3 ms·
Quantum key distribution is completely unsuitable to replace asymmetric cryptography, even when ignoring the (enormous) technological difficulties. It fundament
by fsh 2y ago
Quantum key distribution is completely unsuitable to replace asymmetric cryptography, even when ignoring the (enormous) technological difficulties. It fundamentally cannot handle authentication, and requires a pre-shared key to prevent MITM-attacks, so one can replace it with any modern stream cipher (which are astronomically more econonical and don't require physical point-to-point connections). Even exchanging an SSD with a long key and using a one-time pad is far superior to QKD.
- HappyPanacea 2y agoCan't we sign the key with SPHINCS+ and be back to the same situation as with classical asymmetric cryptography?
- pclmulqdq 2y agoDon't knock sending around gigantic one-time pads on SSDs until you try it :) In all seriousness, QKD also has huge SNR problems over long range. QKD is really a layer 1 protocol that needs you to entangle qubits far away from each other, and that relies on having a very clean physical layer. You can sort of do it over short-range fiber right now with a known-to-be-direct connection, but any other medium is still off the table. Once you have done the QKD layer 1, put any protocol you want on top of it.