Live data from Hacker News

“Quantum-Safe” Crypto Hacked by 10-Year-Old PC

spectrum.ieee.org

131–140 of 187 posts

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#131
post #56
post #39

Earlier quoted context omitted.

Why do you think he's wrong? He's essentially saying IT systems need to be designed with the expectation that cryptographic algorithms will be attacked and may need to be replaced, as I understand it.

If by "crypto agility" one means "we should research diverse cryptographic primitives and constructions so that we can be ready if something we rely upon breaks", nobody disagrees with that. But that's not what Schneier means. What he says instead is that "it’s vital that our systems be able to easily swap in new algorithms when required". That approach has a virtually unbroken track record of failure. It demands neg…

[deleted]

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#132

Earlier quoted context omitted.

Can anyone do long division other than children and those who pursue math academically? Seems impossible to imagine.

You need to be able to perform long division to take quotients in algebraic structures, e.g. polynomials. Yes, Wolfram Alpha can probably do it, but not always.

It's easier with polynomials than with numbers, though.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#133
post #9

I wonder if someday we will see someone generating all the bitcoins on a laptop. How the article says, the math behind most cryptosystems were never proven to be unbreakable, it is just believed to be so, because no one managed to show otherwise.

This is inevitable for all coins with published public keys, which all the early coins are. So, e.g. all of Satoshi's coins. For coins where the public key is hashed, perhaps not inevitable.

Depending on how you look at it, it's either the built-in doomsday for Bitcoin, or it's a built-in multi-billion dollar bounty for exposing the existence of a quantum computer capable of cracking the private key given a Secp256k1 public key (that's the EC curve bitcoin uses).

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#135
post #82

Earlier quoted context omitted.

> Jumping is also real, but we need not worry about people jumping out of the atmosphere. If people are jumping twice as high this year than last, we would ;) https://www.researchgate.net/figure/A-chart-shows-the-progre... (BTW this reply is not meant to make a point about the state of quantum -- it's complicated -- but merely as a response to the analogy)

I'm not much of a believer. It's worth pointing out that as the number of qubits goes up, so too does the error rate.

A larger number of qubits allows us to do effective quantum error correction. The idea is to group multiple physical qubits into one logical qubit, think of it as redundancy.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#137

Earlier quoted context omitted.

Well they for sure have picked a very ironic name for it. "The vault is completely unhackable." "SIKE"

+1, funny -- but for the sake of non-native English speakers, FTR, it's pronounced the same as "psych" and is colloquial for a sarcastic "ha-ha, just kidding"

> it's pronounced the same as "psych"

It’s actually spelled “psych.” It’s a derivative of “to psych out.”

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#138

Earlier quoted context omitted.

My super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption... Its felt like FUD based on FUD for a while. Not that I really trust traditional encryption that much either. There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... Hate making cynical comments tho, they al…

This is a place where Hanlon's razor applies much better than assuming they want weak encryption.

It really isn't, when the annual budget for states crippling cryptographic standards dwarfs the salaries and tuition of everyone in the global academics maths community combined.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#139

> paper: https://eprint.iacr.org/2022/975.pdf Does this mean that probably all SIDH key exchanges are affected? What about TOR? Do we have to assume that key exchanges can be intercepted and recovered? A RUSTSEC advisory was already published and they removed all SIDH algorithms there [1] [1] https://rustsec.org/advisories/RUSTSEC-2022-0045.html

Does Tor use SIKE/SIDH? The proposals I've seen for PQC Tor all seem to run a PQC construction alongside a conventional one (the only sane way to do this right now), and so, no, a break in the PQC wouldn't let you recover sessions.

Yes, this impacts all of SIDH.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#140
post #13

If you'd like to hear someone who can barely do long division† discuss this vulnerability with one of the leading isogeny cryptographer researchers and the world's most isogeny-enthusiastic cryptography engineer, have I got a podcast for you: https://securitycryptographywhatever.buzzsprout.com/1822302/... There's even a transcript, if you want to read things like: So I watched the, uh, I watched Costello's tutorial,…

Can anyone do long division other than children and those who pursue math academically? Seems impossible to imagine.

I guess a few advanced software developers may also be able to apply such a complex algorithm to a couple of integers.
Post reply on HN