Live data from Hacker News

A cryptography engineer's perspective on quantum computing timelines

words.filippo.io

231–240 of 260 posts

Re: A cryptography engineer's perspective on quantum computing timelines

#231

Earlier quoted context omitted.

Perhaps you would care to enlighten us ignorant plebs rather than taunting us? My understanding (obviously as a non expert) matches what cyberax wrote above. Is it not common wisdom that the pursuit of new and exciting crypto is an exercise filled with landmines? By that logic rushing to switch to the new shiny would appear to be extremely unwise. I appreciate the points made in the article that the PQ algorithms are…

Calling out a mistaken assertion isn't a "taunt".

"taunt" in the sense that you dangle some knowledge in front of people and make them beg, not "taunt" in the sense of "insult".

You said:

>"[...] don't even get what the real argument is."

and then refuse to explain what the "real" argument is. someone then asks for clarification and you say:

"It's definitely not [...]""

okay, cool! you are still refusing to explain what the "real" argument is. but at least we know one thing it isnt, i guess.

you haven't even addressed the "mistaken assertion". you just say "nah" and refuse to elaborate. which is fine, i guess. but holy moly is it ever frustrating to read some of your comment chains. it often appears that your sole goal in commenting is to try and dunk on people -- at least that is how many of your comments come across to me.

Re: A cryptography engineer's perspective on quantum computing timelines

#232

Earlier quoted context omitted.

The actual revocation needn't be secure. False revocations are an oxymoron. The practice around revocations need to be secure of course, but that's more on an engineering problem than a cryptographical.

Can you explain a bit more what you mean by "secure" in the context of "actual revocations"? The oxymoronic nature isn't self-evident enough for me to catch your intended meaning before my first cup of coffee.

If you receive a forged crl, in the worst case it will revoke certificates that you can't trust anyway. Even if it says "certificate X is still good", that's equivalent to receiving no crl.

Re: A cryptography engineer's perspective on quantum computing timelines

#233

Earlier quoted context omitted.

Calling out a mistaken assertion isn't a "taunt".

"taunt" in the sense that you dangle some knowledge in front of people and make them beg, not "taunt" in the sense of "insult". You said: >" [...] don't even get what the real argument is. " and then refuse to explain what the "real" argument is. someone then asks for clarification and you say: " It's definitely not [...]" " okay, cool! you are still refusing to explain what the "real" argument is. but at least we kn…

I was explicit about what the real argument isn't: the notion that lattice cryptography is under-studied compared to RSA/ECC.

I understand what your takeaway from this thread is, but my perspective is that the thread is a mix of people who actually work in this field and people who don't, both sides with equally strong opinions but not equally strong premises. The person I replied to literally followed up by saying they don't follow the space! Would you have assumed that from their preceding comment?

(Not to pick on them; acknowledging that limitation on their perspective was a stand-up move, and I appreciate it.)

You do "XYZ isn't the right argument, ABC is" on a thread like that, and the reply tends to be "well yeah that's what I meant, ABC is just a special case of XYZ". No thanks.

Re: A cryptography engineer's perspective on quantum computing timelines

#234

Earlier quoted context omitted.

"taunt" in the sense that you dangle some knowledge in front of people and make them beg, not "taunt" in the sense of "insult". You said: >" [...] don't even get what the real argument is. " and then refuse to explain what the "real" argument is. someone then asks for clarification and you say: " It's definitely not [...]" " okay, cool! you are still refusing to explain what the "real" argument is. but at least we kn…

I was explicit about what the real argument isn't: the notion that lattice cryptography is under-studied compared to RSA/ECC. I understand what your takeaway from this thread is, but my perspective is that the thread is a mix of people who actually work in this field and people who don't, both sides with equally strong opinions but not equally strong premises. The person I replied to literally followed up by saying t…

I'm not a professional cryptographer, but I _am_ really interested in opinions of experts in the field and I do have a lot of prior experience with crypto (the actual kind, not *coin). From my point of view, I just don't see what's the fuss is all about.

Re: A cryptography engineer's perspective on quantum computing timelines

#235

Earlier quoted context omitted.

I was explicit about what the real argument isn't: the notion that lattice cryptography is under-studied compared to RSA/ECC. I understand what your takeaway from this thread is, but my perspective is that the thread is a mix of people who actually work in this field and people who don't, both sides with equally strong opinions but not equally strong premises. The person I replied to literally followed up by saying t…

I'm not a professional cryptographer, but I _am_ really interested in opinions of experts in the field and I do have a lot of prior experience with crypto (the actual kind, not *coin). From my point of view, I just don't see what's the fuss is all about.

I'm really not looking to drill further into the comment you wrote. I think we've converged on a shared understanding at this point.

Re: A cryptography engineer's perspective on quantum computing timelines

#236

Earlier quoted context omitted.

I'm not a professional cryptographer, but I _am_ really interested in opinions of experts in the field and I do have a lot of prior experience with crypto (the actual kind, not *coin). From my point of view, I just don't see what's the fuss is all about.

I'm really not looking to drill further into the comment you wrote. I think we've converged on a shared understanding at this point.

There's no shared understanding, just a snarky expert claiming (in effect) "I know better than all you simpletons but I'm not going to share". At best it's incredibly poor behavior. At worst it's the behavior of someone who doesn't actually have a defensible point to make.

Re: A cryptography engineer's perspective on quantum computing timelines

#237
post #198

Earlier quoted context omitted.

> I'm really concerned by the current rush for PQ solutions and what are the real intentions behind it. You had written. As long as we're in agreement that rushing PQ appears to be the appropriate choice. The only question is the precise form it should take, with the author arguing that hybrid would be unacceptably slow to roll out due to various social and bureaucratic reasons. He's also pointing out that the only s…

I think it is pretty direct from my comment that if you use a hybrid approach (done correctly) you can rely on the hardness of dlog based assumption and therefore my comment on potential weakness of PQ assumptions can be ruled out. In this way we disagree that rushing PQ is the appropriate choice if it rules out dlog based security. > He's also pointing out that the only scenario in which hybrid is of benefit is one…

You seem to just be rehashing what we already clearly agree on. Obviously if you view classically breaking PQ algorithms as higher likelihood than QC breaking classical then you are going to disagree with the premise.

Can you actually back up your prediction that crypto related QC will remain either relatively ineffective or extremely expensive in the medium term?

Re: A cryptography engineer's perspective on quantum computing timelines

#239
post #138

Earlier quoted context omitted.

That would depend... There's a whole lot of cases where the tokens are temporary in nature with an easy cut-over, either dropping old entries or re-encrypting while people are not at work. We tend to think of big commerce like amazon or google that need 24/7 uptime, but most individual systems are not of that scale In most other cases you increment the version number for the new data format and copy-paste the (d)e(n)…

The moment you say "lot of cases", multiply the cost by $100,000,000.

lol, sure

Re: A cryptography engineer's perspective on quantum computing timelines

#240

Earlier quoted context omitted.

I'm really not looking to drill further into the comment you wrote. I think we've converged on a shared understanding at this point.

There's no shared understanding, just a snarky expert claiming (in effect) "I know better than all you simpletons but I'm not going to share". At best it's incredibly poor behavior. At worst it's the behavior of someone who doesn't actually have a defensible point to make.

:thatsbait:
Post reply on HN