[HN Gopher] Why Quantum Cryptanalysis is Bollocks [pdf]
___________________________________________________________________
Why Quantum Cryptanalysis is Bollocks [pdf]
Author : commandersaki
Score : 26 points
Date : 2025-02-14 09:42 UTC (3 days ago)
(HTM) web link (www.cs.auckland.ac.nz)
(TXT) w3m dump (www.cs.auckland.ac.nz)
| kirrent wrote:
| Man, some real "Cynicism is the intellectual cripple's substitute
| for intelligence" energy here. Seems unnecessary given what I
| read of Gutmann's history.
|
| I get it must be annoying to be someone working in cryptography
| and always be hearing about QC when there are endless security
| issues today. It must be tiring to have all these breathless pop-
| science articles about the quantum future, startups claiming
| ridiculous timelines to raise money on hype, and business
| seminars where consultants claim you'll need to be prepared for
| the quantum revolution changing how business works. I feel the
| same way.
|
| But you shouldn't let that drive you so far in the opposite
| direction that you're extrapolating fun small quantum factoring
| experiments from a decade ago to factoring 1024 bit keys in the
| year 4000. Or say things like 'This makes the highly optimistic
| assumption that quantum physics experiments scale linearly... the
| evidence we have, shown by the lack of progress so far, is that
| this is not the case'. If we get fault tolerant QC of course it
| scales linearly and it seems embarrassing as a computer scientist
| to not understand the difference between constant and asymptote.
| "Actually, quantum computers are so new and untested that they
| really qualify as physics experiments"... yeah? And?
|
| None of this is to say that fault-tolerant highly scalable QC
| implementing Shor's algorithm is just around the corner, I truly
| believe it's not. But the world of QC is making really
| interesting advances running some of the coolest experiments
| around and I find this superior Hossenfelder-like cynicism in the
| face of real science making real progress so so tiring.
| nemo wrote:
| This smalls a lot like wishcasting masquerading as critique. I
| just attended a PQC conference, so I'm biased, but this paper's
| author makes a lot of very strong claims about the infeasibility
| of future attacks developing that most experts in the field would
| disagree with. There is a hope that this is all a fire drill and
| RSA/EC will survive the next decade unscathed, but there's also
| plenty of evidence to suggest that incremental improvements in PQ
| compute will eventually reach their goal. Rather than a big
| cannon, I see it looking more like AI/LLMs, lots and lots of
| small incremental improvements by researchers were needed to
| eventually yield some significant advancements. I pray Post
| Quantum computing stays in the realm of Cold Fusion, but I'm not
| about to believe it.
|
| Cryptanalysis has already made a few strides on breaking RSA more
| quickly, and I've heard from noted cryptanalysts the claim
| there's a significant chance RSA will be further broken in the
| next decade regardless of PQ. It's a scary take to double down on
| RSA of all things.
| baxtr wrote:
| Out of curiosity: which conference did you attend? I find the
| field interesting.
| tptacek wrote:
| Love me some Peter Gutmann. This is classic Gutmann.
|
| A lot of this presentation is mooted by understanding PQC as an
| scientific question rather than an engineering one. What are the
| precise natures of quantum-superior attacks on cryptosystems and
| what are key establishments and signatures that resist those
| attacks? Whatever else you think of quantum cryptanalysis those
| are undeniably important theoretical questions.
|
| A few more slides are mooted by the likelihood that any
| mainstream deployed PQC system is going to be hybridized with a
| classical cryptosystem.
|
| As an articulation of a threat model for modern computing, it
| simultaneously makes some sense and proves too much: if you think
| OWASP-type vulnerabilities are where everyone's head should be at
| (and I sort of agree), then all of cryptography is a sideshow.
| I'm a connoisseur of cryptographic vulnerabilities that break
| real systems the way SQL injection does (a bitflipping attack on
| an encrypted cookie, a broken load-bearing signature scheme) but
| even I have to admit there's 1 of those for every 10,000
| conventional non-cryptographic attack.
|
| But of course, it also depends on who your adversary is.
| Ironically, if you're worried about state-level SIGINT, the
| barrier for OWASP-style attacks may be higher than that of large-
| scale codebreaking; passive interception and store-now-decrypt-
| later is the SIGINT love language.
|
| My biggest thing with all of this is a core belief about
| organizations like NSA: that they exist primarily to secure
| budget for NSA. Given that, the one thing you absolutely don't
| want to do is have a system that is breakable only at _almost_
| -implausible cost.
|
| (Also, his RSA-1024 analysis is off; it's missing batch attacks).
| mik1998 wrote:
| I think it is worthwhile to explore cryptography that is not
| based on the discrete logarithm problem. Currently, we're keeping
| all eggs in one conjectured basket. Even if quantum computing
| will never be viable, there is a non-zero chance that the
| discrete logarithm problem will be solved in some other way.
| hujun wrote:
| one thing I agree that software/standard people like to churn,
| churn is a source of new income regardless if QC could break RSA
| or not in the future, people could make profit now
___________________________________________________________________
(page generated 2025-02-17 23:00 UTC)