8 ms·
The page only talks about adopting PQC for key agreement for SSH connections, not encryption in general so the overhead would be rather minimal here. Also from
by fxwin 1y ago
The page only talks about adopting PQC for key agreement for SSH connections, not encryption in general so the overhead would be rather minimal here. Also from the FAQ:
"Quantum computers don't exist yet, why go to all this trouble?"
Because of the "store now, decrypt later" attack mentioned above. Traffic sent today is at risk of decryption unless post-quantum key agreement is used.
"I don't believe we'll ever get quantum computers. This is a waste of time"
Some people consider the task of scaling existing quantum computers up to the point where they can tackle cryptographic problems to be practically insurmountable. This is a possibilty. However, it appears that most of the barriers to a cryptographically-relevant quantum computer are engineering challenges rather than underlying physics.
If we're right about quantum computers being practical, then we will have protected vast quantities of user data. If we're wrong about it, then all we'll have done is moved to cryptographic algorithms with stronger mathematical underpinnings.
Not sure if I'd take the cited paper (while fun to read) too seriously to inform my opinion the risks of using quantum-insecure encryption rather than as a cynical take on hype and window dressing in QC research.
- sigmoid10 1y ago>it appears that most of the barriers to a cryptographically-relevant quantum computer are engineering challenges rather than underlying physics I've heard this 15 years ago when I started university. People claimed all the basics were done, that we "only" needed to scale. That we would see practical quantum computers in 5-10 years. Today I still see the same estimates. Maybe 5 years by extreme optimists, 10-20 years by more reserved people. It's the same story as nuclear fusion. But who's prepping for unlimited energy today? Even though it would make sense to build future industrial environments around that if they want to be competitive.
- fxwin 1y ago> People claimed all the basics were done, that we "only" needed to scale. This claim is fundamentally different from what you quoted. > But who's prepping for unlimited energy today? It's about tradoffs: It costs almost nothing to switch to PQC methods, but i can't see a way to "prep for unlimited energy" that doesn't come with huge cost/time-waste in the case that doesn't happen
- bee_rider 1y agoAnyway, what does prepping for unlimited energy look like? I guess, favoring electrical over fossil fuels. But for normal people and the vast majority of companies, that looks like preparing for mass renewable electricity anyway, which is already a good thing to do.
- fxwin 1y agocould also be just massively scaling up energy consumption with little concern for efficiency (since limitless would imply very low cost), which would probably be a bad idea for renewables, and in case of not-so-cheap energy also very expensive
- thesz 1y agoWith limitless energy you can have "fossil fuel" synthesized from air and water [1] and use existing "fossil fuel" infrastructure. [1] https://www.wired.com/2012/10/fuel-from-air/ https://www.wired.com/2012/10/fuel-from-air/
- thayne 1y ago> It's about tradoffs: It costs almost nothing to switch to PQC methods, It costs: - development time to switch things over - more computation, and thus more energy, because PQC algorithms aren't as efficient as classical ones - more bandwidth, because PQC algorithms require larger keys
- fxwin 1y agoall of which are costs that pale in comparison to having your data compromised, depending on what it is
- throw0101a 1y ago> It costs: Not wrong, but given these algorithms are mostly used at setup, how much cost is actually being occurred compared to the entire session? Certainly if your sessions are short-lived then the 'overhead' of PQC/hybrid is higher, but I'd be curious to know the actually byte and energy costs over and above non-PQC/hybrid, i.e., how many bytes/joules for a non-PQC exchange and how many more by adding PQC. E.g. > Unfortunately, many of the proposed post-quantum cryptographic primitives have significant drawbacks compared to existing mechanisms, in particular producing outputs that are much larger. For signatures, a state of the art classical signature scheme is Ed25519, which produces 64-byte signatures and 32-byte public keys, while for widely-used RSA-2048 the values are around 256 bytes for both. Compare this to the lowest security strength ML-DSA post-quantum signature scheme, which has signatures of 2,420 bytes (i.e., over 2kB!) and public keys that are also over a kB in size (1,312 bytes). For encryption, the equivalent would be comparing X25519 as a KEM (32-byte public keys and ciphertexts) with ML-KEM-512 (800-byte PK, 768-byte ciphertext). * https://neilmadden.blog/2025/06/20/are-we-overthinking-post-quantum-cryptography/ https://neilmadden.blog/2025/06/20/are-we-overthinking-post-... "The impact of data-heavy, post-quantum TLS 1.3 on the Time-To-Last-Byte of real-world connections" (PDF): * https://csrc.nist.gov/csrc/media/Events/2024/fifth-pqc-standardization-conference/documents/papers/the-impact-of-data-heavy-post-quantum.pdf https://csrc.nist.gov/csrc/media/Events/2024/fifth-pqc-stand... (And development time is also generally one-time.)
- unethical_ban 1y agoThe comparison to fusion power doesn't hold. The costs to migrate to PQC continue to drop as they become mainstream algorithms. Second, the threat exists /now/ of organizations capturing encrypted data to decrypt later. There is no comparable current threat of "not preparing for fusion", whatever that entails.
- dlubarov 1y agoI would just take this to mean that most people are bad at estimating timelines for complex engineering tasks. 15 years isn't a ton of time, and the progress that has been made was done with pretty limited resources (compared to, say, traditional microprocessors).
- spauldo 1y agoWhy would you think that fusion would give you unlimited energy? All it does is allow you to get energy from cheap, nearly unlimited fuel. You still have to produce, transmit, store, and distribute that energy. It's great for the environment but for most people not much would change.
- sigmoid10 1y agoWhat you pay in a free market is (highly simplified) the marginal cost. So even if the setup is highly expensive, in the end, if your fuel is abundant and cheap, your electricity will be abundant and cheap
- pclmulqdq 1y agoIt's been "engineering challenges" for 30 years. At some point, "engineering challenges" stops being a good excuse, and that point was about 20 years ago. At some point, someone may discover some new physics that shows that all of these "engineering challenges" were actually a physics problem, but quantum physics hasn't really advanced in the last 30 years so it's understandable that the physicists are confused about what's wrong.
- fxwin 1y agoYou might be right that we'll never have quantum computers capable of cracking conventional cryptographic methods, but I'd rather err on the side of caution in this regard considering how easy it is to switch, and how disastrous it could be otherwise.
- b112 1y agoEspecially of the break through isn't public, and used behind the scenes.
- simiones 1y agoAs others pointed out, it's not so easy to switch, as the PQC versions require much more data to be sent to establish a connection, and consequently way more CPU time. So the CPS you can achieve with this type of cryptography will be MUCH worse than classical algorithms.
- ifwinterco 1y agoLet's be honest though, key exchange is not exactly the limiting factor for web performance in 2025
- msgodel 1y agoIt can be limiting for other things though. Encrypted DNS was already marginal for some TLD operators, adding the overhead of PQC may actually make it completely impractical.
- ktallett 1y agoThose are two odd questions to even ask/answer as first quantum computers exist and secondly, we have them on a certain scale. I assume what they mean is at a scale to do calculations that surpass existing classical calculations.