4 ms·
iirc; Quantum computers do not make symmetric encryption weaker. They make asymmetric encryption relying on factoring primes weaker.
by 0xCMP 5y ago
iirc; Quantum computers do not make symmetric encryption weaker. They make asymmetric encryption relying on factoring primes weaker.
- jonathanstrange 5y agoThey basically half the symmetric keyspace (but there could be better, more specialized quantum algorithms), and the next smallest keysize is usually 128 bit. So that's what most foreign encryption will use after this new law. A brute-force search of a 64 bit keyspace is no problem for a nation state like China.
- adgjlsfhk1 5y agoThey effectively half the size of symmetric encryption keys (via Grover). They aren't considered as "breaking" them because doubling key size is pretty cheap. 256 bit symmetric is generally considered relatively safe vs quantum since a 128 bit key is still quite strong. That said, transitioning to 512 bits wouldn't be bad, since that would pretty much completely nullify quantum assisted breaks.
- zrm 5y agoDoes anyone know how this interacts with the AES-256 break from a while back? Something to do with, they didn't use enough rounds so the security is really only about equivalent to AES-128. And then nobody cared because having the security of AES-128 isn't a practical break. Unless we get quantum computers. Then what happens with AES-256?
- ncmncm 5y agoAs I recall it was about the key schedule. But, same outcome. Some people, idiotically, use 256 bit AES anyway, because it reassures less literate customers. Sort of like the patdowns at airports: security theater.
- hxtk 5y agoI haven't heard anything about not using enough rounds, so it's possible that my information is just out of date. My understanding is that AES-128 was chosen to be resistant against classical attacks, and AES-256 was chosen to achieve the same level of security as AES-128 against attacks that incorporate quantum computers and Grover's algorithm.
- api 5y ago128-bit is still absolutely impractical to brute force now or in the foreseeable future. Even 96-bit is questionable, though likely achievable after some time by someone with a lot of money who is able to create a huge farm full of ASICs for the task. A QC large and stable enough to run Grover's Algorithm would be a problem for symmetric keys and hashes smaller than about 192 bits. Most cryptographers recommend 256-bit or larger for a good margin of safety. Asymmetric crypto is more complex story.
- cobookman 5y agoFurthermore, why brute-force crack crypto when you can inject code using the log4j exploit which transmits the private keys. Sure log4j might have been recently patched, but it's not unrealistic to think that a nation-state has access to similar exploits.
- api 5y agoYes, a thousand times. The vast majority of compromises happen because of software exploits or social engineering. This is not an argument for using shitty cryptography, but it is IMHO an argument for being more afraid of the implementation and the human beings using it than the crypto.