freenode
Security & Cryptography

BSI advises against new use of Classic McEliece

Germany’s cybersecurity agency says the code-based post-quantum candidate should not be chosen for new systems after recent cryptanalysis.

Germany’s Federal Office for Information Security (BSI) has advised that Classic McEliece should no longer be used in new developments or when planning new cryptographic applications, following recent cryptanalysis of the long-standing code-based scheme.

Tobias Hemmert of BSI’s cryptography division pointed the NIST post-quantum cryptography forum to the agency’s English-language note and a German press release. The statement underscores that hybrid deployments pairing Classic McEliece with a classical algorithm still deliver at least the security of the classical component, and that the broader practice of deploying post-quantum cryptography in hybrid mode has proven its value.

Classic McEliece was a prominent candidate in the NIST post-quantum process and has been studied for decades, but it has seen far less large-scale deployment than lattice-based alternatives now moving into standards. John Preuß Mattsson of Ericsson welcomed the clarity of the BSI guidance and argued that the episode strengthens the case for algorithms that have passed open standardization and real-world use. He also favored post-quantum/post-quantum hybrids for high-security key exchange, so that quantum resistance survives if only one of the components remains unbroken, rather than relying on a classical fallback alone.

The BSI position does not claim a total break of every parameter set in existing deployments. It does, however, remove Classic McEliece from the set of schemes German guidance will support for fresh designs while cryptanalysis continues.