News: 1630520491

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NSA: We 'don't know when or even if' a quantum computer will ever be able to break today's public-key encryption

(2021/09/01)


America's National Security Agency has published an FAQ about quantum cryptography, saying it does not know "when or even if" a quantum computer will ever exist to "exploit" public-key cryptography.

In the document, titled Quantum Computing and Post-Quantum Cryptography FAQ , the NSA said it "has to produce requirements today for systems that will be used for many decades in the future." With that in mind, the agency came up with some [1]predictions [PDF] for the near future of quantum computing and their impact on encryption.

Is the NSA worried about the threat posed by a "cryptographically relevant quantum computer" (CRQC)? Apparently not too much.

[2]

"NSA does not know when or even if a quantum computer of sufficient size and power to exploit public key cryptography (a CRQC) will exist," it stated, which sounds fairly conclusive – though in 2014 the agency [3]splurged $80m looking for a quantum computer that could smash current encryption in a program titled Owning the Net, so the candor of the paper's statements is perhaps open to debate.

[4]

[5]

What the super-surveillance agency seems to be saying is that it's not a given that a CRQC capable of breaking today's public-key algorithms will ever emerge, though it wouldn't be a bad idea to consider coming up with new techniques that could defeat a future CRQC, should one be built.

It's almost like the NSA is dropping a not-so-subtle hint, though why it would is debatable. If it has a CRQC, or is on the path to one, it might want to warn allies, vendors, and citizens to think about using quantum-resistant technologies in case bad people develop a CRQC too. But why would the spies tip their hand, so? It's all very curious.

Progress on quantum computers has been steadily made over the past few years, and while they may not ever replace our standard, classical computing, they are very effective at solving certain problems

Eric Trexler, VP of global governments at security shop Forcepoint, told The Register : "Progress on quantum computers has been steadily made over the past few years, and while they may not ever replace our standard, classical computing, they are very effective at solving certain problems. This includes public-key asymmetric cryptography, one of the two different types of cryptosystems in use today."

Public-key cryptography is what the world relies on for strong encryption, such as TLS and SSL that underpin the HTTPS standard used to help protect your browser data from third-party snooping.

[6]

In the NSA's summary, a CRQC – should one ever exist – "would be capable of undermining the widely deployed public key algorithms used for asymmetric key exchanges and digital signatures" – and what a relief it is that no one has one of these machines yet. The post-quantum encryption industry has long sought to portray itself as an immediate threat to today's encryption, as El Reg [7]detailed in 2019.

"The current widely used cryptography and hashing algorithms are based on certain mathematical calculations taking an impractical amount of time to solve," explained Martin Lee, a technical lead at Cisco's Talos infosec arm. "With the advent of quantum computers, we risk that these calculations will become easy to perform, and that our cryptographic software will no longer protect systems."

Given that nations and labs are working toward building crypto-busting quantum computers, the NSA said it was working on "quantum-resistant public key" algorithms for private suppliers to the US government to use, having had its Post-Quantum Standardization Effort running since 2016. However, the agency said there are no such algos that commercial vendors should adopt right now, "with the exception of [8]stateful hash signatures for firmware."

[9]

Smart cookies will be glad to hear that the NSA considers AES-256 and SHA-384 "safe against attack by a large quantum computer."

[10]If you're worried that quantum computers will crack your crypto, don't be – at least, not for a decade or so. Here's why

[11]Edgy: HPE's first message from the International Space Station to Microsoft's Azure? 'hello world'

[12]South Korea plans large scale quantum cryptography adoption, thanks in part to tech partnership with USA

[13]Quantum physics to encrypt clouds of the future - boffins

Jason Soroko, CTO of Sectigo, a vendor that advertises "quantum safe cryptography" said the NSA report wasn't conclusive proof that current encryption algos were safe from innovation.

"Quantum computers alone do not crack public key cryptography," he said, adding that such a beast would need to execute an implementation of Shor’s algorithm. That algo was first described in 1994 by [14]an MIT maths professor and allows for the calculation of prime factors of very large numbers; a vital step towards speeding up the decryption of the product of current encryption algorithms.

"Work on quantum resistant cryptographic algorithms is pushing forward based on the risk that ‘Universal’ quantum computers will eventually have enough stable qubits to eventually implement Shor’s algorithm," continued Soroko. "I think it’s important to assume that innovation in both math and engineering will potentially surprise us."

While advances in cryptography are of more than merely academic interest to the infosec world, there is always the point that security (and data) breaches occur because of primarily human factors. Ransomware, currently the largest threat to enterprises, typically spreads because someone's forgotten to patch or decommission a machine on a corporate network – or because somebody opens an attachment from a malicious email.

Or there's the old joke about rubber hose cryptanalysis, referring to [15]beating the passwords out of a captured sysadmin.

Talos' Lee concluded: “In a world where users will divulge their passwords in return for chocolate or in response to an enticing phishing email, the risk of quantum computers might not be our biggest threat.” ®

Get our [16]Tech Resources



[1] https://media.defense.gov/2021/Aug/04/2002821837/-1/-1/1/Quantum_FAQs_20210804.PDF

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YS-4Ifr5uDxoUdGZJPavjQAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2014/01/03/snowden_docs_show_nsa_building_encryptioncracking_quantum_system/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YS-4Ifr5uDxoUdGZJPavjQAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YS-4Ifr5uDxoUdGZJPavjQAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YS-4Ifr5uDxoUdGZJPavjQAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2019/03/14/quantum_encryption_debunking/

[8] https://csrc.nist.gov/publications/detail/sp/800-208/final

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YS-4Ifr5uDxoUdGZJPavjQAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2019/03/14/quantum_encryption_debunking/

[11] https://www.theregister.com/2021/08/19/spaceborne-2/

[12] https://www.theregister.com/2021/05/25/south_korea_quantum_encryption/

[13] https://www.theregister.com/2012/01/20/blind_quantum_computing_for_the_cloud/

[14] https://news.mit.edu/2016/quantum-computer-end-encryption-schemes-0303

[15] https://www.schneier.com/blog/archives/2008/10/rubber_hose_cry.html

[16] https://whitepapers.theregister.com/



Well, *that's* a relief!

Anonymous Coward

If the NSA says not to worry, that means they already have 3.14159265358979323846264338327950288419716939937510582097494459230781640628620899862803482534211706798214808651328230664709384460955058223172535940812848111745028410270193852110555964462... of them.

Not asking the right people

Pete 2

> it does not know "when or even if" a quantum computer will exist to "exploit" public key cryptography.

I wonder what the response would be if that question was asked of the chinese?

[1]China emerges as quantum tech leader while Biden vows to catch up (says the chinese!)

[1] https://asia.nikkei.com/Spotlight/Datawatch/China-emerges-as-quantum-tech-leader-while-Biden-vows-to-catch-up

AES-256 and SHA-384, is that all?

Anonymous Coward

Bah. I've been using AES-1024 and SHA-4096 for decades. I encoded my library of bad filk about squirrels. To give them something to do. Because I'm a right bastard, that's why. Have fun! =-D

So...

Vulch

saying it does not know "when or even if" a quantum computer will ever exist to "exploit" public-key cryptography.

It went live last week then.

See if the NSA asks for funding for such a computer

Ken G

If it doesn't, it means they already have one and are funding themselves by mining bitcoin.

Re: See if the NSA asks for funding for such a computer

ravenviz

If they had done that then all the Bitcoin would already be in circulation.

"users will divulge their passwords in return for chocolate"

Pascal Monett

What makes you think they will gave their actual password ?

You want to give me a frozen Mars Bar for my email password ? Kachinka2708. Hand it over.

Anonymous Coward

Ultimately for the first 50 years, quantum computers will be too heavily monetised to actually be useful so they are probably telling the truth XD

Chris Miller

If a QC could churn out billions of bitcoin, that would be interesting.

>>> FreeOS is an english-centric name

Have you all been stuck in email, or have any of you tried
*pronouncing* that? free-oh-ess? free-ows? fritos? :-)
-- Mark Eichin