Man, the CBOM is such a pain. There is no standardised format yet (let alone efficient tools for crypto discovery), nobody knew what it was one year ago but now every client is asking ours anyway.
Tell me about it! We've got slightly under 10'000 distinct software assets we are trying to catalogue. There are now a handful of vendors claiming to be able to scan for crypto, but they all suck .
I'm not even there for my employer. I have compiled a list of ~20 different inventory/CBOM solutions and I cannot even fathom how to move to the next step other than picking a few vendors at random and ask them for a demo, but the public info I found was not convincing.
While I can assume these tools do a decent job at crypto asset discovery (a `grep -r "-----BEGIN RSA PRIVATE KEY-----"` is not the hardest product to design), I have no idea what to do for code scanning. CBOMkit and friends do not scan C code, which we actually need.
I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.
I'm logging into websites using unique passwords with 44 bits of entropy, which they feed into a hash algorithm that takes 200ms to hash each attempt, then entering a TOTP code or touching my Yubikey, and they check against my geoip history and fingerprint my browser and they want me to complete a captcha and they e-mail/SMS a one-time code to me and they send me an e-mail telling me there's a new login to my account…
The amount of time I spend per day waiting for my web browser to do about 10 redirects through Okta and touch a Yubikey is substantial.
> by 2050 when, my bet, there still won't be any remotely viable QCs I hate to be that guy, but I'm 52 now and I've been hearing about how Quantum Computing is going to revolutionise everything in the next two years, since I was in primary school and ZX81s were state-of-the-art. At least a couple of manufacturers offered a practical and afforable(-ish) transputer-based system in the 80s that you could have actually g…
Transputers have nothing to do with quantum computing. They're completely classical computers.
Yes, I know. I own some.
They were going to revolutionise absolutely everything to do with computing in just a couple of years, some 40 years ago.
I've been hearing the same thing about quantum computing for about as long.
I will take "Post Quantum Cryptography" seriously when I can buy a quantum microprocessor off the shelf.
Ironically, given that the primary use case for developing quantum computers is breaking classical encryption, switching en-masse to post-quantum schemes may very well ensure that developing a working quantum computer may never be economically viable to develop.
The history of diligence in properly utilising and applying security measures strongly suggests that QC will in fact provide positive utility even if viable PQC countermeasures are developed and deployed. From yesterday's posts: https://news.ycombinator.com/item?id=48983610 > (my comment on the Romanian land registry hacking thread).
I'm afraid I don't see how the linked comment demonstrates the positive utility of QC.
Ironically, given that the primary use case for developing quantum computers is breaking classical encryption, switching en-masse to post-quantum schemes may very well ensure that developing a working quantum computer may never be economically viable to develop.
A large part of the investments in developing quantum computing are for drug discovery, materials science, and logistics.
Certainly, we can imagine other use cases for quantum computers. But just because something could be useful doesn't mean it will be developed; the cost still needs to be surmountable.
A large part of the investments in developing quantum computing are for drug discovery, materials science, and logistics.
Certainly, we can imagine other use cases for quantum computers. But just because something could be useful doesn't mean it will be developed; the cost still needs to be surmountable.
Logistics companies are using hybrid QC now from D-Wave Systems. Quantum computing is currently in use in the real world. There's already physics simulations running on QC hardware beyond the capacities of classical computing, QuEra's Gemini is already doing materials science work now. It's very expensive, giant logistics companies and other industries with lots of capital and the need to do the special kinds of simulations these things are good at will be renting time on these things from specialized vendors who can run this kind of intensive hardware, something like time sharing on a supercomputer. Quantum-as-a-Service (QaaS) via platforms like Amazon Braket, Azure Quantum, or IBM Quantum Platform is already a thing. Big Pharma will be renting this stuff, Google currently plans to have QC for Pharma applications running c. 2028-2030. Lots of folks dealing with materials sciences and so on will be on projects where this will be affordable since not everything needs a massive CRQC to be useful.
A large part of the investments in developing quantum computing are for drug discovery, materials science, and logistics.
Certainly, we can imagine other use cases for quantum computers. But just because something could be useful doesn't mean it will be developed; the cost still needs to be surmountable.
That wasn't just a list of things they could besides breaking crypto. It was the list of the main reasons people are investing in trying to build them.
As you noted the problems they pose for cryptography can be addressed with PQC. Military/Defense/National Security invests in them for the cryptographic applications (and probably also for the logistics applications), but they are only about 1/3 of the investment.
The rest is for the doing better physics simulations and for logistics and financial applications. The physics simulations will be huge and drug development and materials science.
From TFA: "The policy reflects growing concern about Harvest Now, Decrypt Later (HNDL) attacks, in which adversaries intercept and store encrypted communications today with the intention of decrypting them once a cryptographically relevant quantum computer (CRQC) becomes available." Once it gets to be "later" where the harvest data is able to be decrypted, I guess will have decent enough LLMs to summarize all of that…
I mean we have decent enough LLMs and algorithms to classify it pretty easily now, much less the future. Just getting context information on who or what the data is narrows down a lot of what you want to look at.
I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.
> by 2050 when, my bet, there still won't be any remotely viable QCs I hate to be that guy, but I'm 52 now and I've been hearing about how Quantum Computing is going to revolutionise everything in the next two years, since I was in primary school and ZX81s were state-of-the-art. At least a couple of manufacturers offered a practical and afforable(-ish) transputer-based system in the 80s that you could have actually g…
Hey, I've been hearing about AI that could behave like a human all my life and, well, shit, we're almost there.
The thing is we have nearly no idea when an invention is going to occur. We are horrifically bad at predicting it.
Agreed. This looks from the outside like someone read a report, got unnecessarily spooked, and now the rest of the herd is following along. But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it. However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I do…
Would anyone downvoting care to explain? I'm genuinely interested in seeing anything that suggests there's either some secret breakthrough (completely plausible, but there's no evidence that I've seen hint of) making quantum computers actually useful, or an argument that they'll be usable by (say) 2050? Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just wh…
When you're a fully loaded freight train running at full speed you have to hit your brakes miles before the collapsed bridge. It's way easier to switch to another line that is intact when you have the opportunity instead of in a panic.