A cryptography engineer's perspective on quantum computing timelines
191–200 of 260 posts
Re: A cryptography engineer's perspective on quantum computing timelines
#192Earlier quoted context omitted.
How do you do revocation or software updates securely if your current signature algorithm is compromised?
I do not understand the fixation on authentication/signatures. They have different threat characteristics: You cannot retroactively forge historical authentication sessions, and future forgery ability does not compromise past data, and it only matters for long-lived signed artifacts (certificates, legal documents, etc.), yet the thread apparently keeps pivoting to signature deployment complexity? I do not get it.
There is also a difference between closed ecosystems and systems that are composed of components by many different vendors and suppliers. If you are Google, securing the connection between data centers on different continents requires only trivial coordination. If you are an industrial IoT operator, you require dozens of suppliers to flock around a shared solution. And for comparison, in the space of operation technology ("OT"), there are still operators that choose RSA for new setups, because that is what they know best. Change happens in a glacial pace there.
Re: A cryptography engineer's perspective on quantum computing timelines
#193Earlier quoted context omitted.
As long as a hybrid approach is taken what is there to worry about? Whereas not adopting PQC in a timely manner is obviously a gamble.
I agree, but the blog post was specifically ruling out hybrid approach.
You had written. As long as we're in agreement that rushing PQ appears to be the appropriate choice. The only question is the precise form it should take, with the author arguing that hybrid would be unacceptably slow to roll out due to various social and bureaucratic reasons.
He's also pointing out that the only scenario in which hybrid is of benefit is one in which crypto related QC remains either relatively ineffective or extremely expensive in the medium term. Since that assumption is looking increasingly suspect it calls into question the point of hybrid to begin with. In the face of cheap QC hybrid adds zero value.
Re: A cryptography engineer's perspective on quantum computing timelines
#194Earlier quoted context omitted.
> from a classical security point of view PQC cannot be trusted [citation needed] https://words.filippo.io/crqc-timeline/#fn:lattices
Just a little selections of recent attacks on a few post quantum assumptions: Isogenie/SIDH: https://eprint.iacr.org/2022/975 Lattices: https://eprint.iacr.org/2023/1460 Classical McEliece: https://eprint.iacr.org/2024/1193 Saying that you can trust blindly PQ assumptions is a very dangerous take.
Re: A cryptography engineer's perspective on quantum computing timelines
#195The first and most obvious target will be Bitcoin. It’s market cap today is $1.4T. That’s a gigantic reward for any state actor or entity with the resources and budget to break it. Does this mean Bitcoin is going to $0? Absolutely not, it’s just going to take the community organizing and putting in the gigantic effort to make the changes. Frankly I’m not personally clear if that means all existing cold wallets need t…
The market cap of a cryptocurrency — or any commodity, really — is not its market value. If you have all bitcoins in existence and try to sell them you will crash the price to zero. The slope of that price graph — from the current market price to zero — determines how much you make in total. Most cryptocurrency exchanges have public order books, so you can see how much (and at what price per coin) you can actually sell into the market before you eat up all the bids. Last time I checked it was closer to $10bn than $1trn.
Re: A cryptography engineer's perspective on quantum computing timelines
#196Earlier quoted context omitted.
Just a little selections of recent attacks on a few post quantum assumptions: Isogenie/SIDH: https://eprint.iacr.org/2022/975 Lattices: https://eprint.iacr.org/2023/1460 Classical McEliece: https://eprint.iacr.org/2024/1193 Saying that you can trust blindly PQ assumptions is a very dangerous take.
He's obviously not saying that you can "trust blindly" any PQ algorithm out there, just that there are some that have appeared robust over many years of analysis.
One can always debate but we have seen more post quantum assumptions break during the last 15 years than we have seen concrete progress in practical quantum factorisation (I'm not talking about the theory).
Re: A cryptography engineer's perspective on quantum computing timelines
#197Earlier quoted context omitted.
I'm not sure who particularly cares about the stuff Signal is doing with SGX anyway. It always struck me as a 'because we can' move and if you're paranoid enough to worry about it then you're probably paranoid enough to not trust any manufacturer-based attestation anyway (All SGX does is make Intel the root of trust, and it's not like Signal would be less secure than any other third party if SGX were broken).
> I'm not sure who particularly cares about the stuff Signal is doing with SGX anyway. Security researchers like Matthew Green seem to care[0], the Signal people surely do, I myself do, too. Isn't that enough to raise that question? > if you're paranoid enough to worry about it You make it seem like that's an outlandish thought, when in reality there have been tons of reported vulnerabilities for SGX. And now QC repr…
Re: A cryptography engineer's perspective on quantum computing timelines
#198Earlier quoted context omitted.
I agree, but the blog post was specifically ruling out hybrid approach.
> I'm really concerned by the current rush for PQ solutions and what are the real intentions behind it. You had written. As long as we're in agreement that rushing PQ appears to be the appropriate choice. The only question is the precise form it should take, with the author arguing that hybrid would be unacceptably slow to roll out due to various social and bureaucratic reasons. He's also pointing out that the only s…
> He's also pointing out that the only scenario in which hybrid is of benefit is one in which crypto related QC remains either relatively ineffective or extremely expensive in the medium term. Since that assumption is looking increasingly suspect it calls into question the point of hybrid to begin with. In the face of cheap QC hybrid adds zero value.
This is exactly what I'm pointing out as extremely dangerous. My take was that the risk of seeing a quantum computer breaking dlog in a near future isn't stronger than breaking PQ assumptions in a near future.
Re: A cryptography engineer's perspective on quantum computing timelines
#199Earlier quoted context omitted.
AIUI, the scientists achieved a self-sustaining nuclear chain reaction around 1943. That was the hard part, not even a small bomb yet, but a bomb just needed more fuel and scale. Fault tolerance is the hard part for QC, once it's achieved, the difference between factoring 35 and RSA-2048 is an engineering challenge, not an impossibility.
Fault tolerance is a hard problem, assembling qubits for simultaneous gate operations is another hard problem. There are several dozen others. It is exceptionally unlikely CRQC will be achieved in our lifetimes, if ever. The closer example is economically-viable fusion power production, which today has better odds than CRQC but remains solidly in the "maybe" zone after decades of global investment. Even though fusion…
For CRQC it doesn't matter if they're massive expensive energy monsters. Even being able to break a single chosen key is enough to be a problem and once you can do one you can definitely do ten or a hundred.