Live data from Hacker News

Quantum Resistance and the Signal Protocol

signal.org

1–10 of 135 posts

Re: Quantum Resistance and the Signal Protocol

#3

Super cool. If current quantum computers were scaled up to more qubits, could they break modern crypto? Or would we need both more qubits and a new quantum computer architecture?

15 was factorised on a 7 qbit computer by IBM, so yes, they could break RSA if scaled up. I'm not sure about elliptic curve. That was over 20 years ago: https://research.ibm.com/blog/factor-15-shors-algorithm

I wonder how possible it is that IBM could have already gone further and are already cracking modern crypto in secret, e.g. funded by the NSA. Is that a crazy conspiracy idea, or actually a possibility?

Re: Quantum Resistance and the Signal Protocol

#4
post #3

Super cool. If current quantum computers were scaled up to more qubits, could they break modern crypto? Or would we need both more qubits and a new quantum computer architecture?

15 was factorised on a 7 qbit computer by IBM, so yes, they could break RSA if scaled up. I'm not sure about elliptic curve. That was over 20 years ago: https://research.ibm.com/blog/factor-15-shors-algorithm I wonder how possible it is that IBM could have already gone further and are already cracking modern crypto in secret, e.g. funded by the NSA. Is that a crazy conspiracy idea, or actually a possibility?

> Is that a crazy conspiracy idea, or actually a possibility?

I am investing in IBM under the assumption that this is an actual possibility. Their public QC roadmap actually looks like a realistic journey now.

I strongly believe that the NSA, et. al. currently have access to a very powerful quantum computer - likely constructed by IBM under contract.

The game theory around this is such that it is impossible for me to accept that there are zero secret quantum computers in existence by now. There is too much to lose by not playing that game as hard as you can.

Re: Quantum Resistance and the Signal Protocol

#5
Actively resisting future attackers and hardware is an incredibly forward-thinking thing to do, bravo. How long into the future is an achievable and desirable duration for encryption (barring any rapid, unforeseen paradigm shift)? If ten years is acceptable for declassification of standard documents in the US, is this a reasonable target for day to day signal chats?

Re: Quantum Resistance and the Signal Protocol

#6
Given that Signal's main innovation (compared to traditional end to end encryption) was to safeguard its users against future compromises via the ratchet protocol, this actually seems like a logical move for them to make.

Re: Quantum Resistance and the Signal Protocol

#7

Super cool. If current quantum computers were scaled up to more qubits, could they break modern crypto? Or would we need both more qubits and a new quantum computer architecture?

> If current quantum computers were scaled up to more qubits

That depends on what you mean by "scaled up". There is a concept of "Quantum Volume" that exists, which basically means the depth of the longest qubit circuit you can pull off.

https://en.wikipedia.org/wiki/Quantum_volume

'Simply' (it's never simple ;) ) adding qubits to a machine does not necessarily increase its Quantum Volume. Decreasing the noise typically will.

However, there is a threshold at which point you can scale up mostly indefinitely. This is what the whole Quantum Error Correction is all about.

https://en.wikipedia.org/wiki/Quantum_error_correction

There is a paper

https://arxiv.org/abs/1905.09749

That goes into a clear discussion of how to build a quantum computer and the associated thresholds that would allow you to do so. There is a minimum number of qubits needed (that work perfectly), but the paper analyzes how many qubits you'd need under realistic assumptions about how many noisy qubits you'd need to get error correcting qubits at the needed reliability.

Re: Quantum Resistance and the Signal Protocol

#8
post #4
post #3

Earlier quoted context omitted.

15 was factorised on a 7 qbit computer by IBM, so yes, they could break RSA if scaled up. I'm not sure about elliptic curve. That was over 20 years ago: https://research.ibm.com/blog/factor-15-shors-algorithm I wonder how possible it is that IBM could have already gone further and are already cracking modern crypto in secret, e.g. funded by the NSA. Is that a crazy conspiracy idea, or actually a possibility?

> Is that a crazy conspiracy idea, or actually a possibility? I am investing in IBM under the assumption that this is an actual possibility. Their public QC roadmap actually looks like a realistic journey now. I strongly believe that the NSA, et. al. currently have access to a very powerful quantum computer - likely constructed by IBM under contract. The game theory around this is such that it is impossible for me to…

Speaking as a researcher in quantum computing (albiet completely on the theory side, with no practical knowledge of experiments). It seems that actually making a quantum computer which is useful (i.e. has error rate below the threshold you need for error correction to work) is incredibly difficult. I wouldn't be surprised if various secret agencies (specifically in the USA and China) have tried, but I would be quite surprised if they had succeded.

(I deleted my previous edit because I had misread part of what you wrote.)

Re: Quantum Resistance and the Signal Protocol

#10

Actively resisting future attackers and hardware is an incredibly forward-thinking thing to do, bravo. How long into the future is an achievable and desirable duration for encryption (barring any rapid, unforeseen paradigm shift)? If ten years is acceptable for declassification of standard documents in the US, is this a reasonable target for day to day signal chats?

Maybe we need a statue of limitations for encrypted data to help with future proofing/make the collection useless in a court of law? If you go to lengths to encrypt your data, there should be some current and future expectation of privacy around it, even if someone can decrypt it.
Post reply on HN