3 ms·
I think progress against ECC happens first. Because quantum computers exist. I'm not sure how large a problem they can work on yet. ECC is used with smaller bi
by asd999101 10y ago
I think progress against ECC happens first. Because quantum computers exist. I'm not sure how large a problem they can work on yet.
ECC is used with smaller bit lengths which makes it easier to get a sufficient quantum computer.
Of course I may have a fundamental misunderstanding here, and if so, I'd love to be enlightened.
- tptacek 10y agoQuantum computing confuses every thread about RSA and ECC. Shor threatens RSA and ECC. Neither RSA nor ECC are considered post-quantum schemes. If quantum computing is really your threat model, you want to be doing what Google did: run both a pre-quantum and a post-quantum key exchange and mix the results with a KDF. Which post-quantum approach you choose, I don't care. (I'm a quantum computing skeptic). What you do not want to do is build a cryptosystem using solely a post-quantum key exchange algorithm, or, even worse, try to build a cryptosystem without any asymmetric key exchange at all. In both cases, implementation errors --- some of which, in the latter case, are probably inevitable --- will doom your system immediately.