X25519Kyber768Draft00 Hybrid Post-Quantum Key

Discussion in 'privacy technology' started by Sampei Nihira, Jan 19, 2024.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
  2. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,868
    Location:
    the Netherlands
    Interesting, thanks.
    I see it is supported in Firefox Nightly, but not in Firefox release version, so I haven't yet enabled the feature.
     
  3. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    :thumb:

    I decided to enable 2 flags in my Edge and do some testing in the various web pages I usually open:

    • TLS 1.3 hybridized Kyber support
    • Enable Kyber768 + NIST-P384 TLS Kyber Confidentiality
    It is possible to check the various options with the test below:

    https://browserleaks.com/tls


    Default:

    1.jpg

    Only first flag enabled:

    2.jpg

    Both:

    3.jpg
     
    Last edited: Jan 21, 2024
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy

    https://www.bleepingcomputer.com/ne...uantum-resistant-encryption-to-protect-email/

    My wife uses Tuta Mail.
    My wife is German.
    I will probably also consider opening a Tuta Mail account.

    P.S.

    Android app not working well (lost connections) so attachments not uploaded and email message not shown in smartphones without Google Services.
     
    Last edited: Mar 12, 2024
  5. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    I have noticed that almost all of the Web sites I open usually use TLS 1.3.
    But not unfortunately WSF:

    1.jpg


    I decided to enable this flag in Edge:


    Code:
    TLS 1.3 Early Data - Enabled
    to improve browser performance.

    https://www.ssldragon.com/blog/tls-1-2-vs-1-3/
     
  6. Libraman

    Libraman Registered Member

    Joined:
    Apr 26, 2016
    Posts:
    203
    Hi. Firefox stable 124.x is support now.

    cloudflare.png
     
  7. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,868
    Location:
    the Netherlands
    Thanks, Libraman.
    Interesting!

    https://pq.cloudflareresearch.com/
    Software support
    Firefox 124+ if you turn on security.tls.enable_kyber in about:config. [new!]

    I notice that in the release notes for Firefox Nightly 126.0a1 the following is still mentioned:

    Web Platform
    Starting with Firefox 125, Nightly builds will attempt to establish TLS connections using a hybrid post-quantum key agreement mechanism (X25519+Kyber768). This may result in slow TLS handshakes or failed connections on networks with TLS intercepting middleboxes. The feature can be disabled by setting the security.tls.enable_kyber preference to false.
    Bug 1878725
     
  8. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    I also noticed that many websites (but not WSF) use the QUIC protocol:

    https://www.teimouri.net/quic-speeding-web-revolution-networking/

    (which I have long since enabled in my browser).
    It seems to me that with the recent flag enabled I get a much faster response from many websites.

    Example from another forum frequented by some WSF members:

    2.jpg
     
  9. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,942
    at least its a cloudflare-only feature. if you do not use or see CF hosted/secured pages you probably never will notice it. if mozilla will recognise this as an urgent feature they will enable it by default, otherwise no one should care. http3/quic is available since 2020 and enabled by default since ... early 2021 in firefox.
     
  10. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,441
    Location:
    Slovakia
    I did now. Thank you.
    There is no way in hell I will ever enable less secure QUIC to gain a few measly milliseconds.
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    :D;):thumb:

    P.S.

    Consider that almost all websites that adopt the QUIC protocol use X25519Kyber768Draft00 Hybrid Post-Quantum Key with your browser.
    Websites using TLS 1.3 do not always use the Post Quantum key.
     
    Last edited: Mar 30, 2024
  12. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    I recently noticed that,at least in Edge, using the QUIC flag at default does not guarantee that the browser will NOT use this protocol.

    So I would like to advise all forum members who do not like this active feature to check via the browser development tools.

    Or simply disable the QUIC flag.
     
  13. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,441
    Location:
    Slovakia
    You can also check via a firewall or a network watcher, UDP via port 443 is a dead giveaway. I use QUIC on Brave for Youtube/Google, since privacy or security does not matter there. :p
     

    Attached Files:

  14. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    I have a curiosity.
    In LibreWolf:

    Code:
    network.http.http3.enable
    is it set to false by default?
     
  15. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,441
    Location:
    Slovakia
    True by default
     

    Attached Files:

  16. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    Do you leave it to default?
    Or do you trust Mozilla QUIC more than Google QUIC?
    ;):)
     
  17. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,441
    Location:
    Slovakia
    I use LibreWolf only for Facebook, but to be fair I did not know about it, I must have forgotten about it back then. I have blocked UDP in the firewall now and FB is still working. So thank you, again. I must buy you a beer sometime. ;)
     
  18. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    :thumb::)
    If you come to Italy,I will gladly take a beer.
    Thank you for your answers.
     
  19. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    I insert a simple QUIC connection test for W. members who do not like to use indirect methods:


    https://quic.nginx.org/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.