-
-
Notifications
You must be signed in to change notification settings - Fork 3.2k
Post-quantum key support in Kubo #11281
Copy link
Copy link
Open
Labels
P2Medium: Good to have, but can wait until someone steps upMedium: Good to have, but can wait until someone steps upneed/analysisNeeds further analysis before proceedingNeeds further analysis before proceedingneed/community-inputNeeds input from the wider communityNeeds input from the wider communityneed/maintainers-inputNeeds input from the current maintainer(s)Needs input from the current maintainer(s)status/blockedUnable to be worked further until needs are metUnable to be worked further until needs are met
Description
Activity
Metadata
Metadata
Assignees
Labels
P2Medium: Good to have, but can wait until someone steps upMedium: Good to have, but can wait until someone steps upneed/analysisNeeds further analysis before proceedingNeeds further analysis before proceedingneed/community-inputNeeds input from the wider communityNeeds input from the wider communityneed/maintainers-inputNeeds input from the current maintainer(s)Needs input from the current maintainer(s)status/blockedUnable to be worked further until needs are metUnable to be worked further until needs are met
Google published a threat model for post-quantum cryptography with a 2029 migration deadline.
IIUC the near-term risk is store-now-decrypt-later (SNDL): adversaries capturing encrypted traffic today for future decryption. This makes upgrading connection-layer forward secrecy urgent even before quantum computers exist.
NIST has finalized three post-quantum standards relevant to Kubo dependencies (libp2p and IPNS):
Multicodec code points for all three are registered or in review:
Ongoing spec and implementation discussions:
libp2p-keyand things that enable decoupling fromlibp2p-keyThe goal is not to change the default key type away from
Ed25519; that is a separate decision.The goal is working, opt-in PQ support well ahead of any forced migration. Large public and private swarms need multi-year upgrade lead time before a new key type can be broadly relied upon. Starting late means the option to migrate gracefully disappears.
What needs to happen:
go-libp2pipfs keycommandslibp2p-keyprotobuf wrapper?ctxboxo/gatewayandboxo/ipnsandboxo/namesysipfs namecommandsKubo does not need to wait for libp2p to fix IPNS, we should decouple anyway.