Live data from Hacker News

NIST announces first PQC algoritms to be standardized

groups.google.com

131–132 of 132 posts

Re: NIST announces first PQC algoritms to be standardized

#131
post #105

Earlier quoted context omitted.

Why would a croudsoursing site know that? This is the kind of question where 1 expert will fare better than the average of 90% of the people.

Sure. If that 1 expert bothered to post a falsifiable prediction like “x% likely this’ll happen by year y”, the rest of us could read their argument and update our predictions. Unfortunately that’s pretty uncommon so everyone has to go by base rates (crypto algorithms seem to last x years historically) and vague guesses (quantum computer capabilities seem to be doubling every x years so I dunno maybe enough qbits by…

> quantum computer capabilities seem to be doubling every x years so I dunno maybe enough qbits by 2050

Ok, let's get a try from a mildly informed person, that is also probably better than the 90% average...

The number of qbits seems to be growing linearly, at about 7 qbits every 2 years. Extending that trend says that none of us will ever see a quantum computer break 256-bits ECC.

But I really doubt the trend will hold. Quantum computing seems prone to surprise gains, and those are unpredictable by their nature.

About this:

> crypto algorithms seem to last x years historically

I don't think we have enough data to decide on an average, but the distribution does surely look fat-tailed, so any statistic summary you make from it will be useless.

If history tells anything, it is that algorithms that have minor attacks will be broken quickly, and algorithms that don't have minor attacks will survive for very long.

Re: NIST announces first PQC algoritms to be standardized

#132
post #100

Earlier quoted context omitted.

Bernstein being "involved in never-ending drama" is the reason it's legal to export strong cryptography from the US today and the reason much of this PQC work got done at all. He's clearly a person who often fights in cases where almost everyone else surrendered instead, which is presumably what you mean by "the problem is him," but I don't see why you describe it as a "problem". His inclination to tell hard truths,…

It doesn't seem reasonable to say that Bernstein is the reason much of this PQC work got done at all. He was one of the earliest PQC popularizers and probably coined the term. But asserting that he enabled everyone else's work is a little like saying that the person who coined "misuse-resistant authenticated encryption" enabled all the different misuse-resistant schemes; the underlying issue was plainly evident, and…

No post body was provided.
Post reply on HN