent RAMPAL
commented
Proton should implement post-quantum hybrid TLS both on SMTP and HTTPS.
This has been normalized with https://www.rfc-editor.org/info/rfc10024/
For SMTP TLS is the ONLY layer of defense when exchanging with other servers.
This is not a substitution for post-quantum end-to-end encryption but another important layer.An error occurred while saving the comment
Vincent RAMPAL
commented
Post quantum cryptography will affect Proton both for data at rest and data in transit.
I see your plan for GPG encryption quantum safe but could you please clarify for TLS/QUIC and certificates ?Proton use encryption at different level:
* when Proton exchange mails with other mail servers (encryption in transit)
* when Proton verify the identity of other mail servers (certificate / signature)
* when Proton store mails using GPG (encryption at rest)
* when user connects to Proton servers (encryption in transit)
* when user verifies the identity of Proton servers (certificate / signature)
All of them needs to support post-quantum cryptography.Post quantum crypto is supported in GPG since version 2.5.1.
Source: https://lists.gnupg.org/pipermail/gnupg-announce/2024q3/000485.htmlNIST offer several standard of post quantum crypto.
Source: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardizationOpen Quantum Safe is also provide several solutions.
Project: https://openquantumsafe.org/
Presentations: https://www.douglas.stebila.ca/research/presentations/Cloudflare is quite active on this topic and you can use it as a reference to see if you are above or bellow competition.
https://www.cloudflare.com/pqc/
https://blog.cloudflare.com/pq-2024/
https://pq.cloudflareresearch.com/
Vincent RAMPAL
supported this idea
·
-
10 votes
An error occurred while saving the comment
Vincent RAMPAL
commented
Proton should implement post-quantum hybrid TLS both on SMTP and HTTPS.
This has been normalized with https://www.rfc-editor.org/info/rfc10024/
For SMTP TLS is the ONLY layer of defense when exchanging with other servers.
This is not a substitution for post-quantum end-to-end encryption but another important layer.
Vincent RAMPAL
supported this idea
·
-
164 votes
An error occurred while saving the comment
Vincent RAMPAL
commented
Proton should implement post-quantum hybrid TLS both on SMTP and HTTPS.
This has been normalized with https://www.rfc-editor.org/info/rfc10024/
For SMTP TLS is the ONLY layer of defense when exchanging with other servers.
This is not a substitution for post-quantum end-to-end encryption but another important layer.
Vincent RAMPAL
supported this idea
·
-
2,947 votes
Vincent RAMPAL
supported this idea
·
-
1,276 votes
Vincent RAMPAL
supported this idea
·
-
680 votes
Vincent RAMPAL
supported this idea
·
-
1,539 votes
Vincent RAMPAL
supported this idea
·
-
1,253 votes
Vincent RAMPAL
supported this idea
·
-
2,878 votes
Vincent RAMPAL
supported this idea
·
-
10 votes
Vincent RAMPAL
shared this idea
·
-
1,318 votes
Vincent RAMPAL
supported this idea
·
-
796 votes
Vincent RAMPAL
supported this idea
·
-
1,643 votes
Vincent RAMPAL
supported this idea
·
Proton should implement post-quantum hybrid TLS both on SMTP and HTTPS.
This has been normalized with https://www.rfc-editor.org/info/rfc10024/
For SMTP TLS is the ONLY layer of defense when exchanging with other servers.
This is not a substitution for post-quantum end-to-end encryption but another important layer.