3 ms·
I wonder if and when we have working quantum computers bitcoin and crypto will be able to adapt or die. I mean, breaking secret keys with quantum should be easy
by kwelstr 9y ago
I wonder if and when we have working quantum computers bitcoin and crypto will be able to adapt or die. I mean, breaking secret keys with quantum should be easy.
- danenania 9y agoExisting crypto would be broken, but quantum computation also seems provide much stronger encryption possibilities by leveraging entanglement states. [1] 1: https://en.m.wikipedia.org/wiki/Quantum_cryptography https://en.m.wikipedia.org/wiki/Quantum_cryptography
- dsacco 9y agoNot all existing crypto would be broken. Symmetric encryption algorithms like AES will be fine. Asymmetric encryption (public-key) algorithms like RSA/DSA will be in trouble due to Shor's algorithm, but other public-key systems will be fine. Hash functions like SHA-2 and SHA-3 will be mostly fine, because Grover's algorithm is at best sub-exponential, not quadratic. Also, quantum cryptography mostly provides superior key establishment/management capabilities, not superior confidentiality guarantees. It's a misnomer to state that we can achieve "stronger encryption" by "leveraging entanglement states"; most of quantum computing is useful for cryptanalytic attacks right now, not cryptographic construction.
- danenania 9y agoThanks, that's very enlightening!
- zamalek 9y agoMerkle–Damgård algorithms are thought to be safe. I'm not sure about Keccak.
- dsacco 9y agoKeccak (SHA-3) is currently thought to be safe. The current state of the art would be Brassard-Hoyer-Tapp[1], but SHA3-512 should be secure against that. It's basically a birthday attack that generates a giant table, then uses Grover's algorithm to find a collision. _______ 1. https://link.springer.com/chapter/10.1007%2FBFb0054319 https://link.springer.com/chapter/10.1007%2FBFb0054319
- drcode 9y agoThe next version of ethereum includes a "bring your own cryptography algo" feature that lets you substitute your preferred algorithm for the default choice. This gives it safeguards against the outside risk that a direct attack against core cryptography ever becomes feasible.