10 ms·
I think QKD encryption will be essential in the future for securing our data. Data leaks as seen with big tech companies like Google, Facebook, etc. are a massi
by cprasai 8y ago
I think QKD encryption will be essential in the future for securing our data. Data leaks as seen with big tech companies like Google, Facebook, etc. are a massive problem and will only continue to become worse as big data grows. QKD could nip the problem in the bud (may require large infrastructure investment) and save us all a lot of privacy headaches as we move towards a data-fueled future.
- ardy42 8y ago> Data leaks as seen with big tech companies like Google, Facebook, etc. are a massive problem and will only continue to become worse as big data grows. QKD could nip the problem in the bud (may require large infrastructure investment) and save us all a lot of privacy headaches as we move towards a data-fueled future. Can you go into more detail? I'm inclined to disagree because most "data leaks" rarely seem to be about cracked encryption, but rather software bugs, poor security practices, or just plain giving the wrong people access.
- est 8y agonone of the data breach happened because of the key leak. Key exchange is the least of worries. Also a QKD receiver is expensive and you have to have connect to a satellite by powerful lasers. If you connect to a ground station then its no different from regular Internet.
- est31 8y agoYeah, we are using the current crypto algorithms as if they would continue to be strong in 20,30,40 years. So many secrets encrypted "only" with current-industry-grade crypto. This is better than not encrypting at all but overall it's foolish to assume that cracking capabilities won't improve. "Perfect forward secrecy" only helps against compromised long-term keys, but it doesn't help against entities who store vast amounts of encrypted internet traffic in facilities in, say Bluffdale. And then once these algorithms can be cracked they will have a gigantic valuable trove of data. The 2010s have seen major players adopting encryption that is proof against current attackers, with one event being the launch of encrypted.google.com in 2010 [0]. Hopefully in the 2020s we'll see major players adopting algorithms that are proof against future attackers. It isn't guaranteed that we can ever build quantum computers that can crack current industry grade encryption nor is it guaranteed that computing capabilities as well as theoretical advances will improve enough, but we are betting too much onto that we can't ever. E.g. there are proposals in Germany to upload health data to the cloud and even if it is end-to-end encrypted, the data, once decrypted, stays highly valuable throughout the life of the patient, see the recent 35c3 talk on this if you know German [2]. Thankfully, there is an open NIST competition on post-quantum crypto [3] [4] (added a second link because the first is currently dead), but this isn't enough, as there may be theoretical attacks on them as well. Quantum based encryption is quite valuable here because it gives a physical guarantee but it's also really tough to roll out and probably won't be deployed in consumer devices for a while. [0]: https://googleblog.blogspot.com/2010/05/search-more-securely-with-encrypted.html https://googleblog.blogspot.com/2010/05/search-more-securely... [2]: https://media.ccc.de/v/35c3-9992-all_your_gesundheitsakten_are_belong_to_us https://media.ccc.de/v/35c3-9992-all_your_gesundheitsakten_a... [3]: https://csrc.nist.gov/Projects/Post-Quantum-Cryptography https://csrc.nist.gov/Projects/Post-Quantum-Cryptography [4]: http://web.archive.org/web/20181225214652/https://csrc.nist.gov/Projects/Post-Quantum-Cryptography http://web.archive.org/web/20181225214652/https://csrc.nist....