[HN Gopher] Why Quantum Cryptanalysis is Bollocks [pdf]
       ___________________________________________________________________
        
       Why Quantum Cryptanalysis is Bollocks [pdf]
        
       Author : commandersaki
       Score  : 26 points
       Date   : 2025-02-14 09:42 UTC (3 days ago)
        
 (HTM) web link (www.cs.auckland.ac.nz)
 (TXT) w3m dump (www.cs.auckland.ac.nz)
        
       | kirrent wrote:
       | Man, some real "Cynicism is the intellectual cripple's substitute
       | for intelligence" energy here. Seems unnecessary given what I
       | read of Gutmann's history.
       | 
       | I get it must be annoying to be someone working in cryptography
       | and always be hearing about QC when there are endless security
       | issues today. It must be tiring to have all these breathless pop-
       | science articles about the quantum future, startups claiming
       | ridiculous timelines to raise money on hype, and business
       | seminars where consultants claim you'll need to be prepared for
       | the quantum revolution changing how business works. I feel the
       | same way.
       | 
       | But you shouldn't let that drive you so far in the opposite
       | direction that you're extrapolating fun small quantum factoring
       | experiments from a decade ago to factoring 1024 bit keys in the
       | year 4000. Or say things like 'This makes the highly optimistic
       | assumption that quantum physics experiments scale linearly... the
       | evidence we have, shown by the lack of progress so far, is that
       | this is not the case'. If we get fault tolerant QC of course it
       | scales linearly and it seems embarrassing as a computer scientist
       | to not understand the difference between constant and asymptote.
       | "Actually, quantum computers are so new and untested that they
       | really qualify as physics experiments"... yeah? And?
       | 
       | None of this is to say that fault-tolerant highly scalable QC
       | implementing Shor's algorithm is just around the corner, I truly
       | believe it's not. But the world of QC is making really
       | interesting advances running some of the coolest experiments
       | around and I find this superior Hossenfelder-like cynicism in the
       | face of real science making real progress so so tiring.
        
       | nemo wrote:
       | This smalls a lot like wishcasting masquerading as critique. I
       | just attended a PQC conference, so I'm biased, but this paper's
       | author makes a lot of very strong claims about the infeasibility
       | of future attacks developing that most experts in the field would
       | disagree with. There is a hope that this is all a fire drill and
       | RSA/EC will survive the next decade unscathed, but there's also
       | plenty of evidence to suggest that incremental improvements in PQ
       | compute will eventually reach their goal. Rather than a big
       | cannon, I see it looking more like AI/LLMs, lots and lots of
       | small incremental improvements by researchers were needed to
       | eventually yield some significant advancements. I pray Post
       | Quantum computing stays in the realm of Cold Fusion, but I'm not
       | about to believe it.
       | 
       | Cryptanalysis has already made a few strides on breaking RSA more
       | quickly, and I've heard from noted cryptanalysts the claim
       | there's a significant chance RSA will be further broken in the
       | next decade regardless of PQ. It's a scary take to double down on
       | RSA of all things.
        
         | baxtr wrote:
         | Out of curiosity: which conference did you attend? I find the
         | field interesting.
        
       | tptacek wrote:
       | Love me some Peter Gutmann. This is classic Gutmann.
       | 
       | A lot of this presentation is mooted by understanding PQC as an
       | scientific question rather than an engineering one. What are the
       | precise natures of quantum-superior attacks on cryptosystems and
       | what are key establishments and signatures that resist those
       | attacks? Whatever else you think of quantum cryptanalysis those
       | are undeniably important theoretical questions.
       | 
       | A few more slides are mooted by the likelihood that any
       | mainstream deployed PQC system is going to be hybridized with a
       | classical cryptosystem.
       | 
       | As an articulation of a threat model for modern computing, it
       | simultaneously makes some sense and proves too much: if you think
       | OWASP-type vulnerabilities are where everyone's head should be at
       | (and I sort of agree), then all of cryptography is a sideshow.
       | I'm a connoisseur of cryptographic vulnerabilities that break
       | real systems the way SQL injection does (a bitflipping attack on
       | an encrypted cookie, a broken load-bearing signature scheme) but
       | even I have to admit there's 1 of those for every 10,000
       | conventional non-cryptographic attack.
       | 
       | But of course, it also depends on who your adversary is.
       | Ironically, if you're worried about state-level SIGINT, the
       | barrier for OWASP-style attacks may be higher than that of large-
       | scale codebreaking; passive interception and store-now-decrypt-
       | later is the SIGINT love language.
       | 
       | My biggest thing with all of this is a core belief about
       | organizations like NSA: that they exist primarily to secure
       | budget for NSA. Given that, the one thing you absolutely don't
       | want to do is have a system that is breakable only at _almost_
       | -implausible cost.
       | 
       | (Also, his RSA-1024 analysis is off; it's missing batch attacks).
        
       | mik1998 wrote:
       | I think it is worthwhile to explore cryptography that is not
       | based on the discrete logarithm problem. Currently, we're keeping
       | all eggs in one conjectured basket. Even if quantum computing
       | will never be viable, there is a non-zero chance that the
       | discrete logarithm problem will be solved in some other way.
        
       | hujun wrote:
       | one thing I agree that software/standard people like to churn,
       | churn is a source of new income regardless if QC could break RSA
       | or not in the future, people could make profit now
        
       ___________________________________________________________________
       (page generated 2025-02-17 23:00 UTC)