2 ms·
The paper discusses the quantum case: > However, it will require major advances in physics and engineering before quantum computing can scale significantly. Wh
by sdevlin 11y ago
The paper discusses the quantum case:
> However, it will require major advances in physics and engineering before quantum computing can scale significantly. When that happens, of course P-256 and P-384 will fall first. But, as the head of cybersecurity research at a major corporation put it, “after that it’s just a matter of money” before RSA-3072 is broken. At the point when P-384 is broken it would be unwise to use either ECC or RSA. It is not likely that the gap between quantum cryptanalysis of a 384-bit key and a 3072-bit key will be great enough to serve as a basis for a cryptographic strategy.
- vox_mollis 11y agoIs it really just a matter of money, though? My understanding is that the coherence window (timewise) decreases exponentially as you add more qubits. "Just a matter of money" implies linear scalability.