news.volyx.in

A cryptography engineer's perspective on quantum computing timelines (words.filippo.io)

551 points by thadt · 147 days ago · 248 comments on HN

Article summary

A cryptography engineer discusses the urgent need to roll out quantum-resistant cryptography due to recent advancements in quantum computing. The engineer cites papers from Google and Oratomic that demonstrate the feasibility of breaking 256-bit elliptic curves, which could compromise WebPKI and other cryptographic systems. The engineer argues that the risk of quantum computers breaking current cryptography is too high to ignore and that post-quantum cryptography should be deployed as soon as possible. This may require significant changes to existing cryptographic protocols and systems.

Main themes

  • post-quantum cryptography
  • quantum computing timelines
  • cryptographic protocol updates
  • hybrid algorithms
  • lattice-based cryptography
  • security risk assessment

What commenters say

  • The use of hybrid algorithms that combine classical and post-quantum cryptography is a viable solution to mitigate the risks of quantum computers.
  • Relying solely on post-quantum cryptography without hybrid algorithms may not be the best approach due to the uncertainty of post-quantum cryptography's security.
  • The development and deployment of post-quantum cryptography is too complex and nuanced to be rushed or oversimplified.
  • The risk of quantum computers breaking current cryptography is not imminent and the focus on post-quantum cryptography is premature.
  • The use of lattice-based cryptography is a promising approach to post-quantum cryptography, but its security assumptions are still understudied.
  • The progress towards practical quantum computing is not as rapid as some experts claim, and the threat to current cryptography may be overstated.
  • The deployment of post-quantum cryptography requires significant changes to existing protocols and systems, and a careful consideration of the trade-offs involved.