5 ms·
No encryption is intended to be permanent. That's an all-but-impossible feat. Encryption exists to protect data for a meaningful length of time. A threat model
by Fej 8y ago
No encryption is intended to be permanent. That's an all-but-impossible feat. Encryption exists to protect data for a meaningful length of time. A threat model extending far into the future is naïve.
The Caesar cipher worked until it didn't, the Enigma was secure until it was broken, and DES was good until it wasn't.
- est31 8y agoSure, that's the what they were intended for. But it's not being used that way, it's used as if the encryption were permanent.
- krastanov 8y agoThe Caesar cipher was based on obfuscation, not on computational complexity. It is not unreasonable to expect humanity to soon have enough knowledge to make unbreakable cyphers. We might very well already have such symmetric cyphers. If you count one time pads then we definitely do.
- est31 8y agoShannon's theorem about perfect secrecy says that it is only attainable by ciphers that have similar key lengths to OTP. We can get a lot smarter but that theorem will stay.
- krastanov 8y agoI was left with the impression that if "good" random number generators exist, then this is not a problem: you use your small key as a seed to make the big key. And we do not have a reason yet to doubt the existence of such RNGs. Did I get this wrong? Edit: I think I was right, as the mathematical term "perfect secrecy" from the theorem is not particularly practical (lack of perfect secrecy does not imply the existence of a way to break the cypher). http://www.cs.miami.edu/home/burt/learning/Csc609.011/Perfect/ http://www.cs.miami.edu/home/burt/learning/Csc609.011/Perfec...
- gizmo686 8y agoWe have no particuarly good reason to believe in the exsitence of a good PRNG. Worse, we have no good reason to trust that any particular PRNG is good.
- admax88q 8y agoGood ol symmetric crypto is not easily broken by quantum computers. It is reasonable to think that we could or have already built a symmetric cipher that may never be broken.
- gizmo686 8y agoTheir key size is effectivly halfed. Not a big deal, but if quantom computers reach near parity with classical, we will need to increase our key sizes.
- gizmo686 8y agoPhysics gives us some tools to meaningfully talk about "unbreakable" without perfect secrecy. In particular, we can currently reason about "unbreakable on any classical computer operating in an ambiant temperature no less than the cosmic microwave background, and consuming no more energy than exists in the universe". Physics still has some backdoors (notably reversable computing which, as far as I am aware, has no fundamental limit), but the bigger problem is that complexity theory has not advanced to a point where we can make meaningfull use of this. (The most I have ever seen is computing the lowerbound on energy to enumerate all keys. ) This is probably a solvable problem, but is going to be harder than p vs np.
- pradn 8y agoI think the parent is trying to highlight an attack vector that most people are unaware of. Most people are happy to see the green lockbox and do not know that it's possible for their browsing habits to be cracked in 30 years when they run for congress.
- est31 8y agoYeah, that's the point that I wanted to make. Doubt that you want someone to reveal the private sexting images you sent thirty years ago before you even thought about wanting to run for governor or similar. Content like that still has value decades down the line, but it's only protected with encryption that might be considered offline-attackable at a certain point in time. This affects browsing habits as well as end-to-end stuff like Snapchat, Whatsapp, Signal, ...
- akvadrako 8y agoUnbreakable encryption is pretty easy. Just use a one-time pad.
- dwheeler 8y agoNo. Encryption with one-time pads is easy, except for safely sharing the key. Which means that for most situations they are completely impractical. Real-world encryption is a system problem, not just a math problem.