3 ms·
What's the limiting factor of homomorphic encryption? Is it that it's provable? Is it the compute overhead? Is it too magical for governance?
by ericalexander0 4y ago
What's the limiting factor of homomorphic encryption? Is it that it's provable? Is it the compute overhead? Is it too magical for governance?
- deleted 4y ago[deleted]
- lucgommans 4y agoRight now? For broad applicability it is the computational overhead. There are some applications that are doable now, such as reading data anonymously from a small-ish dataset (or a low-volume service where you can afford to wait a minute for an answer, or using really expensive hosting). An example of that was a Wikipedia server that someone made which would serve you pages without the server knowing which page your client was actually after (https://news.ycombinator.com/item?id=31668814 https://news.ycombinator.com/item?id=31668814 4 months ago, 119 comments). It's still not really efficient; you can't simply swap out the real Wikipedia for this system and expect it to simply work. > the server [needs] to scan through the entire encrypted dataset [for every request] (this is unavoidable, otherwise its I/O patterns would leak information) Imagine Wikipedia servers needs to read every byte written on Wikipedia and operate on it before being able to formulate an answer to a random pageload. Additionally, if I remember correctly, things like autocomplete worked by just downloading the entire list of articles and doing that locally. It's all not impossible, but not a drop-in solution. And then when you have a situation where you can practically apply it, there aren't popular/trusted/already-audited software packages out there for you to just use with confidence.