Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Shipping post-quantum cryptography to Python

Trail of Bits has contributed post-quantum cryptography (PQC) support to CPython's hashlib and ssl modules, enabling Python developers to experiment with quantum-resistant algorithms like ML-KEM (FIPS 203) and ML-DSA (FIPS 204). The implementation uses the liboqs library and is scheduled for inclusion in Python 3.15, though it remains experimental and not ready for production use.

Background

- Trail of Bits is a respected cybersecurity research and consulting firm that routinely contributes security improvements to major open-source projects.<br>- Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist attacks from quantum computers, which could break widely used systems like RSA and elliptic-curve cryptography (ECC).<br>- The US National Institute of Standards and Technology (NIST) has been standardizing PQC algorithms; ML-KEM (also known as CRYSTALS-Kyber) is one of the chosen key-encapsulation mechanisms, designed for secure key exchange.<br>- This project adds ML-KEM support to the Python standard library's `hashlib` module, meaning any Python developer can use quantum-resistant cryptography without installing third-party packages — a major step for mainstream readiness.<br>- Python is one of the world's most popular programming languages, used in everything from web apps to data science to security tools, making widespread adoption of PQC possible through this library change.

Related stories