Live data from Hacker News

Will you heed my warnings now?

scottaaronson.blog

1–10 of 106 posts

Re: Will you heed my warnings now?

#2
Ok, maybe I'm missing something here.

So we know that quantum computers hold a real risk of being able to break a lot of encryption. We also know that changing cyphers is hard (because reasons)

But what I don't see is what I can practically do now, as either someone who is a CTO/Big Cheese™ or a lowly engineer?

Re: Will you heed my warnings now?

#4
Aaronson know his stuff but I am not sure he hasn’t considered the fact that, in this current hype cycle, the quantum researchers breathlessly reporting to him on a breakthrough just around the corner are just lying to him and themselves.

I have been hearing about one more technical hurdle to solve before quantum algorithms become feasible since before I graduated. That was in 1996.

Re: Will you heed my warnings now?

#5
"The Shor of Damocles" - what a metaphor.

I thought it was a typo at first but wikipedia explained:

The Sword of Damocles is an ancient Greek moral anecdote, an allusion to the imminent and ever-present peril faced by those in positions of power.

Shor's algorithm is a quantum algorithm for finding the prime factors of an integer

Re: Will you heed my warnings now?

#6

Aaronson know his stuff but I am not sure he hasn’t considered the fact that, in this current hype cycle, the quantum researchers breathlessly reporting to him on a breakthrough just around the corner are just lying to him and themselves. I have been hearing about one more technical hurdle to solve before quantum algorithms become feasible since before I graduated. That was in 1996.

quantum computers will flourish the same day that fusion does.

Re: Will you heed my warnings now?

#7

Ok, maybe I'm missing something here. So we know that quantum computers hold a real risk of being able to break a lot of encryption. We also know that changing cyphers is hard (because reasons) But what I don't see is what I can practically do now, as either someone who is a CTO/Big Cheese™ or a lowly engineer?

This is what Cloudflare[1] is doing.

[1] https://blog.cloudflare.com/post-quantum-roadmap/

Re: Will you heed my warnings now?

#8

Ok, maybe I'm missing something here. So we know that quantum computers hold a real risk of being able to break a lot of encryption. We also know that changing cyphers is hard (because reasons) But what I don't see is what I can practically do now, as either someone who is a CTO/Big Cheese™ or a lowly engineer?

I think lobby for saner defaults (tip of the hat to Steve Gibson's term "the tyranny of the default"), configuring one's GPG config to mark certain cyphers as insecure (to prevent downgrade attacks)... and have one's (chief) information security officer write those things down as policy and maybe have a yearly onboarding workshop teaching people why it's important.

Re: Will you heed my warnings now?

#9

Ok, maybe I'm missing something here. So we know that quantum computers hold a real risk of being able to break a lot of encryption. We also know that changing cyphers is hard (because reasons) But what I don't see is what I can practically do now, as either someone who is a CTO/Big Cheese™ or a lowly engineer?

If you're a CTO, have a post quantum strategy: know what crypto you use and where it is, plan to migrate to post quantum secure ciphers over the next decade or so, or sooner if possible. If you're a lowly engineer, not very much unless you're specifically selecting technologies with crypto. In which case crypto agility (being able to switch out existing crypto when needed) is a good property to look for.
Post reply on HN