4 ms·
I don't think this is that helpful a framing of the situation. We don't know if or when a cryptographically relevant quantum computer (CRQC) will be developed,
by ekr____ 2y ago
I don't think this is that helpful a framing of the situation. We don't know if or when a cryptographically relevant quantum computer (CRQC) will be developed, but if it happens, it will be a very serious problem for most of the encryption we are currently using.
While it's true that as far as we know, symmetric encryption is likely safe from quantum computers (assuming the algorithm in question is safe from classical computers), in a huge fraction of cases the symmetric encryption keys were established using asymmetric encryption, which are vulnerable to quantum computers. But in this case it doesn't actually matter that the symmetric algorithm is secure, because once you have the key you can just decrypt directly without attacking that algorithm. In particular, this is the case for much of the encryption protecting your Web browsing and instant messaging traffic.
As noted in the article, there are new "post-quantum" algorithms which are designed to be resistant to quantum computers. However, they are just being rolled out now and so (1) a lot of current traffic is still vulnerable (2) anything you sent in the past with the old algorithms is vulnerable and there's nothing to do about that.
- _bin_ 2y agoEntirely true. China has been storing encrypted data for years specifically preparing for when CRQCs are available [1] and this is a huge concern for basically everyone in the world. There's a solid chance other evil actors have been doing the same. [1]: https://www.nextgov.com/emerging-tech/2021/11/report-china-may-steal-encrypted-government-data-now-decrypt-quantum-computers-later/187020/ https://www.nextgov.com/emerging-tech/2021/11/report-china-m...
- MattPalmer1086 2y agoIt's reasonable to point out that quantum computers can't make much of a dent in symmetric crypto on it's own. I do agree though that failing to point out that the vast majority of those symmetric keys are established with vulnerable asymmetric crypto is a bit misleading about the potential impact.