upvote
While I'm highly sympathetic to competing priorities crowding out movement to pq cryptography. At the same time it's not sudden at all. It's been 10 years since nist first said "move shit over"?
reply
Yes, and at that time the answer was "move over where?" now it's 2026 and x-wing is a draft still
reply
Ah. This is a bold faced lie. There were plenty of options in 2016. Nist released final candidates in 2024 and published the candidates this year.

ssh (as noted in tfa) has had pq defaults since 2022.

reply
In case you wanted to know, the expression is actually "bald-faced lie", i.e. unmasked, shameless.
reply
"bold-faced lie" and "bald-faced lie" are both valid expressions. The original expression is "bare-faced lie" but they're all pretty similar to each other.
reply
Yes but only one of them makes most people who hear it think you don’t know the expression you’re trying to use. There’s no objective reason it has to be this way, but it is, and at least personally I appreciate being told when I’ve got something stuck to my back.
reply
bold-faced lie is just the usual English drift that was actually questioned as incorrect when it first surfaced. If a lie is bold, you don't have to suggest that the user's face is bold when doing it. You can in thirty seconds of google searching find numerous sources explaining that "bold-faced" is a malapropism.
reply
It's the usual English drift perhaps, but "bold faced lie" has been used since the 17th century, which is also apparent from "thirty seconds of Google searching". Three hundred years is enough usage for me to count it as correct.

On a side note, "bold faced" does not mean the persons face is bold, only that it is said boldly, which implies a level of rudeness that "bald-faced" or "bare-faced" does not.

reply
Colloquialisms and slang have unstable meaning over history, location, and cultures.

Generally, something to be avoided by people striving for clearer communication. =3

reply
They are also lying, it is an Italics-Faced lie... thank you, I will see myself out. =3
reply
Calling it a lie is pretty heavy.
reply
Yeah the deadline to move everything is drawing near I am actually not impressed by how fast things are going but all progress is good.
reply
its ok we are still rawdogging ftp every day in the business world. The fax machines of the future truly
reply
The .NET team have been similarly busy on post-quantum lately, it completely dominated the .NET API reviews for the dotnet 11 release.

It seems there's a big push happening behind the scenes.

reply
And Java implementations as well.
reply
US Government is starting to push hard so code first needs to support it.
reply
Ok, but when is it coming to our web browsers and email clients?
reply
I don't know about mail clients, but it's in most web browsers already.
reply
Then I'm wondering why they don't simply use the same crypto libraries as the web browsers.
reply
Chromium uses BoringSSL, which opens its readme as follows:

> BoringSSL is a fork of OpenSSL that is designed to meet Google's needs.

> Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.

OpenSSL itself is a clusterfuck that doesn't really meet anyone's needs: https://cryptography.io/en/latest/statements/state-of-openss...

reply
Go features cleaner crypto APIs (than OpenSSL for example) with less footguns.
reply
Preventing CGO overhead maybe?
reply
It’s been on by default for 2 years in Chrome.
reply
This person was public on the recent nist list against hybrid solutions. I simply don't understand why they would oppose the safer option. Yes I've read the mailing list, it just all seems quite suspicious.
reply