4 ms·
This smalls a lot like wishcasting masquerading as critique. I just attended a PQC conference, so I'm biased, but this paper's author makes a lot of very strong
by nemo 2y ago
This smalls a lot like wishcasting masquerading as critique. I just attended a PQC conference, so I'm biased, but this paper's author makes a lot of very strong claims about the infeasibility of future attacks developing that most experts in the field would disagree with. There is a hope that this is all a fire drill and RSA/EC will survive the next decade unscathed, but there's also plenty of evidence to suggest that incremental improvements in PQ compute will eventually reach their goal. Rather than a big cannon, I see it looking more like AI/LLMs, lots and lots of small incremental improvements by researchers were needed to eventually yield some significant advancements. I pray Post Quantum computing stays in the realm of Cold Fusion, but I'm not about to believe it.
Cryptanalysis has already made a few strides on breaking RSA more quickly, and I've heard from noted cryptanalysts the claim there's a significant chance RSA will be further broken in the next decade regardless of PQ. It's a scary take to double down on RSA of all things.
- baxtr 2y agoOut of curiosity: which conference did you attend? I find the field interesting.
- nemo 2y agoPKI Consortium: https://pkic.org/events/2025/pqc-conference-austin-us/ https://pkic.org/events/2025/pqc-conference-austin-us/
- tptacek 2y agoCould you relate who those noted cryptanalysts are, that are predicting a significant chance that RSA-2048 is broken classically?
- nemo 2y agoI don't recall their name, they were a guest on the Root Causes podcast discussing PQ topics, though your summary varies from what I was trying to express. It's not that RSA will be classically broken, but that novel attacks to reduce factoring times of RSA key like batch attacks have a statistically significant chance of being discovered, that "further" was not meant to imply "completely broken classically," but "weakened further using classical approaches". Sounded plausible to me, though that's not a thing I'm any kind of domain expert in.
- tptacek 2y agoRight, batch attacks certainly threaten 1024 bit RSA, but, obviously, 2048 bit RSA is not just incrementally harder to break than 1024 bit RSA.
- oh_my_goodness 2y agoAnything specific at all would be helpful.
- nemo 2y agoSorry I'm busy, might have time to spend to look the podcast up in a day or two, but I don't think there's any actual value in that to anyone over an offhand comment so forgive me if I find other things to do instead.
- dadrian 2y agohttps://podcasts.apple.com/us/podcast/root-causes-408-takeaways-from-recent-conversations/id1455703066?i=1000663796648 https://podcasts.apple.com/us/podcast/root-causes-408-takeaw...
- pbsd 2y agoAntoine Joux was on the side of classical cryptanalysis on a 2014 bet. This was right after the small-characteristic discrete log advances, so that might no longer be the bet if it was made today. https://x.com/hashbreaker/status/494867301435318273 https://x.com/hashbreaker/status/494867301435318273