news.volyx.in

Cloudflare targets 2029 for full post-quantum security (blog.cloudflare.com)

386 points by ilreb · 146 days ago · 112 comments on HN

Article summary

Cloudflare aims to achieve full post-quantum security by 2029, including post-quantum authentication, in response to recent breakthroughs in quantum computing that threaten current encryption methods. Google has also accelerated its post-quantum migration timeline to 2029 due to concerns about the potential for quantum computers to break essential cryptography. The development of quantum computers is progressing rapidly, with advancements in hardware, error correction, and software. This has significant implications for online security, particularly for interactions between unrelated parties that rely on public-key cryptography.

Main themes

  • Post-Quantum Security
  • Quantum Computing
  • Encryption Methods
  • Online Security
  • Cryptography

What commenters say

  • The secrecy surrounding quantum computing advancements is a concern, as it may indicate that global powers are preparing for war and hiding their capabilities.
  • The threat of quantum computers to current encryption methods is real and warrants urgent attention, with some experts believing that quantum computers could break essential cryptography as early as 2030.
  • The transition to post-quantum cryptography is not a rush job, but rather a carefully considered process that has been ongoing for several years, with lattice cryptography being a well-established field.
  • Some post-quantum cryptography algorithms have been shown to be vulnerable to attacks, which raises questions about the security of these algorithms and the need for further research and testing.
  • The use of pre-shared secret keys can avoid the need for public-key cryptography and mitigate the risk of quantum computer attacks, but this approach may not be practical for all applications.
  • The comparison between the current state of post-quantum cryptography and the development of AES is not entirely accurate, as the underlying technologies and theories are different.
  • Experts in the field believe that the current post-quantum cryptography constructions are secure within the bounds of our current understanding of quantum computing, but there may still be unknown vulnerabilities.
  • The lack of transparency and openness in the development of quantum computing and post-quantum cryptography is a concern, as it may hinder progress and create mistrust among experts and the public.