News: 1682490485

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

You can cross 'Quantum computers to smash crypto' off your list of existential fears for 30 years

(2023/04/26)


RSA Conference Adi Shamir, the cryptographer whose surname is the "S" in "RSA", thinks folks need to stop worrying about quantum computing breaking encryption algorithms.

Speaking on the annual cryptographers' panel at the RSA Conference in San Francisco this week, he opined that in the 1990s he saw three big issues appear on the security industry's radar: AI, cryptography, and quantum computing. Two out of three had delivered, he said, and quantum computing has yet to show promise and won't for decades to come.

99 percent of encrypted messages are junk, he opined. Requests for lunch meetings or banal chat; waste of time to decrypt, and there's so much of it.

[1]

The idea that such missives would be a top cracking priority isn't realistic, he reminded the audience. And while important messages might be decoded decades on, the signal-to-noise ratio is going to make throwing a quantum machine at the job a poor way to find real secrets.

[2]

[3]

He wasn't alone in his skepticism. British mathematician Cliff Cocks, who developed public-key cryptography years before session host Dr Whitfield Diffie and his colleagues came up with the same idea, was somewhat cutting about stories that the Chinese [4]have developed quantum systems to crack current encryption systems.

The Chinese system may work well on very small data sets, he opined, but there's "no evidence whatsoever" that it would work on a larger scale. That said, Anne Dames, IBM zSystems Distinguished Engineer and Cryptographic Technology Architect, argued China's efforts are as good a reason as any to update your public-private keys just to be on the safe side. The longer and more secure the keys the better she opined. There's no harm in using quantum-resistant algorithms, either, we note.

[5]

The RSA cryptographer's panel in San Francisco today

"Quantum computers, even if they don't exist today, will do in the next 30-40 years, so we will need to switch keys," she advised, saying the current concerns over quantum cryptography reminded her a lot of blockchain hype.

[6]India gives itself a mission to develop a 1000-qubit quantum computer in just eight years

[7]Assume the superposition: Intel emits SDK to simulate quantum computers

[8]Bosch-backed VCs pour more funds into Brit quantum silicon chips

[9]What Mary, Queen of Scots, can teach today's cybersec royalty

That said, all the encryption in the world isn't going to help you defend against insider threats. It's been ten years since an IT contractor called Edward Snowden managed to walk off with the NSA's crown jewels, and the latest Pentagon leak is [10]alleged to have involved a guy showing off classified information on Discord to impress friends. This showed the systems we use are still critically weak, Diffie argued.

Shamir argued Snowden was a short-term and long-term disaster for the NSA, and diminished America's influence by exposing directly long-suspected practices - such as the presence of backdoors in commercial products - for which no evidence had previously been available. Quantum computers breaking encryption could deliver similar revelations, Shamir opined, but it's a way off doing so. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZEj2SpzoACW8-rI5cCc3MwAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEj2SpzoACW8-rI5cCc3MwAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEj2SpzoACW8-rI5cCc3MwAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2023/01/07/chinese_researchers_claimed_quantum_encryption/

[5] https://regmedia.co.uk/2023/04/25/rsa.jpg

[6] https://www.theregister.com/2023/04/20/india_quantum_mission/

[7] https://www.theregister.com/2023/03/01/intel_quantum_sdk/

[8] https://www.theregister.com/2023/02/21/quantum_motion_funding/

[9] https://www.theregister.com/2023/02/20/opinion_column_mary_queen_of_scots/

[10] https://www.theregister.com/2023/04/13/alleged_pentagon_leaker_arrested/

[11] https://whitepapers.theregister.com/



There's a Mandy Rice-Davies quote in there

Anonymous Coward

somewhere.

Encryption is not the only answer. The biggest problem is the human

ColinPa

Having your data encrypted means someone who does not have the keys cannot read it.

If you do have the keys then you can usually copy the data (or photograph it).

I have data on an encrypted disk. The data is visible to me because I had the key. I can easily copy the data to a USB. It is going to be a challenge to make this secure.

How many years away?

IanRS

I strongly suspect there will be a very similar wait for usable quantum decryption as there is (and has been) for usable nuclear fusion. All the practical problems will be sorted out in twenty years. Twenty years later: it will be ready in twenty years.

Re: How many years away?

Adrian 4

Is that a generation of people or a generation of crypto ?

Does the same as the system call of that name.
If you don't know what it does, don't worry about it.
-- Larry Wall in the perl man page regarding chroot(2)