5 ms·
We will be able to crack today’s encryption algorithms in the future because we’ll find flaws in them. In other words, one day brute force won’t be necessary!
by galeaspablo 3y ago
We will be able to crack today’s encryption algorithms in the future because we’ll find flaws in them. In other words, one day brute force won’t be necessary!
Have a look at this post, which illustrates this reality being true for hash functions (where similar principles as symmetric and asymmetric encryption apply). https://valerieaurora.org/hash.html https://valerieaurora.org/hash.html
Notice Valerie specifically calls out, “Long semi-mathematical posts comparing the complexity of the attack to the number of protons in the universe”.
- GTP 3y ago> illustrates this reality being true for hash functions (where similar principles as symmetric and asymmetric encryption apply) I think you're making a bit of confusion. hash functions are part of symmetric key cryptography, while asymmetric cryptography is public key cryptography that is very different from hash functions.
- galeaspablo 3y agoNo. Hash functions can be used outside of symmetric encryption. Which is the wording I used. In any case, the overall point remains. Short of the one time pad you can’t build a provably flawless scheme.
- GTP 3y agoThey can be used outside symmetric encryption, e.g. in signature schemes, but the hashing primitives are part of symmetric cryptography.
- galeaspablo 3y agoAgain, I didn’t say symmetric cryptography :)
- GTP 3y agoYou talked about symmetric encryption.
- deleted 3y ago[deleted]
- segfaultbuserr 3y ago> We will be able to crack today’s encryption algorithms in the future because we’ll find flaws in them. Big if. We already knew how to design good and strong symmetric ciphers way back in the 1970s. One of the standard blocking blocks of modern symmetric cipher is called the Feistel network, which was used to create DES. Despite that it's the first widely used encryption standard, even today there's essentially no known flaw in its basic design. It was broken only because the key was artificially weakened to 56 bits. In the 1980s, cryptographers already knew 128 bit really should be the minimum security standard in spite of what NSA officially claimed. In the 1990s, when faster computers meant more overhead was acceptable, people agreed that symmetric ciphers should have an extra 256-bit option to protect them from any possible future breakthrough. There are only two possible ways to break them, perhaps people will eventually find a flaw in Feistel network ciphers to enable classical attacks against all security levels, but it would require a groundbreaking mathematical breakthrough unimaginable today, so it's possible but unlikely. Another route is quantum computing. If it's possible to build a large quantum computer, all 128-bit ciphers will eventually be brute-forced by Glover's algorithm. On the other hand, 256-bit ciphers will still be immune (and people already put this defense in place long before post-quantum cryptography became a serious research topic). Thus, if you want a future archeologist from the 23rd century to decrypt your data, only use 128-bit symmetric ciphers.
- galeaspablo 3y agoPlacing no time constraints, my gut tells me it’s almost inevitable those breakthroughs will eventually come. Either in mathematics or quantum computing. Or both. Namely I’d ask when not if. My opinion is that short of the one time pad, we won’t come up with provably unbreakable schemes.
- segfaultbuserr 3y ago> Namely I’d ask when not if. The big assumption of cryptography is that, there exists some problems that are not provably unsolvable but difficult enough for almost any practical purposes. To engineers, no assumption can be more reasonable than that. Given unlimited time, it's a provable fact that any (brand new) processor with asynchronous input signal will malfunction due to metastability in digital circuits, it's also a provable fact that metastability is a fundamental flaw in all digital electronics - but computers still work because the MTBF can be made as large as necessary, longer than the lifetime of the Solar system if you really want to. So the only problem here is, how long is the MTBF of today's building blocks of symmetric ciphers? If it's on the scale of 100 years or so, sure, everything is breakable if you're patient. If it's on the scale of 1000 years, well, breaking it is "only" a matter of time. But if it's on the scale of 10000 years, I don't believe it's relevant to the human civilization (as we know it) anymore - your standard may vary. The problem is that computerized cryptography is a young subject, the best data we have so far is symmetric ciphers tend to be more secure than asymmetric ones. We know that Feistel networks have an excellent safety record and remain unbroken after 50 years. We also know that we can break almost all widely used asymmetric ciphers today with large quantum computers if we can build one, but we can't do the same to symmetric ones - even the ancient DES is unbreakable if it's redesigned to use 256-bit keys. So while nobody knows for sure, but most rational agents will certainly assign higher and higher confidence every year - until a breakthrough occurs. > My opinion is that short of the one time pad, we won’t come up with provably unbreakable schemes. Many mathematicians and some physicists may prefer a higher standard of security than "lowly" practical engineers. This is the main motivation behind quantum cryptography - rather than placing security on empirical observations, its slogan is that the security is placed on the laws of physics. Many have pointed that the this slogan is misleading: any practical form of quantum cryptography must exist in the engineering sense, and there will certainly be some forms of security flaws such as sensor imperfection or at least side channels... That being said, I certainly understand why it looks so attractive to many people if you're the kind of person who really worry about provability.