Live data from Hacker News

Quantum Algorithms for Lattice Problems

eprint.iacr.org

41–50 of 127 posts

Re: Quantum Algorithms for Lattice Problems

#41
post #38
post #19

I work on homomorphic encryption, and there are some rumors circulating that, if this checks out, it will break some of the leading FHE schemes like BFV, where the moduli used are quite large (in the hundreds of bits or even over a thousand bits).

… only if scalable quantum computers exist.

If scalable quantum computers do not exist, we do not need PQC.

Re: Quantum Algorithms for Lattice Problems

#42
post #37
post #36

Earlier quoted context omitted.

I'm sure they have thought more about how to prioritize security threats than an anonymous internet commenter.

The fact that you work at Google and did not care to ask what are the extensions just confirms to me nobody there cares.

I’ll bite; what are some of these extensions?

Re: Quantum Algorithms for Lattice Problems

#43
post #37

Earlier quoted context omitted.

The fact that you work at Google and did not care to ask what are the extensions just confirms to me nobody there cares.

I’ll bite; what are some of these extensions?

HBO watch party. If relays a fake costumer support chat if you visit a site like united airlines, that puts you in touch with scammers (probably does other malwary stuff too). A friend almost got scammed by this, they reported it to someone they know who works at Google and a couple months later the extension is still up.

Tbh that is the only actual example I know, but after poking around a bit, ppl who actually know about security say that's the state of things with these extension and app store apps, and nobody at google seems to think fixing it is their job.

Funny thing is, they were asking this google friend for advice about getting rid of the malicious chat before they realized it was this chrome extension. The advice the google employee gave was to format the computer (it wouldn't have fixed it because once they logged into chrome again all the extensions would come back).

Hard sell that people running this clown show could be doing PQC in any meaningful sense (other than publishing papers. The papers are fine).

Re: Quantum Algorithms for Lattice Problems

#47
Some post-quantum signatures like CRYSTALS-Dilithium are based on lattices. Makes me think that quantum key distribution (what I've been working on for the past 6 months) has a chance to actually become useful instead of being only of interest to academics and to a few companies that sell overpriced solutions to paranoids.

Re: Quantum Algorithms for Lattice Problems

#48

Some post-quantum signatures like CRYSTALS-Dilithium are based on lattices. Makes me think that quantum key distribution (what I've been working on for the past 6 months) has a chance to actually become useful instead of being only of interest to academics and to a few companies that sell overpriced solutions to paranoids.

Code based systems are still in, and classic McEliece could be extended to ~50 MiB for a keypair and still be way more practical than QKD. Just run the max current classic McEliece spec hybrid post quantum with X448.

Re: Quantum Algorithms for Lattice Problems

#49
post #38

Earlier quoted context omitted.

… only if scalable quantum computers exist.

If scalable quantum computers do not exist, we do not need PQC.

We need PQC about 20 years before practical, scalable gate quantum computers appear (if they can do all the right gates).

I think that this will be signaled when someone factors a 32 bit integer on one. At that point I guess it'll be about 20 years before someone can factor a 2048 bit integer, and I'll get twitchy about what I am sending over the wire with PKI. My feeling is that all my secrets from 20 years ago are irrelevant to life now so I feel 20 years of warning is quite sufficient.

Re: Quantum Algorithms for Lattice Problems

#50
post #48

Some post-quantum signatures like CRYSTALS-Dilithium are based on lattices. Makes me think that quantum key distribution (what I've been working on for the past 6 months) has a chance to actually become useful instead of being only of interest to academics and to a few companies that sell overpriced solutions to paranoids.

Code based systems are still in, and classic McEliece could be extended to ~50 MiB for a keypair and still be way more practical than QKD. Just run the max current classic McEliece spec hybrid post quantum with X448.

NSA is that you?
Post reply on HN