Live data from Hacker News

“Quantum-Safe” Crypto Hacked by 10-Year-Old PC

spectrum.ieee.org

81–90 of 187 posts

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#81
post #79

It was not in NIST final competition, right ? Just alternate candidate.

IIUC, NIST did not select a winner for post-quantum public-key-encryption, but rather winnowed the field to 4 potential candidates, and this is one of them.

No, it selected the CRYSTALS-Kyber KEM and then proceeded for an additional round to consider alternatives/understudy KEMs, of which SIKE was one potential one.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#82
post #50

Earlier quoted context omitted.

> Its felt like FUD based on FUD for a while. Not really...? Quantum stuff is real, there are real quantum computers that have been demonstrated to really do quantum operations. They're not close to being usable to break crypto yet, but it certainly makes sense to get ahead of it. > There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... These are com…

quantum is used for problems like finding the factorization of the number 4. Jumping is also real, but we need not worry about people jumping out of the atmosphere.

> Jumping is also real, but we need not worry about people jumping out of the atmosphere.

If people are jumping twice as high this year than last, we would ;) https://www.researchgate.net/figure/A-chart-shows-the-progre...

(BTW this reply is not meant to make a point about the state of quantum -- it's complicated -- but merely as a response to the analogy)

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#83
post #50

Earlier quoted context omitted.

> Its felt like FUD based on FUD for a while. Not really...? Quantum stuff is real, there are real quantum computers that have been demonstrated to really do quantum operations. They're not close to being usable to break crypto yet, but it certainly makes sense to get ahead of it. > There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... These are com…

quantum is used for problems like finding the factorization of the number 4. Jumping is also real, but we need not worry about people jumping out of the atmosphere.

I'm not a believer (I'm not qualified to have an opinion but neither is almost anyone else here) in PQC, but to be clear, the logic behind moving forward on PQC is straightforward: everybody acknowledges that there are no known useful QC attacks on cryptography, nor really any on the horizon, but adversaries can easily stockpile terabytes of recorded network conversations today and keep them around to break when QC attacks do work.

If you think QC attacks are 20 years away from real-world demonstrations, then conventional cryptography has a 20-year ceiling, which would be a hair-on-fire analysis in any other context. How long are you willing to bet conventional cryptography will hold out? 50 years is also too short by cryptographic standards. And 50 years is a long time. You willing to bet 100 years? I am, but, like, nobody should listen to me on this.

This is also why KEMs are a priority over signatures for PQC deployment.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#85

Earlier quoted context omitted.

Well they for sure have picked a very ironic name for it. "The vault is completely unhackable." "SIKE"

+1, funny -- but for the sake of non-native English speakers, FTR, it's pronounced the same as "psych" and is colloquial for a sarcastic "ha-ha, just kidding"

For additional cultural context, I think this usage was popularized by Eddie Murphy in Delirious (NSFW language: https://youtu.be/Ft4kEk5CHrE, you'll want to listen to at least 2:15)

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#86
post #61
post #37

sort of offtopic but it reminds me of the first auto shop I worked in. I just got certified on a new laser alignment tool and had a chip on my shoulder for almost a week, until an old timer manually dialed in an alignment that checked out perfect on my shiny new gizmo. I'd never felt so humbled in my life and spent that whole summer practicing manual alignments.

Your seem to be using “chip on the shoulder” to mean “being overly proud”: is your usage common in your circles or is it a mistake? https://grammarist.com/idiom/chip-on-your-shoulder/

My anecdotal usage is a combination of these two. Until I saw your provided definition I would have described chip on my shoulder to mean a sense of superiority that leads to me be rude or difficult to interact with.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#87
post #10

You KNOW they first had to do this in the normal way (large scale, distributed servers)..... and cracked it in like a second. Then for grins, the engineer HAD to say "I wonder if I could do this on my old Mac mini". And it worked. And for embarrassment of the original design, the story, and clickbait... they did it on that old machine

Mathematicians do not have funding for „large scale“. A 10-year old mid-range server is exactly the kind of system I would expect Magma to run on in the average case. Perhaps even just a desktop pc. Source: worked with algebra researchers using Magma.

I was being a bit facetious, but not by much. Maybe because they're mathematicians and had found a theorem - but a pen tester wouldn't have.

It costs less than a few hundred bucks to do numerous, multi compute AWS server spot instances for cracks on large dictionaries with large hash rates, on random seed password lists (where each password has it's own seed).

If it was trying to crack a quantum-safe where by design the classical computer shouldn't be able to even solve it (except for potentially with a theorem hole) - you'd think they'd start higher.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#88

Earlier quoted context omitted.

Well they for sure have picked a very ironic name for it. "The vault is completely unhackable." "SIKE"

+1, funny -- but for the sake of non-native English speakers, FTR, it's pronounced the same as "psych" and is colloquial for a sarcastic "ha-ha, just kidding"

Further, "sike" has become a common spelling when used to indicate "not really." At least, according to urban dictionary and other online dictionaries.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#89

It was designed by engineers to be quantum resistant without enough deference to mathematicians who could see that it was not resistant to more conventional approaches.

> It was designed by engineers to be quantum resistant without enough deference to mathematicians who could see that it was not resistant to more conventional approaches.

Ie, they didn't take enough time and money to consult with every cryptography and mathematics expert.

Post reply on HN