4 ms·
I'm under the impression that quantum computers buy you a square root. So instead of doubling the number of bits in your key to improve the strength of a key by
by peterwaller 13y ago
I'm under the impression that quantum computers buy you a square root. So instead of doubling the number of bits in your key to improve the strength of a key by a ludicrous amount, you should quadruple them.
In addition to this, I don't know how well quantum computers help against (good) symmetric encryption. They help against certain types of PKI because they give you the aforementioned speedup in factoring large integers. However, I think Schneier's argument holds, because brute forcing 2^256 possible keys is.. well, see the argument above about forcing a counter through all those states.
(apologies for not citing sources. Hopefully someone more knowledgeable can weigh in)
- archgoon 13y agoFor AES you are correct. The best known quantum attack is Grover's Search Algorithm (but emphasis on 'known' here), reducing the key space to 2^128. RSA, however, is based on prime factors, so it can be broken with Shor's Algorithm, which means it will take on the order of (256)^3 operations.