We used to do all kinds of crazy stuff with pen and paper or funky mechanical tools.

But then along comes Horst Feistel at IBM and just makes it sooo boring. Everything is computers!

Security tokens are sooo boring. Give me back a code wheel and make me do some crap with a cryptex or something.

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 2 days ago* (last edited 2 days ago)

In principle quantum computers could break many modern asymmetrical ciphers, such as RSA and elliptic curve cryptography. Although, there are a few caveats.

  1. This depends upon being able to build a quantum computer with extraordinarily large numbers of qubits. Current development trends are so slow that if this does occur, it could take decades. Unless a major breakthrough is announced tomorrow, we are not anywhere near seeing widespread breaking up encryption via quantum computers.
  2. This is also entirely new empirical territory, applying quantum theory to a regime it has never been tested. While nothing in our current models suggest it is impossible, our current models have never been applied in these regimes before. There are hypothetical models in the literature, like rational quantum mechanics, which predict a breakdown in our predictions in these regimes, and so we cannot be 100% certain that building a large-scale quantum computer is even possible.
  3. We've already developed post-quantum cryptography, which consists of asymmetrical ciphers that are not known to be defeated by quantum computers, and so, worse comes to worse, we already have replacements to solve the problem. The main issue will be companies that are slow to upgrade, or companies which have upgraded but someone has collected a bunch of encrypted traffic for the purpose of unencrypting it the distant future.

My point is that it's a real concern, but it's not exactly absolutely certain that quantum computers will break modern encryption, but it is indeed a possibility we should be worried about, but at the same time, we've already developed methods to avoid it. So, it's a possibility, that we've already developed the tools to mitigate. Some browsers, like Firefox, already include support for post-quantum cryptography, and so if you are a business that is worried about it, you can just use those ciphers in your HTTPS and then there is no worry.

  • source
  • parent