Live data from Hacker News

A cryptography engineer's perspective on quantum computing timelines

words.filippo.io

191–200 of 260 posts

Re: A cryptography engineer's perspective on quantum computing timelines

#192

Earlier quoted context omitted.

How do you do revocation or software updates securely if your current signature algorithm is compromised?

I do not understand the fixation on authentication/signatures. They have different threat characteristics: You cannot retroactively forge historical authentication sessions, and future forgery ability does not compromise past data, and it only matters for long-lived signed artifacts (certificates, legal documents, etc.), yet the thread apparently keeps pivoting to signature deployment complexity? I do not get it.

The argument is that deploying PQ-authentication mechanisms takes time. If the authenticity of some connections (firmware signatures, etc…) is critical to you and news comes out that (")cheap(") quantum attacks are going to materialize in six months, but you need at least twelve months to migrate, you are screwed.

There is also a difference between closed ecosystems and systems that are composed of components by many different vendors and suppliers. If you are Google, securing the connection between data centers on different continents requires only trivial coordination. If you are an industrial IoT operator, you require dozens of suppliers to flock around a shared solution. And for comparison, in the space of operation technology ("OT"), there are still operators that choose RSA for new setups, because that is what they know best. Change happens in a glacial pace there.

Re: A cryptography engineer's perspective on quantum computing timelines

#193
post #190

Earlier quoted context omitted.

As long as a hybrid approach is taken what is there to worry about? Whereas not adopting PQC in a timely manner is obviously a gamble.

I agree, but the blog post was specifically ruling out hybrid approach.

> I'm really concerned by the current rush for PQ solutions and what are the real intentions behind it.

You had written. As long as we're in agreement that rushing PQ appears to be the appropriate choice. The only question is the precise form it should take, with the author arguing that hybrid would be unacceptably slow to roll out due to various social and bureaucratic reasons.

He's also pointing out that the only scenario in which hybrid is of benefit is one in which crypto related QC remains either relatively ineffective or extremely expensive in the medium term. Since that assumption is looking increasingly suspect it calls into question the point of hybrid to begin with. In the face of cheap QC hybrid adds zero value.

Re: A cryptography engineer's perspective on quantum computing timelines

#194
post #161

Earlier quoted context omitted.

> from a classical security point of view PQC cannot be trusted [citation needed] https://words.filippo.io/crqc-timeline/#fn:lattices

Just a little selections of recent attacks on a few post quantum assumptions: Isogenie/SIDH: https://eprint.iacr.org/2022/975 Lattices: https://eprint.iacr.org/2023/1460 Classical McEliece: https://eprint.iacr.org/2024/1193 Saying that you can trust blindly PQ assumptions is a very dangerous take.

He's obviously not saying that you can "trust blindly" any PQ algorithm out there, just that there are some that have appeared robust over many years of analysis.

Re: A cryptography engineer's perspective on quantum computing timelines

#195

The first and most obvious target will be Bitcoin. It’s market cap today is $1.4T. That’s a gigantic reward for any state actor or entity with the resources and budget to break it. Does this mean Bitcoin is going to $0? Absolutely not, it’s just going to take the community organizing and putting in the gigantic effort to make the changes. Frankly I’m not personally clear if that means all existing cold wallets need t…

> It’s market cap today is $1.4T. That’s a gigantic reward for any state actor or entity with the resources and budget to break it.

The market cap of a cryptocurrency — or any commodity, really — is not its market value. If you have all bitcoins in existence and try to sell them you will crash the price to zero. The slope of that price graph — from the current market price to zero — determines how much you make in total. Most cryptocurrency exchanges have public order books, so you can see how much (and at what price per coin) you can actually sell into the market before you eat up all the bids. Last time I checked it was closer to $10bn than $1trn.

Re: A cryptography engineer's perspective on quantum computing timelines

#196
post #161

Earlier quoted context omitted.

Just a little selections of recent attacks on a few post quantum assumptions: Isogenie/SIDH: https://eprint.iacr.org/2022/975 Lattices: https://eprint.iacr.org/2023/1460 Classical McEliece: https://eprint.iacr.org/2024/1193 Saying that you can trust blindly PQ assumptions is a very dangerous take.

He's obviously not saying that you can "trust blindly" any PQ algorithm out there, just that there are some that have appeared robust over many years of analysis.

He is assessing that the risk of seeing a quantum computer break dlog cryptography is stronger than the risk of having post quantum assumptions broken, in particular for lattices.

One can always debate but we have seen more post quantum assumptions break during the last 15 years than we have seen concrete progress in practical quantum factorisation (I'm not talking about the theory).

Re: A cryptography engineer's perspective on quantum computing timelines

#197

Earlier quoted context omitted.

I'm not sure who particularly cares about the stuff Signal is doing with SGX anyway. It always struck me as a 'because we can' move and if you're paranoid enough to worry about it then you're probably paranoid enough to not trust any manufacturer-based attestation anyway (All SGX does is make Intel the root of trust, and it's not like Signal would be less secure than any other third party if SGX were broken).

> I'm not sure who particularly cares about the stuff Signal is doing with SGX anyway. Security researchers like Matthew Green seem to care[0], the Signal people surely do, I myself do, too. Isn't that enough to raise that question? > if you're paranoid enough to worry about it You make it seem like that's an outlandish thought, when in reality there have been tons of reported vulnerabilities for SGX. And now QC repr…

I mean, if you're worried about Signal being a bad actor you also should probably be worried about Intel being a bad actor, and they hold the keys to SGX (especially because the biggest threat, if you're worried about this at all, is going to be governments compelling the involved companies to hand over data or attempt to intercept messages). And Signal is also a third party to your communications, that's how it works. But nothing about SGX makes me think Signal is more trustworthy, it doesn't meaningfully remove actions that they could take to compromise my communications.

Re: A cryptography engineer's perspective on quantum computing timelines

#198
post #190

Earlier quoted context omitted.

I agree, but the blog post was specifically ruling out hybrid approach.

> I'm really concerned by the current rush for PQ solutions and what are the real intentions behind it. You had written. As long as we're in agreement that rushing PQ appears to be the appropriate choice. The only question is the precise form it should take, with the author arguing that hybrid would be unacceptably slow to roll out due to various social and bureaucratic reasons. He's also pointing out that the only s…

I think it is pretty direct from my comment that if you use a hybrid approach (done correctly) you can rely on the hardness of dlog based assumption and therefore my comment on potential weakness of PQ assumptions can be ruled out. In this way we disagree that rushing PQ is the appropriate choice if it rules out dlog based security.

> He's also pointing out that the only scenario in which hybrid is of benefit is one in which crypto related QC remains either relatively ineffective or extremely expensive in the medium term. Since that assumption is looking increasingly suspect it calls into question the point of hybrid to begin with. In the face of cheap QC hybrid adds zero value.

This is exactly what I'm pointing out as extremely dangerous. My take was that the risk of seeing a quantum computer breaking dlog in a near future isn't stronger than breaking PQ assumptions in a near future.

Re: A cryptography engineer's perspective on quantum computing timelines

#199

Earlier quoted context omitted.

AIUI, the scientists achieved a self-sustaining nuclear chain reaction around 1943. That was the hard part, not even a small bomb yet, but a bomb just needed more fuel and scale. Fault tolerance is the hard part for QC, once it's achieved, the difference between factoring 35 and RSA-2048 is an engineering challenge, not an impossibility.

Fault tolerance is a hard problem, assembling qubits for simultaneous gate operations is another hard problem. There are several dozen others. It is exceptionally unlikely CRQC will be achieved in our lifetimes, if ever. The closer example is economically-viable fusion power production, which today has better odds than CRQC but remains solidly in the "maybe" zone after decades of global investment. Even though fusion…

Fusion also came to my mind but after thinking about it for longer I think it's a bad argument. The challenge with fusion is mostly around scale and efficiency to make it competitive against other energy sources (and net energy positive in the first place).

For CRQC it doesn't matter if they're massive expensive energy monsters. Even being able to break a single chosen key is enough to be a problem and once you can do one you can definitely do ten or a hundred.

Post reply on HN