From 668fb65efbc2a6a699742612e8666c73408f545f Mon Sep 17 00:00:00 2001 From: Laan Tungir Date: Wed, 29 Jul 2026 09:18:28 -0400 Subject: [PATCH] Removed ML-KEM note from TLDR area per feedback; keep TLDR unchanged --- README.md | 2 -- package.json | 2 +- www/js/version.json | 6 +++--- 3 files changed, 4 insertions(+), 6 deletions(-) diff --git a/README.md b/README.md index 3240f2f..3bf2337 100644 --- a/README.md +++ b/README.md @@ -23,8 +23,6 @@ I have currently used the following post quantum algorithms: This app will generate public-private keypairs for each of these, publish on nostr your public key for each, and sign it with your current Nostr identity via your favorite signer (the nsec never leaves the signer). -> **Note on ML-KEM-768.** ML-KEM-768 (Kyber, FIPS 203) is a **Key Encapsulation Mechanism (KEM)**, not a signature scheme — it cannot sign events. The first four algorithms (ML-DSA-44, ML-DSA-65, SLH-DSA-128s, Falcon-512) are the post-quantum **signature** schemes that sign the attestation and provide post-quantum authenticity. ML-KEM-768 is included only to pre-commit a post-quantum **encryption** public key, so that a future post-quantum Nostr messaging protocol (e.g., PQ-encrypted DMs or session-key exchange) can use it without re-anchoring a new key to your identity. Its ownership is authorized by your existing secp256k1 signature over the kind 1 event, not by a PQ signature. See [ML-KEM cannot sign](#ml-kem-cannot-sign) for the full rationale. - You are making a statement to the world: "Here are post quantum pubkeys. If quantum computers hit, you know that the person signing using these can only be me." This entire kind 1 event is then hashed and stamped into a block on Bitcoin using OpenTimestamps. diff --git a/package.json b/package.json index 9386998..0bf079f 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "nostr_quantum_preparation", - "version": "0.1.2", + "version": "0.1.3", "description": "A migration strategy for bringing post-quantum security to Nostr without breaking the social graph, without requiring consensus on a single post-quantum algorithm, and without forcing existing users to abandon their identities.", "main": "index.js", "scripts": { diff --git a/www/js/version.json b/www/js/version.json index 22a1f19..708b4d4 100644 --- a/www/js/version.json +++ b/www/js/version.json @@ -1,5 +1,5 @@ { - "VERSION": "v0.1.2", - "VERSION_NUMBER": "0.1.2", - "BUILD_DATE": "2026-07-29T13:17:12.249Z" + "VERSION": "v0.1.3", + "VERSION_NUMBER": "0.1.3", + "BUILD_DATE": "2026-07-29T13:18:27.972Z" }