3 ms·
> only asymmetric systems based on DLP and IFP will be compromised due to the efficiency of Shor's algorithm. Quantum computing has larger implications than th
by ReidZB 13y ago
> only asymmetric systems based on DLP and IFP will be compromised due to the efficiency of Shor's algorithm.
Quantum computing has larger implications than that. For instance, AES with 128-bit keys will need to be phased out since Grover's algorithm would allow a 2^64 time known-plaintext search. MD5 will likewise require 2^64 time to find a preimage, despite its resistance so far to non-quantum preimage attacks.
You should not discount that "only" asymmetric schemes based on DLP/IFP will be vulnerable, either. Much of our current key-exchange implementations do not have post-quantum strength at present.
Still, as you say, it is not "end of the world" status for cryptography. It will just require a lot of effort on the part of system builders to implement post-quantum constructions. The issue of backwards compatibility and widespread implementations will (as it always is) be a significant hurdle.
It's my experience, however, that the average person doesn't know or care about encrypting their data at all. It's almost certainly the opposite on a site like reddit or HN, but anecdotally, when my parents' friends (as an example) ask what I study and I say "cryptography," it's exceptionally hit-and-miss if they'll even know what I'm talking about. (A nontrivial portion of people think I've said "photography," actually!)
I've found that "encryption" is more widely-known than cryptography, but even then, it's been my experience that most (non-techie) people have no clue about it. But, I suspect that changes quite drastically given your social circle, area of the world you live in, and culture.