Live data from Hacker News

Will you heed my warnings now?

scottaaronson.blog

91–100 of 106 posts

Re: Will you heed my warnings now?

#91
post #83
post #35

Earlier quoted context omitted.

I have another comment[1] on this post with more practical instructions, but the `ssh-keygen` is a good question. The cryptography community is still focused on migrating encryption/key exchange algorithms, for fear of data being captured today and decrypted in the future. So OpenSSH 10.0+ already enables ML-KEM by default. SSH keys, on the other hand, are authentication and would require an online Quantum Computer t…

Late edit: PQC migration also includes sometimes changing configuration files/library invocations to enable the new algorithms, and ensuring that your processes still work during the migration, where you might have both pure classical and PQC/hybrid at the same time.

I just went through some ~/.ssh/config files and realized that, along side the entries for ancient systems that need to be forced to use undesirable ciphers and Kexies, I also had some entries for current systems that stipulated only the "good" values, to "protect me from hypothetical future downgrade attacks". Which means that I wasn't getting the latest PQ Kex, because my entries hadn't been updated since ssh 9.x.

Maybe the best practice here is to have one or more Boppers on your team who send out periodic notifications to update not just algos in libraries but, more importantly, make sure those updates are reflected in the damned configs.

We also really need a cultural shift where it becomes expected that, for any given app, we have something like:

$ ssh --best user@host

which does that for us. Because this is a failure mode that shouldn't even be possible for most users and cases.

Re: Will you heed my warnings now?

#92
post #79

Earlier quoted context omitted.

This is what bugs me about both quantum computers and commercial fusion power. There's so much talk about how it's just inevitable and will happen soonish, but a lot of the evidence suggests, in some cases strongly, that it might not ever be possible. I find it weird how bleeding edge research, at the very edges of both physics and engineering, is treated as though it's a market development about to drop. Possibly a…

There's no strong evidence of impossibility. For quantum computers to be impossible at scale we need new unknown physics. Fusion requires lots of engineering. And before those engineering efforts would show practical impossibility or impracticality, there can't be strong evidence.

By not ever be possible, I mean in a practical sense, including e.g. the economics of it, as well as reliability, checkability, etc.

Jassby's article about fusion (https://thebulletin.org/2017/04/fusion-reactors-not-what-the...) describes several well-understood issues that could prevent commercial fusion power from ever being practically possible.

For quantum computers, the situation is quite similar. Michel Dyakonov and several others have laid out the situation well.

At least we don't have anyone claiming that interstellar travel is just 10 years away, yet. Probably because it's more difficult to make an economic case for it. But the issues are quite similar. In principle, in terms of physics, nothing prevents an interstellar journey. In practice, it just isn't going to happen.

Re: Will you heed my warnings now?

#93
post #83

Earlier quoted context omitted.

Late edit: PQC migration also includes sometimes changing configuration files/library invocations to enable the new algorithms, and ensuring that your processes still work during the migration, where you might have both pure classical and PQC/hybrid at the same time.

I just went through some ~/.ssh/config files and realized that, along side the entries for ancient systems that need to be forced to use undesirable ciphers and Kexies, I also had some entries for current systems that stipulated only the "good" values, to "protect me from hypothetical future downgrade attacks". Which means that I wasn't getting the latest PQ Kex, because my entries hadn't been updated since ssh 9.x.…

There are also scanners that you can deploy to identify vulnerable servers, like https://sshcheck.com/ . Clients are harder to check, but you can always observe your logs.

Re: Will you heed my warnings now?

#94

Earlier quoted context omitted.

I am reminded of a certain comedian who lost his job hosting an awards ceremony because he had once said something on stage that people didn't like.... ...8 years previously.[1] Long, long ago in a datacenter far away, breaking 3DES used to be the province of expensive bespoke hardware owned by only the elite nation states. Today it is so trivial that the gpu in your second hand laptop can do it "at scale". 5 years a…

As far as I know, cracking 3DES is still not trivial, and requires a very large number of operations and/or a very large amount of data. But can just about be done in some situations. If you have any link to trivially cracking it on your second hand laptop and doing it at scale, would be very interested.

Mea culpa! I must have had a brain fart and added the 3 in there. My sincere apologies!

Of course I can't find the link to whatever I read that discussed gpu accelerated des cracking now.

Re: Will you heed my warnings now?

#95

Earlier quoted context omitted.

There is evidence of the opposite: graph singular isogeny mumbo jumbo algorithm was proven to be easily broken on an ordinary computer. Hybrid encryption is as simple as running one encryption and then the other. Problem is mostly that post quantum keys are large.

Am I missing something fundamental here? If Algo-A and Algo-B both rely on "factoring big numbers is hard!" then once the Quantumpocalypse occurs, breaking Algo-B(Algo-A(plaintext)) is no harder than asking ChatGPT 99.5 to add an extra step in your vibe coded cracking engine's frontend, such that it now does B_breaker > plaintext.lol or whatever the equivalent is for the fashionable language of the that future day.

You have to break both algorithms. One of them is quantum-safe if it's secure, but it could also be completely insecure like supersingular isogeny was.

Re: Will you heed my warnings now?

#96
post #46

Sounding the alarm while presenting no data or science, as a member of the National academy of sciences, is doing a disservice to the position, to science, to the self. Show the data, the charts, let people decide for themselves.

> Sounding the alarm while presenting no data or science One needs to read OP's blog post in the context of his other posts from the last couple months (many of which have been discussed here on HN in one way or another), where he does discuss the science.

Demanding information one won't read or understand.

Re: Will you heed my warnings now?

#97

Earlier quoted context omitted.

There is evidence of the opposite: graph singular isogeny mumbo jumbo algorithm was proven to be easily broken on an ordinary computer. Hybrid encryption is as simple as running one encryption and then the other. Problem is mostly that post quantum keys are large.

Am I missing something fundamental here? If Algo-A and Algo-B both rely on "factoring big numbers is hard!" then once the Quantumpocalypse occurs, breaking Algo-B(Algo-A(plaintext)) is no harder than asking ChatGPT 99.5 to add an extra step in your vibe coded cracking engine's frontend, such that it now does B_breaker > plaintext.lol or whatever the equivalent is for the fashionable language of the that future day.

He was saying hybrid encryption as in use both a well established classical "factoring big numbers is hard!" algo and also a fancy new post quantum cryptography algo. That way if it turns out the fancy new algo can be broken by non-quantum computers at least you aren't in a worse position than you were in before because you are still protected by the well established classical algo.

Re: Will you heed my warnings now?

#99

"The Shor of Damocles" - what a metaphor. I thought it was a typo at first but wikipedia explained: The Sword of Damocles is an ancient Greek moral anecdote, an allusion to the imminent and ever-present peril faced by those in positions of power. Shor's algorithm is a quantum algorithm for finding the prime factors of an integer

It applies to those subject to a capricious arbitrary power as well. Like living under a shitty parent, the same threat(s) they settle on to control them becomes the dangling Sword till its forecefully removed and they are neutered

Re: Will you heed my warnings now?

#100

Earlier quoted context omitted.

As far as I know, cracking 3DES is still not trivial, and requires a very large number of operations and/or a very large amount of data. But can just about be done in some situations. If you have any link to trivially cracking it on your second hand laptop and doing it at scale, would be very interested.

Mea culpa! I must have had a brain fart and added the 3 in there. My sincere apologies! Of course I can't find the link to whatever I read that discussed gpu accelerated des cracking now.

Phew, thought I'd missed an important development there! The 3 makes the difference :)
Post reply on HN