Google is updating the post-quantum cryptography used in the Chrome browser to protect against TLS attacks using quantum computers and to mitigate store-now-decrypt-later. The upcoming change will replace Kyber used in hybrid key exchanges with a newer and slightly modified version of quantum cryptography, renamed Module Lattice Key Encapsulation Mechanism (ML-KEM).
See also: Hazard Ransomware: The story of a failed decryption

This change comes about five months after Google introduced its post-quantum secure TLS key encapsulation system in Chrome for all users, which also caused some issues with TLS exchanges.
However, the transition from Kyber to ML-KEM is not about those early problems being solved immediately. Rather, it is a strategic choice to abandon an experimental system for a NIST-approved and fully standardized mechanism.
Chrome's ML-KEM encryption was fully approved by the US National Institute of Standards and Technology (NIST) in mid-August, with the organization publishing the full technical specifications of the final version at that time. Google explains that despite the minor technical changes from Kyber to ML-KEM, the two are essentially incompatible, so a change had to be made.
See also: New Cryptokat Ransomware Implements Fast Encryption
Yata leaves Kyber
Google explains that support for Kyber must be removed completely because post-quantum encryption involves much larger data sizes compared to pre-quantum algorithms.

For example, a Kyber-based key exchange can take up over 1,000 bytes , and meta-quantum signatures like ML-DSA are even more bulky – leading to over 14,000 bytes in a typical exchange. If Google decides to keep Kyber support in addition to ML-KEM, the performance and network efficiency of Chrome will be severely affected.
Google notes that server operators could temporarily support both standards to maintain security for a broader set of customers and help make the transition smoother for customers who haven't upgraded yet, but ML-KEM encryption should be the ultimate goal for all interested Chrome users.
A proposed solution is for servers to announce which encryption algorithms they support via DNS, so that the client uses the appropriate key from the start, avoiding additional procedures during the exchange.
The update is set to be implemented in Chrome 131 (current version is 128), scheduled for release on November 6, 2024.Users of development channels like Chrome Canary, Beta , and Devshould see ML-KEM support sooner.
See also: Signal fixes encryption key flaw
Quantum encryption represents a groundbreaking advancement in the field of encryption, offering unprecedented security measures by leveraging the principles of quantum mechanics. Unlike classical encryption, which relies on complex mathematical algorithms, quantum encryption uses the unique properties of quantum particles, such as entanglement and superposition, to secure data. This approach makes it theoretically impossible for attackers to intercept communications without detection, as any attempt to measure quantum data would inherently alter it. As technology continues to evolve, quantum encryption is poised to revolutionize data security, providing strong protection for sensitive information in an increasingly digital world.
Source: bleepingcomputer
