3 ms·
I think people have to be extremely careful with this kind of opinion. In particular seeing such a push for post-quantum crypto while the current state of the a
by Tyyps 6mo ago
I think people have to be extremely careful with this kind of opinion.
In particular seeing such a push for post-quantum crypto while the current state of the art for quantum factorisation is 15 and 21 and the fact that current assumptions (for KEM in particular) are clearly not as studied as dlog.
It's maybe good to remember that SIDH was broken in polynomial time by a classical computer 3 years ago...
I'm really concerned by the current rush for PQ solutions and what are the real intentions behind it.
On a side note there might even be a world where a powerfully enough quantum computer that break 2048 bigs RSA will never exists (Hooft, Palmer... Recent quantum gravity theory).
- mikestorrent 6mo agoThe largest number factorised on a quantum computer is 8,219,999 on a D-Wave machine (a quantum annealer, so not capable of running Shor's, but capable of being an actual shipping product you can use, unlike gate model machines). https://www.nature.com/articles/s41598-024-53708-7 https://www.nature.com/articles/s41598-024-53708-7 > Overall, 8,219,999 = 32,749 × 251 was the highest prime product we were able to factorize within the limits of our QPU resources. To the best of our knowledge, this is the largest number which was ever factorized by means of a quantum annealer; also, this is the largest number which was ever factorized by means of any quantum device without relying on external search or preprocessing procedures run on classical computers.
- nextaccountic 6mo agoThe D-Wave machine doesn't benefit from the quantum speedups discussed in the article
- Tyyps 6mo agoThis is quantum annealing and it has nothing to do with Shor (I should have been precise sorry). It is not clear at all that quantum annealing provides any speedup compared to a classical computer.
- mikestorrent 6mo agoYeah that was the first line of my comment. Annealing is in fact proven to be able to do certain things faster than any classical CPU; whether you can make use of that particular feature is a different question. If you're into spinglasses, maybe
- William_BB 6mo agoYou should read the article you posted before you write a comment. Hint: check P_F=0 in tables 2, 3 and 4. "Factored" is doing a lot of lifting here and is borderline deceptive. Plenty of researchers have long ago pointed out that this won't scale, see M Mosca for reference.
- mikestorrent 6mo agoI'm aware; I don't think gate model machines have demonstrated much potential of scaling in practice any time soon so this is more of a lark to show how unimpressive the current Shor's attempts have been
- fc417fc802 6mo agoAs long as a hybrid approach is taken what is there to worry about? Whereas not adopting PQC in a timely manner is obviously a gamble.
- Tyyps 6mo agoI agree, but the blog post was specifically ruling out hybrid approach.
- fc417fc802 6mo ago> I'm really concerned by the current rush for PQ solutions and what are the real intentions behind it. You had written. As long as we're in agreement that rushing PQ appears to be the appropriate choice. The only question is the precise form it should take, with the author arguing that hybrid would be unacceptably slow to roll out due to various social and bureaucratic reasons. He's also pointing out that the only scenario in which hybrid is of benefit is one in which crypto related QC remains either relatively ineffective or extremely expensive in the medium term. Since that assumption is looking increasingly suspect it calls into question the point of hybrid to begin with. In the face of cheap QC hybrid adds zero value.
- Tyyps 6mo agoI think it is pretty direct from my comment that if you use a hybrid approach (done correctly) you can rely on the hardness of dlog based assumption and therefore my comment on potential weakness of PQ assumptions can be ruled out. In this way we disagree that rushing PQ is the appropriate choice if it rules out dlog based security. > He's also pointing out that the only scenario in which hybrid is of benefit is one in which crypto related QC remains either relatively ineffective or extremely expensive in the medium term. Since that assumption is looking increasingly suspect it calls into question the point of hybrid to begin with. In the face of cheap QC hybrid adds zero value. This is exactly what I'm pointing out as extremely dangerous. My take was that the risk of seeing a quantum computer breaking dlog in a near future isn't stronger than breaking PQ assumptions in a near future.