15
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
(words.filippo.io)
a community for posting cool tech news you don’t want to sneer at
non-awfulness of tech is not required or else we wouldn’t have any posts
First, I personally don't yet believe in the cryptographic security of LWE on lattices. I agree that it sure looks hard, but we don't have a solid proof. But also, I don't believe that we've found any provably one-way functions in the classical regime either. So I agree with you from different premises.
Unlucky 10,000: Shor's algorithm speeds up any discrete logarithm. It actually speeds up the abelian HSP. This does give us a theoretical reason to expect that LWE on lattices won't fall to Shor's approach, as the underlying groups are non-abelian. It does make me sad for elliptic curves, though; they're so elegant and the keys are so small.
Not sure what you think my "different premises" are? Also I obviously already know that Shor's algorithm solves the discrete log problem. I don't know why you phrased your comment assuming I'm an idiot.
Would an idiot know the difference between abelian and non-abelian group theory? I wasn't trying to underestimate you; I agreed with your position and provided a tangent that opens up your position without compromising it. Next time I'll explicitly say "yes, and" if that will help.
Ok next time you should really not do the "lucky 10000" bit, it comes off as very condescending especially if the person you're talking to already knows the thing you're telling them.
I will say that, speaking as an idiot, I appreciated the information and the accessibility of many of these very technical conversations here is one of the elements of this community I appreciate. I would be very surprised if it had been meant as any kind of dig instead of explicitly clarifying a usually-unstated bit of context.