Slashdot Mirror


Quantum Computer Not Ready To Break Public Key Encryption For At Least 10 Years, Some Experts Say (theregister.co.uk)

physburn writes: The Register has spoken to some experts to get a better understanding of the risk quantum computers present to the existing encryption systems we have today. Richard Evers, cryptographer for a Canadian security biz called Kryptera, argues that media coverage and corporate pronouncements about quantum computing have left people with the impression that current encryption algorithms will soon become obsolete. But they will not be ready for at least 10 years, he said. As an example, Evers points to remarks made by Arvind Krishna, director of IBM research, at The Churchill Club in San Francisco last May, that those interested in protecting data for at least ten years "should probably seriously consider whether they should start moving to alternate encryption techniques now." In a post Evers penned recently with his business partner Alastair Sweeny, he contends, "The hard truth is that widespread beliefs about security and encryption may prove to be based on fantasy rather than fact." And the reason for this, he suggests, is the desire for funding and fame.

84 comments

  1. Quantum bunghole by Anonymous Coward · · Score: 0

    nt

  2. 10? by OneHundredAndTen · · Score: 0

    That sounds optimistic - I think that we have yet to reach the point at which we can tell with certainty that that will at all be feasible. Forget when.

    1. Re:10? by Spazmania · · Score: 2

      10 years? Where have I heard that before? Oh, right, AI in the 1960s.

      Seriously though, if your security is immediately breached when someone breaks your encryption, you should rethink your security. Security is about depth - how many layers an adversary must breach before he gains access to your valuables. If you only have one layer between you and your adversary, your valuables are not very secure.

      I thinking of you, blockchain.

      --
      Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
    2. Re:10? by TechyImmigrant · · Score: 2, Insightful

      I've been led to thinking that it will never be feasible. We don't know yet, but there are good reasons to think it might not pan out - for breaking crypto.

      E.G. The energy required to cool a volume of space for an n-qbit machine to temps that will maintain entanglement between the qbits will scale with 2^n. So you spend just as much energy doing it in parallel on a quantum computer as you would in a classical computer serially. This isn't known to be true, but try plotting the size of fridge against n for existing quantum computers and see what the curve looks like.

      or

      You can't achieve the isolation from the surrounding universe (which is kind of the same thing).

      I've seen other arguments about noise presented by physicists, but I haven't grokked them sufficiently,

      Quantum computing for physics simulation, as envisioned by Feinman, makes a lot more sense.

         

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    3. Re:10? by Anonymous Coward · · Score: 0

      Sure, do you remember when DES was going to take the lifetime of the Universe to crack, then some egg-heads had custom ASICS fabbed and built Deep Crack (EFF DES Cracker), which could break DES in a day?

      Just saying that nobody wants to be the dumbass who will be quoted for the foreseeable future saying something like, "They couldn't hit an elephant at this distance"

    4. Re:10? by Excelcia · · Score: 1, Insightful

      Seriously though, if your security is immediately breached when someone breaks your encryption, you should rethink your security

      Ah. Spoken like a true armchair security warrior. I love the sweeping declarations. If your security is breached when someone can open all your locks then you should rethink your security.

      Here are a few points to consider for you:
      1) My electronic security isn't all (or even necessarily mostly) in my hands any more. It's in the hands of banks, government agencies, and (not me but for the rest of you) social networks. I'm just sure that every tired career bureaucrat is just jumping at quantum computing resistant security. They are just right on that.
      2) In addition to my most important data residing, for the most part, in the hands beyond my control, so are the standards. Name a major implementation of an encryption technology standard that deprecated an algorithm before it was demonstrably broken. AES is currently broken in a cryptographic sense and there is not whisper on the horizon of deprecating it. Too costly.
      3) In addition to data being at the control of others, and available cryptography being at the mercy of established standards, even when standards are quick enough to add "heir and a spare" algorithms, the software that makes use of those standards doesn't necessarily have the configurability to choose the right algos. Dovecot, for example, just recently added in configurations to allow you to select which curves to use. For years you were stuck with terrible NIST curves which are at best horribly suspect, even though most systems had better curves.

      All these things are mitigatable to an extent, but you have to be a hermit not to be vulnerable.

    5. Re:10? by Megol · · Score: 4, Informative

      Sure, do you remember when DES was going to take the lifetime of the Universe to crack, then some egg-heads had custom ASICS fabbed and built Deep Crack (EFF DES Cracker), which could break DES in a day?

      No, I don't remember that for two reasons the most important being that nobody sane ever made such an idiotic claim. In fact in the wikipedia page linked by yourself (that you obviously didn't read) contains this: "One of the major criticisms of DES, when proposed in 1975, was that the key size was too short. Martin Hellman and Whitfield Diffie of Stanford University estimated that a machine fast enough to test that many keys in a day would have cost about $20 million in 1976, an affordable sum to national intelligence agencies such as the US National Security Agency".

      So not only didn't anybody make your ludicrous claim but people at the time said it was too easy to crack and estimated that one could realistically build a DES cracker.

    6. Re:10? by Anonymous Coward · · Score: 0

      There are many ways to assemble qubits, it is not/not all cryogenic, so the naive and frankly irresponsible commentary that large quantum computers will take a long time to develop reveals scientific ignorance. There are already quantum computers online today and available for use to the general public, the only questions is when they will be large enough to break crypto. This is now an engineering problem, not a physics question. China has invested 200X the combined US private/public investment in quantum computing and they've been storing US encrypted commercial and government communications for over a decade knowing they'll be able to break it in the near future. The US technological future is quantum computing, not AI or anything else. Don't listen to the opinions of English and biology majors (aka science writers *gulp*) about the feasibility, they have zero basis for a valid assessment, no more than a physicist has about oncology. These are the same people who never admit they were wrong and the first to make excuses like they didn't have all the facts. No, they did, they just weren't smart enough to be silent instead of pretending to have a knowledgeable opinion or insight. In this case, it is about the durable secrecy and privacy of communications that matter - financial, health, government, etc. Many of these collected today are still highly valuable ten years from now. Just ask Google, Facebook, Microsoft, etc.

    7. Re:10? by Joce640k · · Score: 1

      Sure, do you remember when DES was going to take the lifetime of the Universe to crack,

      Nope. The precise limitations of DES key size (56 bits) were known from day one, nobody ever thought it would take that long to crack.

      Math. It works.

      --
      No sig today...
    8. Re:10? by jellomizer · · Score: 2

      Technology projection:
      1 year: The technology works, we are just trying to find a vendor to sell it.
      5 years: We have a proof of concept working, however we don't know how to mass produce it.
      10 years: We have a theory that a proof of concept should work, trending shows it is possible a goal.
      20 years: We have no idea, but it seems possible
      100+ years: Impossible and have no idea on where to start. But it sounds nice.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    9. Re:10? by Joce640k · · Score: 1

      I've been led to thinking that it will never be feasible. We don't know yet, but there are good reasons to think it might not pan out - for breaking crypto.

      E.G. The energy required to cool a volume of space for an n-qbit machine to temps that will maintain entanglement between the qbits will scale with 2^n. So you spend just as much energy doing it in parallel on a quantum computer as you would in a classical computer serially. This isn't known to be true, but try plotting the size of fridge against n for existing quantum computers and see what the curve looks like.

      Also: Increasing key size is very easy. If quantum computers look like they're getting close we can simply double the key size.

      The reality is that only old messages will be decrypted and those messages are already out there so there's nothing you can do about that anyway.
      .

      --
      No sig today...
    10. Re:10? by Anonymous Coward · · Score: 0

      ah, the power of hindsight in the hands of a fuckwit

      Perhaps, if you were working in the field in the 90's, you would have heard such claims. I certainly did, not only for DES, but even for the crappy encryption (24 bit, then moved to 40 bit) that was used on Windoze

      The point is that each and every encryption scheme that has been foisted upon us has been presented as unbreakable and secure, when the opposite was not only true, BUT WELL KNOWN IN LIMITED CIRCLES.

      The fact that an extremely limited number of people were aware of the weaknesses of DES does not mean that the same messaging was given to the general public where were expected to use DES.

    11. Re:10? by sjames · · Score: 2

      Not only is the ability likely more than 10 years out, once it arrives it will be fantastically expensive, and fiddly as hell to keep the things running. You would have to be a very high value target (billions of dollars) to even be worth hacking for a while.

    12. Re:10? by sjames · · Score: 3, Interesting

      AES is currently broken in a cryptographic sense

      That cries out for a citation much as a man lost in the desert for a week cries out for water. As far as I know, the very best known attacks of AES256 reduce it to an effective 253 bits. That is FAR from broken in any sense.

      To say it's broken is like saying you can break a 2x4 with your bare hands as long as it came from a diseased tree and you saw 90% of the way through it first.

    13. Re:10? by Anonymous Coward · · Score: 0

      When talking about DES in Administrator/Technician level texts (what I was reading mostly in the 90s) it was common to sometimes do some illustrative calculation that would show the sun would eat the earth (or something like that) before (upper enthusiast level equipment of the day) could brute force a random password.
      Naturally at alt.cypherpunk the prevailing attitude was that it wasn't good enough (true) and that the sky is falling and digital pearl harbor has already happened and nobody noticed that we're full steam into digital armageddon and also the NSA has had full blown quantum accelerated superconducting AI FPGAs that can read minds and has had them since roswell (Not true but this is probably what they're still saying)

    14. Re:10? by Jaime2 · · Score: 2

      If there ever was an encryption algorithm that whose creators were realistic about how it would be attacked and the real threat posed, it was DES.

      They knew that 56 bits was "right" for the algorithm. That's why you see triple-DES, but not quadruple-DES. It only works well under very specific circumstances and the creators knew those circumstances well. They also knew enough to harden it against differential cryptanalysis, before differential cryptanalysis was publicly discussed.

    15. Re:10? by Anonymous Coward · · Score: 0

      AES is currently broken in a cryptographic sense

       
      That is the stupidest thing I have heard all day. I think you might be retarded

    16. Re:10? by gweihir · · Score: 2

      I agree. The number of entangled qbits has been scaling atrociously bad over the last few decades. A linear increase in qbits may well come with an exponential increase in effort and we may never reach even 100 of them. Also, the computations done with entangled qbits do not yet conclusively prove that quantum computing is really possible. The complexity of the computations done so far is so low that this could still be some other effect. Sure, the theory says it works, but remember that basically every physical model so far has failed when accuracy was scaled up enough. The accuracy scaling needed for breaking even simple ciphers is extreme here.

      Hence predictions that we will be able to do it at all are, at this time, basically lies, nothing else. There is no reliable data either way and a lot of indicators that it likely is practically impossible and it may still turn out to be theoretically impossible, giving us a better understanding of Physics in the process.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    17. Re:10? by gweihir · · Score: 1

      "10 years" is the time were most people making predictions hope that nobody will remember what they predicted. Here, it is obvious complete nonsense, but only experts can see that. All the others, including a large group of self-proclaimed experts that in reality do not know what they are talking about, are just going with the demented hype.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    18. Re:10? by gweihir · · Score: 1

      Math. It works.

      Like basically all things based on rational thought, it is not accessible to most people though.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    19. Re:10? by Anonymous Coward · · Score: 0

      The Feds had just given up on force-feeding Clipper down our throats when DES showed up and my full expectation was that they simply failed to mention the backdoors

      Pgp, on the other hand, had some credibility since the feds attempted to prevent export by calling it munitions, forcing Zimmerman to clean room it in Japan for resale globally

      imo, that was probably all kabuki

    20. Re:10? by Excelcia · · Score: 0

      That cries out for a citation much as a man lost in the desert for a week cries out for water.

      Other people might not appreciate the hyperbole but I do. Well done.

      As far as I know, the very best known attacks of AES256 reduce it to an effective 253 bits. That is FAR from broken in any sense.

      No, this is precisely what broken means. In a cryptographic sense (which I was careful to mention as being what I meant) broken is any attack which renders a result in less than brute-force time. AES's break is significant because it's not a reduced-round version that is vulnerable. It's the full version version. Rijndael's primary competitor in the AES competition was Serpent. Serpent's design philosophy was safety. Their design strategy was to include the number of rounds they thought would be safe against any attack during it's lifetime, and then to take that and double it. Serpent was, unfortunately, rejected, but their design philosophy was sound. It's not the known attacks that ever get you. It is, of course, the unknown. Security margin is important.

      Unfortunately, AES now has zero security margin. As mentioned, it's not a reduced round variant that has been broken. It's the full cipher. Which means every subsequent advance isn't biting into more rounds of security margin. It's biting into the real security of the cipher. The attack is still infeasible today. It requires 2^126 calculations (down from 2^126.2).

      That all being said, you latched onto the least important aspect of my point earlier, so let's refocus back on the important issue. Which was that it's easy for armchair security experts to just make sweeping statements about how we should just not rely on vulnerable technology. Fine. Let's see you get every bit of your important data into non-vulnerable algorithms in a layered security system. First describe that system to us, and then explain how you'll go about making sure your banking, health care, tax, social media, GPS location, television viewing preference, purchasing habits, email, and insurance information is properly migrated over into that system. I'm quite intrigued.

    21. Re:10? by ge · · Score: 1

      That DES by itself was too weak to withstand a state-funded attack was well known in the 90s, I was not exactly part of the cryptography in-crowd in those days, but I knew that much. I remember discussing the key length issue in a crypto discussion in college in 1985 or so, after a presentation about DES. No hindsight needed.

      If by "extremely limited" you mean tens of thousands of people I agree, but it was not exactly a secret. The big issue was that this was before there was "the web" so accessing information about anything was much harder in general, unless you had access to a research library.

    22. Re:10? by sjames · · Score: 1

      Actually broken means it is possible to come up with the key in a practical timeframe. Weakness is highly variable and somewhat subjective. In this case, the weakening doesn't look like it will make more progress and notably, it cannot actually be used since even for a 128 bit key you have to store 9 petabytes of data to use the technique (and anyone serious about security is using 256 bits).

      All that and you still have to use enough guesses that your grandchildren will be dead before you get the key.

      It's a bit premature to be replacing it.

    23. Re:10? by Spazmania · · Score: 1

      Nice ad-hominem you got going there. Let me offer a point for you to consider.

      I've left my front door open before. Forget locked, I've left the door wide open intending to go back inside, changed my mind in the 20 feet to the car and driven off forgetting the door was wide open.

      My security was not breached.

      I live in a neighborhood with watchful neighbors and a healthy police presence. Strangers poking around are noticed, reported, stopped. I could leave my door unlocked every day and it's unlikely I'd be burgled because: depth of security.

      Locked door. Watchful neighbors, Police presence. An adversary must defeat three distinct layers of security to steal my television. And if I was worried that wasn't enough, I could add an alarm system and a security camera.

      My home security does not, does not, does not critically depend on an adversary being unable to defeat the lock on my door.

      Encryption is like the lock on my front door. It's only one element of a successful security architecture. If it's the only element of your security system, if someone with the right electronic crowbar can pry your system open with impunity, it's time to rethink your security.

      And oh by the way, I've been in one or another part of the information security business for a quarter of a century. If one of us is an amateur, you're looking at the wrong one of us.

      --
      Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
    24. Re:10? by TechyImmigrant · · Score: 1

      Key size doesn't help with public key crypto. Shor's attack is a logarithmic speed up. Key size helps with the Grover attack for symmetric crypto since it's a square root speed up, but that wasn't the topic of TFA.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    25. Re:10? by Obfuscant · · Score: 1

      That sounds optimistic

      The latest issue of IEEE Spectrum has an article from a quantum computing expert who opines that true quantum computing for any serious task will never happen. It's an argument based on how many qubits are required to create a computing element and how precise the measurments of the wave functions have to be. That's paraphrasing it, but that's the idea.

      I tried finding an online link to it but can't.

  3. I have a prediction as well... by Anonymous Coward · · Score: 0

    It will never happen. This whole thing is a scam. Educate yourself and use your brain if you believe this is viable.

  4. 10 years for who? by Anonymous Coward · · Score: 0

    If publicly available machines will be capable in about 10 years, the military/intelligence agencies in the US have likely had them for 15 years already.

    1. Re:10 years for who? by gweihir · · Score: 1

      Since it is more like > 100 years for publicly available, and may well be "never", nobody has anything here. Also, if any such machine were used, there would be indications. There is none. In fact, the demented push against encryption is repeated again and again, rather strongly indicating that nobody can get into good encryption.

      Also remember that even a perfect QC cannot break something like AES-256 in this universe. It would still require 2^128 or so computations and that is just not feasible, no matter what resources you have. Oh, and that is the known-plaintext case, the other ones are harder.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  5. 10 Years == nonexistent security margin by Anonymous Coward · · Score: 0

    Really, 10 years is nothing. The NSA is presumably the world's largest employer of mathematicians and they are probably also not very short on engineers. 10 years of development judged from public available sources could mean that the NSA and similarly well-equipped intelligence agencies can already break it. Ten years is not a security margin at all in cryptography.

    1. Re:10 Years == nonexistent security margin by guruevi · · Score: 3, Interesting

      10 years to break today's encryption. We have more modern ciphers that will become used in the next few years that are resistant to the current theoretical models of quantum-computing based attacks.

      Also, quantum computing still has trouble of scale with larger keys, I assume that we'll see the next 10 years require 4096 or 8192 bit keys as scalable rental CPU and GPU becomes more powerful.

      And people really have to stop planning to have the same security model for the next 10 years in the future. Upgrades and long term support are becoming a necessity.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    2. Re:10 Years == nonexistent security margin by Anonymous Coward · · Score: 0

      Don't worry, quantum computers don't work as advertised.

    3. Re:10 Years == nonexistent security margin by gweihir · · Score: 1

      10 years is also not a time were we will see any significant advances in Quantum Computing. Maybe in 100 years, maybe never. Remember that we have been at this for like 50 years now and there is _still_ no viable computing hardware. All other alternate computing approaches have gone to the trash-heap of tech history long before that. But because many people associate "quantum" with "magic", this is still going, despite no practical results.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  6. The experts say... by jlv · · Score: 3, Insightful

    The "experts" say "not possible for 10 years".

    This means it will likely happen in the next 18 months.

    1. Re:The experts say... by aardvarkjoe · · Score: 0

      The "experts" say "not possible for 10 years".

      This means it will likely happen in the next 18 months.

      Well, either that, or every ten years the experts will say "ten more years."

      --

      How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
    2. Re:The experts say... by Hallux-F-Sinister · · Score: 2

      The "experts" say "not possible for 10 years".

      This means it will likely happen in the next 18 months.

      Actually, I think what this means is they've broken it and have been able to read messages "protected" or spoof messages "authenticated" in this way for a while. BUT they want people to keep using it, and not switch to something even more secure, that they CAN'T read. What makes me think this? Um, because it's obvious? That's the reason to make a giant fuss over encryption being too strong, so people think you haven't broken it. Did the Allies tell the Axis powers, "oh, hey, just to be fair and gentlemanly, we have to tell you we've totally broken your Enigma machine cypher system and can completely read any message you send with it within hours of intercepting it." Of course not. The fact that they'd broken it was likely an EXTREMELY closely guarded secret.

      Similarly, the NSA or MI...5 or 6 or whatever, I forget, having broken all the various forms of commercially available encryption is probably something they'll keep really quiet about if they ever do it, and pretend they haven't, hence... they've probably already done it.

      The closest thing to secure messaging is a one-time-pad cypher system, which is only really secure if BOTH ends hold the only keys and are secure and not compromised, if the code is TRULY random, and if any pad is only used EXACTLY ONCE. Naturally, key-distribution and security, (especially if there are multiple recipients,) is a giant problem and it's why, I suspect, it's probably not very widely used. Not compared with SSL or TLS or whatever, I imagine. Admittedly, I am not a cryptographic expert.

      --
      Our reign has gone on long enough. Indeed. Summon the meteors.
    3. Re:The experts say... by Anonymous Coward · · Score: 0

      Worse. It means this is a propaganda piece by the 5-eyes and they already have a quantum system that can break RSA.

    4. Re:The experts say... by Anonymous Coward · · Score: 0

      And the "stupid comment of the day" award for March 14 2019 goes to ....

    5. Re:The experts say... by Anonymous Coward · · Score: 0

      Yes, that's because there is an error on the predictions of approximately +/-20 years

    6. Re:The experts say... by Anonymous Coward · · Score: 0

      All good points, I would suggest Between Silk and Cyanide as baseline reading in understanding the concepts that Mr. Sinister brings to light.

      Key exchange is the critical point in any one time pad system (as it is in PKE), and there is a long history of smuggling, dead drops and broadcast 'numbers stations', which have been used to support it.

    7. Re:The experts say... by Anonymous Coward · · Score: 0

      And the same day google comes out to say it used 25 server 4 months to generate a new 31.4 trillion long password
      https://www.wired.co.uk/article/google-computing-pi-maths
      ( they have more than 25 servers right ? )

    8. Re:The experts say... by Megol · · Score: 1

      Just as we have fusion reactors in our cars and intelligent computers.

    9. Re:The experts say... by Anonymous Coward · · Score: 0

      Current crypto will be broken in 2-5 years if it hasn't been already. Honeywell and other big manufacturers just came out of stealth mode development in quantum computers, perhaps one of the most powerful, stable and scalable today. This is only the beginning and we should expect far more to be revealed in the next few years. Again, cryptographic security needs to stand the test of time, not just 2-5 years. Doubling the key length only applies to symmetric keys, not the ubiquitous public key (asymmetric) infrastructure. The current generation of solutions to this problem have no mathematical proof - we only think they will be secure just like my kid thinks the easter bunny will be coming this year. No scientific proof, but he believes it for sure.

    10. Re:The experts say... by gweihir · · Score: 1

      That is our "flying" cars, of course!

      Completely agree, the whole thing is BS. There is no threat to encryption from QCs at this time. Maybe when they can break DES or factor arbitrary 512 bit numbers, we need to think about it, but that looks unlikely to happen in the next 50 years, if the last 50 years are any indication.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    11. Re:The experts say... by Anonymous Coward · · Score: 0

      The Easter bunny is dead.
      He was shot with a 308.
      There's not much left of him.

  7. Yet to see a demo of useful quantum computing by Anonymous Coward · · Score: 1

    When will we see a traditional computer and quantum computer side by side, showing the quantum computer actually performing the same computation a million, or maybe just a thousand, or perhaps just ten times faster than the traditional computer?

    Let me know when, because before then it's nothing but quantum schmantum pipe-dreaming and weird research projects.

  8. Translation by Anonymous Coward · · Score: 0

    Quantum computers are already breaking Public key encryption. The public shall not be informed for at least the next century.

  9. Depends on relevant lifetime of messages by Anonymous Coward · · Score: 2, Interesting

    Whether or not people should be switching to encryption methods today that will be resistant to decrypting by quantum computers in thee future depends on the expected relevance of those messages in the future. If you assume that no message sent today will be relevant 10 years from now, then there is no hurry to update encryption methods. On the other hand, if you need to ensure that an encrypted message sent today or in the near future remains unreadable 10 years from now, then maybe you should be researching and changing methods today.

    1. Re: Depends on relevant lifetime of messages by David+Gould · · Score: 1

      Right. Another way of saying "it won't be broken for at least 10 years" would be "it could be broken in as soon as 10 years!" -- which, for the purposes of at least some organizations, is a "ZOMG THE SKY IS FALLING WE'RE SCREWED AAAAAAAH!!1!" scenario.

      --
      David Gould
      main(i){putchar(340056100>>(i-1)*5&31|!!(i<6)<< 6)&&main(++i);}
  10. I disagree by JcMorin · · Score: 1

    I don't think the military/intelligence agencies are ahead tech wise. In fact, I think they are way behind because of the complex structure and slow moving. When they want something, they don't use state of the art technique but rather simple letter request for it... or you go in jail. Gov don't break security by breaking the protocol, just just ask for a backdoor at the company. Much much easier and put the job on someone else.

    1. Re:I disagree by Anonymous Coward · · Score: 1

      "I don't think the military/intelligence agencies are ahead tech wise" I would re-think this erroneous and quite frankly stupid statement. Every government organization even peripherally connected with developing military or security related technology are what drives advances in technology. From times of war where budgets and cost factors are supplanted with only one goal which is to survive. To the trillions of dollars spent creating our modern technology base.

  11. If I were the US govt that's exactly what I would by Anonymous Coward · · Score: 0

    If I were the US govt that's exactly what I would tell you. ;-)

    "Nope. We can't see your data. That's a decade away!" Wink. Wink.

  12. Smoke and Mirrors because RSA = broken already by Anonymous Coward · · Score: 1

    Quantum computers work by solving the "hard" problem of prime factorization.
    Essentially an RSA key is the product of 2 randomly selected prime numbers. One is chosen by Alice and one is chosen by Bob at which point they exchange their halves, then they multiply to construct the key. Since the key is never transmitted, only the halves, the theory is that anyone attempting to decrypt their communications needs to guess the two halves of the whole key.

    So all of RSA is based on this idea that it is very hard to take a large number and deconstruct it into it's prime factors. But this is and always has been smoke and mirrors.

    The problem here is that there are a limited number of prime numbers currently known, roughly 2 billion, especially if you discount the smaller primes that wouldn't be cryptographically useful.

    Thus the total RSA key space is limited to the square of the total number of known primes, or 4 quintillion possible keys given the known number of primes. This is a really big number, but it isn't at all intractable.

    If you simply precompute by multiplying all known primes together, you can get at the shared secret for every RSA exchange. This could be stored in a database of just 500 petabytes.

    Considering there are systems that can crunch this kind of data in the 10TB/s range, you could safely crack any RSA message in no more than 14 hours on an HPC cluster, or 5 days running at home on your laptop.

    This is why quantum computing isn't particularly useful. State actors like the NSA, and Mossad and of course Bose Allen Hamilton (who handles the contracting work for both and sells the intelligence they gather in the process to the highest bidder) already have this capability and have been using it for decades.

    Simply switching over to NaCL https://nacl.cr.yp.to/index.html is enough to defeat this and for message exchanges larger than a few K you can use NaCL to handle AES key exchange, then use AES for the heavy lifting.
    But the powers that be will never allow this to become standard because it would prevent them from profiting off you. Hence the whole "quantum computing is coming zomg! schtick"

    1. Re: Smoke and Mirrors because RSA = broken already by Anonymous Coward · · Score: 0

      yeah no it doesn't work like that.

      The computer finds a NEW prime when it generates an RSA key.
      If anyone else knew this prime, the system would be broken.

      The prime is a "secret".

    2. Re:Smoke and Mirrors because RSA = broken already by Anonymous Coward · · Score: 1

      You really don't know how the numbers used in RSA are generated. I suggest becoming educated on the subject, and cryptography in general, so you don't sound like /.'s mental case who preaches local file based machine name lookups as security but with crypto instead. You are advocating switching from prime factorization based to elliptical curve based public key crypto which is really dumb when talking about quantum computers. Elliptical curve crypto is even easier to break with Shor's Algorithm than regular prime factorization crypto is.

    3. Re:Smoke and Mirrors because RSA = broken already by Anonymous Coward · · Score: 0

      there are a limited number of prime numbers currently known, roughly 2 billion

      The number is dramatically higher than that: https://en.wikipedia.org/wiki/Prime-counting_function

    4. Re:Smoke and Mirrors because RSA = broken already by gweihir · · Score: 1

      RSA is not broken. Stop pushing lies.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    5. Re:Smoke and Mirrors because RSA = broken already by Anonymous Coward · · Score: 0

      The problem here is that there are a limited number of prime numbers currently known, roughly 2 billion, especially if you discount the smaller primes that wouldn't be cryptographically useful.

      What the ever loving fuck???
      And some genius gave you a mod point.

    6. Re:Smoke and Mirrors because RSA = broken already by Anonymous Coward · · Score: 0

      One is chosen by Alice and one is chosen by Bob at which point they exchange their halves, then they multiply to construct the key.

      So OK, you don't even know the first thing about public key encryption.

      The problem here is that there are a limited number of prime numbers currently known, roughly 2 billion, especially if you discount the smaller primes that wouldn't be cryptographically useful.

      So much fail in the one post.
      Why the FUCK did you feel qualified to chime in on this?

    7. Re:Smoke and Mirrors because RSA = broken already by MrVictor · · Score: 1

      there are a limited number of prime numbers currently known, roughly 2 billion

      Totally wrong.

      Look at just the approximate number of 2048-bit primes which is in the range [2^2047 ... 2^2048-1].

      Approximate number of primes less than x is x/ln(x)

      So, we have (2^2048-1)/ln(2^2048-1) - (2^2047-1)/ln(2^2047-1)

      Which is ~ 1.14 x 10^613; a truly monstrous number.

  13. Public Key Encryption by Anonymous Coward · · Score: 0

    Broken already I'd say.

  14. Apply the NSA rule by SuperKendall · · Score: 2

    The "experts" say "not possible for 10 years".

    There's also the aspect of, the NSA is about 10 years ahead in relation to crypto and computing related technologies so...

    Nothing to worry about! Move along!

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  15. How long do you want that document to be secure? by Minupla · · Score: 1

    So if you encrypt something today, do you care if itâ(TM)s secret 10 years from now? Depending on what youâ(TM)re encrypting, yes you do.

    If your oposition is nation-states, theyâ(TM)re probably collecting things that are interesting now, for decryption later when they have the ability, so ya, you probably care now.

    Iâ(TM)ve had multiple professional conversations about âoepost-quantum cryptographyâ in the last 2 years because of exaclty this. Todayâ(TM)s emails are evidence or headlines 10 years from now, so you may care.

    Min

    --
    On the whole, I find that I prefer Slashdot posts to twitter ones because I don't get limited to 140 chars before
  16. Maybe they should put the AI in charge by Anonymous Coward · · Score: 0

    AI quantum computing holy cow!

  17. I'm sick of "news" of things that "will" happen... by Anonymous Coward · · Score: 0

    I wish I could only get news that *have* happened, or *will for sure* happen in the next week. None of these bullshit fantasies.

  18. Hardware, not software, prediction by SuperKendall · · Score: 1

    10 years? Where have I heard that before? Oh, right, AI in the 1960s.

    AI is all based on the ability of software, which is why predictions of reaching a specific point (which itself wasn't all that specific anyway, very nebulous) can and will be wildly inaccurate.

    When talking about quantum computing though, you aren't talking about anything nebulous or so hard to predict progress of. Generally predictions around when hardware will be developed by have been pretty accurate (if not underestimated).

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  19. Re:How long do you want that document to be secure by necro81 · · Score: 3, Interesting

    To quote from Cryptonomicon:

    Randy ... has pointed out to Avi, in an encrypted e-mail message, that if every particle of matter in the universe could be used to construct one single cosmic supercomputer, and this computer was put to work trying to break a 4096-bit encryption key, it would take longer than the lifespan of the universe.

    "Using today's technology," Avi shot back, "that is true. But what about quantum computers? And what if new mathematical techniques are developed that can simplify the factoring of large prime numbers?"

    "How long do you want these messages to remain secret?" Randy asked, in his last message before leaving San Francisco. "Five years? Ten years? Twenty-five years?"

    After he got to the hotel this afternoon, Randy decrypted and read Avi's answer. It is still hanging in front of his eyes, like the after image of a strobe:
    I want them to remain secret for as long as men are capable of evil.

  20. In other news by theCat · · Score: 1

    Burglar just released from prison says not ready to break into houses for a least a few years. "If anyone sees a break in," he offers, "It wasn't me. No sir."

    --
    =^..^= all your rodent are belong to us
  21. 10 years to read our traffic by Ronin+Developer · · Score: 1

    On the assumption they think it will take 10 years to crack existing crypto before there is a need to migrate to post-quantum algorithms, leads me to think they already have it or will very soon.

    I attended the RSA Data Security Conference In, I think it was 1993, when Diffie talked about cracking DES with dedicated hardware in a matter of hours. That same year, 512 bit RSA was cracked as one of the RSA Challenges.

  22. Re:How long do you want that document to be secure by Solandri · · Score: 1

    Quantum computing is useless against a one-time pad. It would just come up with all possible pads which convert the ciphertext into all possible plaintexts which makes sense. e.g. It would come up with decryption ciphers which convert the ciphertext to "one of by land, two if by sea" and "two if by land, one if by sea", leaving the code breaker no better off than not being able to break it.

    The only reason we use public key encryption is because it's a lot easier than meeting up in person to exchange a one-time pad before you can exchange secure communications. In public key encryption, you can exchange the key publicly yet still have encrypted communication. Also, it's slow enough that it's generally not used for the communications itself. It's used to exchange AES key(s) (basically one-time pads) securely. The encryption of the plaintext is then done using AES.

    All breaking public key encryption would do is put us back to the pre-1970s state of encryption, where secure communications required pre-sharing keys in some way. Difficult for random people/sites who have never spoken to each other before. But trivial for things like chipped credit cards, where the credit card company first has to physically mail you the credit card. (The one-time use rule for a one-time pad could be maintained by pre-loading thousands of one-time pads onto the chip, and replacing the credit card before they're all used up. Unthinkable a couple decades ago, but trivial today with modern storage capacities.)

    I could see trusted key escrow services popping up, which pre-share one-time pads with online sites and users. So if a user needs to communicate securely with some online site that they hadn't heard of until 5 minutes ago, they could go through the key escrow service to securely exchange keys with the site. User generates temporary key and securely transmits it to the key escrow service. Escrow service relays key to the site using their pre-shared key with the site. Escrow service immediately destroys their interim plaintext copy (the key the user generated). User uses that key to exchange a new key with the site. Then user can go about communicating securely with the site. It's not as secure as public key encryption since there's a third party involved. But it's still workable, and immune to quantum computing.

  23. Quantum computers are the future of global tech by Anonymous Coward · · Score: 0

    There are many ways to assemble qubits, it is not/not all cryogenic, so the naive and frankly irresponsible commentary that large quantum computers will take a long time to develop reveals scientific ignorance. There are already quantum computers online today and available for use to the general public, the only questions is when they will be large enough to break crypto. This is now an engineering problem, not a physics question. China has invested 200X the combined US private/public investment in quantum computing and they've been storing US encrypted commercial and government communications for over a decade knowing they'll be able to break it in the near future. The US technological future is quantum computing, not AI or anything else. Don't listen to the opinions of English and biology majors (aka science writers *gulp*) about the feasibility, they have zero basis for a valid assessment, no more than a physicist has about oncology. These are the same people who never admit they were wrong and the first to make excuses like they didn't have all the facts. No, they did, they just weren't smart enough to be silent instead of pretending to have a knowledgeable opinion or insight. In this case, it is about the durable secrecy and privacy of communications that matter - financial, health, government, etc. Many of these collected today are still highly valuable ten years from now. Just ask Google, Facebook, Microsoft, etc. Big companies with decades of engineering experience have been working in stealth to be first to market and the first few are just now going public, see Honeywell.

  24. Y2Q! plus 10 by Anonymous Coward · · Score: 1

    We've been told that once quantum computers reached quantum supremacy they would be able to break current encryption also known as Y2Q. Now you're saying it will be another 10 years? I don't buy it.

    https://en.wikipedia.org/wiki/Quantum_supremacy

  25. False by DontBeAMoran · · Score: 1

    If that's what they're announcing then it means they've broken it and are now trying to put our minds at ease, in order to "catch the bad guys" of course.

    --
    #DeleteFacebook
  26. Re: How long do you want that document to be secur by cyber-vandal · · Score: 1

    Please turn off "smart" quotes in your keyboard settings.

  27. Level of un-crackability by DrYak · · Score: 1

    No there are fundamentally different level.

    Old encryption standard, be it the venerable Enigma or more recently DES, were considered "hard to crack" because the key-space couldn't realistically be searched with the hardware available at the time.
    But lo and behold:
      - Computer technology emerged, making the enigma search-space manageable (well that, and a few short-coming of the Enigma algorithms, making it easier to crack thanks to clever tricks).
      - As mentioned above, DES couldn't be realistically brute forced with the available hardware, but researcher estimated that hardware capable of covering the search-space could be built within budget available to some state-level adversaries. And with Moore's law helping, modest modern hardware can now beat these.

    They were never considered "impossible to crack" only "very hard to crack" but eventually over time/with ressources, it could be achieved.

    More modern encryption standards such as RC4, AES, etc. are considered "impossible to crack within current laws of physics and/or math" because even if you converted the whole planet Earth into a giant computer, you couldn't cover the whole search-space before the death of the solar system. This time even Moore's law won't save you (in time).
    You'd need :
    - Cryptanalysis: problems found in a standard such as RC4. Meaning that you don't actually need to spend the heat-death of the universe searching the whole search-space. Instead there are way to find the few most likely candidate to focus on.
    - New physics/maths: finding new different ways to solve the problem that won't necessitate individually testing every single key in the search-space.

    TL;DR: So in short, old algos weren't secure, because eventually somebody would built a bigger computer faster enough to brute-force the password.
    Modern algos are secure, because the "bigger computer" required is beyond what is physically possible.
    You either need new physics.
    Or discovering that actually the password is always "Swordfish".

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
    1. Re:Level of un-crackability by Anonymous Coward · · Score: 0

      funny, it seems like we are always being told that we are given encryption tools that are unbreakable, only in hindsight to find out that they were nowhere as secure as advertised.

      The more it happens, the more I expect it to continue to happen

      So, you can take your condescending attitude and have a nice circle-jerk with megol whilst feeling secure nobody will break the encryption on your video

      I, on the other hand, will expect it to pop up on 4chan... eventually (and no, I am not waiting > 10 years for that to happen)

  28. Re:How long do you want that document to be secure by Anonymous Coward · · Score: 0

    This is the problem. You can bet your butt that groups like the NSA have a cache of encrypted communications - why not, they store everything else they intercept - and the moment they have a way to break the system used to encrypt, they will go back and read all those documents and communications.

    There's a really good sci-fi story by Isaac Asimov, "The Dead Past" where the protagonists discover a means to spy on the present but not the far past. Instead, we'll have a rolling horizon and communications from 10 years ago, 5 years ago, 3 years ago will slowly become exposed as the tech progresses.

    Assuming the tech works.

  29. Just in time for retirement by Anonymous Coward · · Score: 0

    Encryption will be broken just in time for state actors to empty out my 401K. Watch as my government shrugs and doesn't give a shit.

  30. What a relief! by Anonymous Coward · · Score: 0

    We can wait ten years before bothering to attempt to design post quantum encryption because we're safe until then!

  31. Suuuuuuuure....... by JustAnotherOldGuy · · Score: 1

    "Quantum Computer Not Ready To Break Public Key Encryption For At Least 10 Years, Some Experts Say"

    That's what they want you to believe.

    You know, the mysterious, shadowy "they" that's behind everything- chemtrails, the flat-earth, anti-vaxxers, Reptilians, C++ pointers...it's all them and they. Hopefully they won't delete this post where I blow the lid off of their nefarious activities.

    The light in your fridge burned out? They did it. One of your tires suddenly gets low? They did it. Who ate all the ice cream? They did.

    It's so obvious, sheeple! Wake up!

    --
    Just cruising through this digital world at 33 1/3 rpm...
  32. Again types of unbreakable. by DrYak · · Score: 1

    funny, it seems like we are always being told that we are given encryption tools that are unbreakable, only in hindsight to find out that they were nowhere as secure as advertised.

    Maybe the long post wasn't clear enough.
    I'm not saying that the algorithms are guaranteed 100% unbreakable for ever.

    I'm just saying that the reason of unbreakability have change drastically over time.

    - Old algorithms were unbreakable because to break them requires additional computing power. It wasn't available at the time. But with time (and Moore's law) a big enough computer is guaranteed to emerge, eventually.
    They were (in a way) *guaranteed* to be breakable one day in the future. Just a matter of (computer) engineering.

    - Newer algorithm *WILL NOT* be broken just by a bigger computer. That doesn't guarantee that they'll never be broken, it only guarantees that a bigger computer *IS NOT* the thing that will break.
    They'll get broken instead by either one of the following three:

    - New type of physics and maths that make the algorithm irrelevant.
    ( ^- that is what all the quantum-crypto love to speculate about, but currently it's not something that we observe in the wild)
    - Bugs are discovered, turns out the algorithm is flawed. In theory no a big enough computer can physically exist to break it, but it in practice, thanks to bugs it turns out it's trivial.
    ( ^- that's what happens to all cryptography standards that get phased out. See RC4)
    - People are stupid. No amount of cryptographic science is going to save you if your password everywhere is always "123". Hey that's my luggage's... Or if it can simply be bypassed due to implementation blunder, because basically the lock is indeed locking the door on the left side, but noone will prevent you from unscrewing the door's hinge on the right side.
    ( ^- in practice, that's what is happening most of the time time nowadays. See haveibeenpwnd).

    So, you can take your condescending attitude and have a nice circle-jerk with megol whilst feeling secure nobody will break the encryption on your video

    Nobody is saying that the encryption of the video is never ever going to by broken.
    The things that we try to say is that the way it will be broken have changed.

    Back in the old days, the hairy-porn video with moustaches will eventually get broken, because somebody will eventually make a big enough computer.

    Nowadays, most of the time, the amateur-porn will get broken/private nudie pick will get disseminated, because most likely some bozo though that "pa$$w0rd" was secure enough (but, it follows the required numbers/signs rules !), or because some researcher has noticed that the reportedly "military grade super secret crypto technique" used by the video storage, if you twiddle the bits in a certain un-expected way, boils down to a simple ROT-13 that your pocket calculator could break.

    But nowadays a bigger computer isn't the thing that will break it, it's physically not possible *now*.

    (but it was physically possible a long time ago, but considered distant enough, so such crypto did get used back then)

    To go back to the subject,

    - 56bits DES got broken, because 56bits is small and eventually a big computer could be built (even back then people were drawing attention and sending alerts that a government *could* have the budget to make such a big computer quite soon).

    - 256bits AES cannot be broken by a physical computer. Not now, not in 1'000 years from now. It could be broken by an entire new physics and maths to make an exotic new type of computer (that's what quantum computing is touted by some to be able to open as possibilites), or because some scientist will discover bugs, enabling ways to break AES, without needing to go through all 2^256 combinations (and this just hasn't happened yet for any meaningful reduction of this big number).

    AES considered unbreakable and potentially getting broken on

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]