Author Topic: What is "quantum safe"?  (Read 6912 times)

0 Members and 3 Guests are viewing this topic.

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11179
  • Country: fi
Re: What is "quantum safe"?
« Reply #25 on: February 14, 2025, 12:15:57 pm »
Do not bother, there will be no quantum computers capable of breaking existing public key scheme encryption for the next 15 years at least.

According to someone who's actually done the math, it's not 15 years, it's 4,000 years.

That's pretty fun and enjoyable reading, and it does have a point, but saying he has "done the math" is an overstatement. Clearly the presentation is meant as a joke, and the author has not done their homework, because he so strongly believes that he must be right and others wrong that he does not bother to listen what others have to say. Instead of numbers and evidence, the presenter is applying "common sense" in a way which is most likely correct, but even a trained dog can do it, and sometimes "common sense" is not correct.

Even being just year or two old (I don't know, it shows 2023 as a data point), the presentation already didn't age well. The claim that quantum computing basically does not exist (and is just "physics experiment") already proved false. I was actually pretty surprised personally discussing this with a guy who does physics simulations and him telling with straight face that of course quantum computers exist, they use them all the time; they develop algorithms for them and use them to do real-world physics simulations. This is in huge contrast what you read on EEVBlog forum comments which basically claim that there are no commercial quantum computers available and all they can do is calculate 3*5=15 on a physics lab.

Given that the whole premise of this presentation ended up wrong, I would not place my bets on the conclusion being correct either. (Or maybe I would do exactly that: place my bets that he's correct - point being it's a gamble, not a scientific fact.) Quantum computing breaking current asymmetric key cryptography is a possibility which either realizes or does not realize within next 10, 20, or 50 years. This author places their bets on it not realizing any time soon with not much else than their personal "hunch" or "intuition"; if they end up being wrong then they are either silent about it or say "sorry, I was wrong". Such people are often right, but not always.

Also complaining about TLS being "too complex" during the time of historical simplification process of TLS (the 1.2 to 1.3 transition) simply indicates this guy... does not follow what's happening on the field he's talking about. It probably still is too complex, but claiming that somehow all the resources flow into quantum conferences is... ludicrous. I'm sure that 99% of the resources spent in data security are spent on everything else except quantum anything.

The most underlying point is of course valid: we should probably be concentrating on the attacks that happen today, especially because they are mostly the same they were 5 years ago, and will remain the same for the next 5 and 10 and probably 15 years.
« Last Edit: February 14, 2025, 12:17:40 pm by Siwastaja »
 

Online 5U4GB

  • Super Contributor
  • ***
  • Posts: 1734
  • Country: au
Re: What is "quantum safe"?
« Reply #26 on: February 14, 2025, 12:27:24 pm »
Given that the whole premise of this presentation ended up wrong,

Why is it wrong, apart from you claiming it is?  This was originally discussed on (from memory) Reddit and no-one there came up with anything to counter it.
 

Offline coppice

  • Super Contributor
  • ***
  • Posts: 10289
  • Country: gb
Re: What is "quantum safe"?
« Reply #27 on: February 14, 2025, 12:54:21 pm »
There are two essential components to a quantum computer. 1) Smoke and 2) mirrors.

I don't think I've ever encountered a technology as full of BS as quantum computers. People have been making pretty much the same positive and negative claims about it since D-Wave shipped their first machine in 2011. If they were getting somewhere there should by now have been some well published result that convinces people its doing something impressive by the standards of traditional computing. I have yet to see an impressive claim that has stood up to scrutiny. This isn't to say it won't at some point be impressive, but they seem to be in that awkward phase in the development of a new technology where the only way to keep the funding going is to turn the BS up to 11.
 
The following users thanked this post: 5U4GB

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11179
  • Country: fi
Re: What is "quantum safe"?
« Reply #28 on: February 14, 2025, 01:22:18 pm »
Given that the whole premise of this presentation ended up wrong,

Why is it wrong, apart from you claiming it is?

The claim that quantum computers do not exist as computers (are not computers, it literally says so) is of course incorrect, because now quantum computers do exist: they are available for commercial use. See e.g. https://www.vttresearch.com/en/ourservices/quantum-computing

I was also under belief they don't exist at all, or are completely incapable of computing any real-world job. A short lunch-time discussion with someone who actually writes software for them, and uses them for real-world workloads, namely multi-physics simulations, changed that view. Of course, they also said that classic computers are so far superior. And that noise is a big issue in quantum computing. No surprise there, no one is claiming otherwise.

Quantum computers are still completely impractical, and incapable of breaking RSA or ECC, with nothing in sight that would change it in a few years. No one claimed otherwise.

But claiming they are "just" scientific experiments unable to do anything more than a dog can do was maybe true in 2010, but not in 2023. Therefore, cherry-picking over 10 year old two datapoints and then claiming it takes 4000 year is intellectual dishonesty.

Really the only one making strong and certain claims is the author you linked to. As the one making the claim, I would expect stronger evidence. And don't me wrong, I have nothing against that presentation, it's a good "let's keep our feet on the ground" wakeup presentation presented in a humorous way. But really, saying
"According to someone who's actually done the math, it's not 15 years, it's 4,000 years."
completely mispresents it. That is not a serious calculation, based on any serious research, but you make it sound like it is.
« Last Edit: February 14, 2025, 01:27:26 pm by Siwastaja »
 

Offline coppice

  • Super Contributor
  • ***
  • Posts: 10289
  • Country: gb
Re: What is "quantum safe"?
« Reply #29 on: February 14, 2025, 01:29:45 pm »
Given that the whole premise of this presentation ended up wrong,

Why is it wrong, apart from you claiming it is?

The claim that quantum computers do not exist as computers (are not computers, it literally says so) is of course incorrect, because now quantum computers do exist: they are available for commercial use. See e.g. https://www.vttresearch.com/en/ourservices/quantum-computing

I was also under belief they don't exist at all, or are completely incapable of computing any real-world job. A short lunch-time discussion with someone who actually writes software for them, and uses them for real-world workloads, namely multi-physics simulations, changed that view. Of course, they also said that classic computers are so far superior. And that noise is a big issue in quantum computing. No surprise there, no one is claiming otherwise.

Quantum computers are still completely impractical, and incapable of breaking RSA or ECC, with nothing in sight that would change it in a few years. No one claimed otherwise.

But claiming they are "just" scientific experiments unable to do anything more than a dog can do was maybe true in 2010, but not in 2023. Therefore, cherry-picking over 10 year old two datapoints and then claiming it takes 4000 year is intellectual dishonesty.

Really the only one making strong and certain claims is the author you linked to. As the one making the claim, I would expect stronger evidence. And don't me wrong, I have nothing against that presentation, it's a good "let's keep our feet on the ground" wakeup presentation presented in a humorous way. But really, saying
"According to someone who's actually done the math, it's not 15 years, it's 4,000 years."
completely mispresents it. That is not a serious calculation, based on any serious research, but you make it sound like it is.
You just claimed they are currently nothing more than scientific experiments at this time, yet say that claim is untrue. You aren't making sense.
 

Online peter-hTopic starter

  • Super Contributor
  • ***
  • Posts: 5990
  • Country: gb
  • Doing electronics since the 1960s...
Re: What is "quantum safe"?
« Reply #30 on: February 14, 2025, 03:00:51 pm »
From above link:

VTT Q5 is a 5-qubit superconducting quantum computer co-developed and built by IQM and VTT. It is located in Espoo, Finland, at VTT.

VTT Q5, also called Helmi, has been available for academic users since autumn 2022. Now, VTT Q5 is open for research and commercial users interested in developing quantum computer software and algorithms.

VTT Q5 is accessible through the supercomputer LUMI. Read more on the CSC website.

VTT also launched a 20-qubit quantum computer in autumn 2023. After that, we aim to build a 50-qubit quantum computer during spring 2025.


Also:

The number of qubits needed to break RSA encryption depends on the size of the RSA key. For example, breaking a 256-bit RSA key might require 2,500 qubits, while breaking a 2048-bit RSA key might require around 4,000 qubits. However, the exact number of qubits required is difficult to determine because it depends on other factors, such as the levels of interference and errors in the quantum computer.

but the above assumes zero noise, so it is hard to extrapolate.

Z80 Z180 Z280 Z8 S8 8031 8051 H8/300 H8/500 80x86 90S1200 32F417
 

Offline Halcyon

  • Global Moderator
  • *****
  • Posts: 6804
  • Country: au
Re: What is "quantum safe"?
« Reply #31 on: February 15, 2025, 02:33:20 am »
No encryption is safe, all you need is Janek's black box. ;-)

 

Online 5U4GB

  • Super Contributor
  • ***
  • Posts: 1734
  • Country: au
Re: What is "quantum safe"?
« Reply #32 on: February 15, 2025, 05:18:02 am »
The number of qubits needed to break RSA encryption depends on the size of the RSA key. For example, breaking a 256-bit RSA key might require 2,500 qubits, while breaking a 2048-bit RSA key might require around 4,000 qubits. However, the exact number of qubits required is difficult to determine because it depends on other factors, such as the levels of interference and errors in the quantum computer.

but the above assumes zero noise, so it is hard to extrapolate.

The estimate for the number of qubits in the presence of noise, i.e. with some (well, many) used for error correction, is a million qubits.  It's pure fantasy-land stuff.
 

Online 5U4GB

  • Super Contributor
  • ***
  • Posts: 1734
  • Country: au
Re: What is "quantum safe"?
« Reply #33 on: February 15, 2025, 05:30:34 am »
The claim that quantum computers do not exist as computers (are not computers, it literally says so) is of course incorrect, because now quantum computers do exist: they are available for commercial use. See e.g. https://www.vttresearch.com/en/ourservices/quantum-computing

Great, now come back when you've used one to factor a 512-bit RSA key, which you can do with a current desktop PC.

Quote
Therefore, cherry-picking over 10 year old two datapoints and then claiming it takes 4000 year is intellectual dishonesty.

Again, come back with newer data points.  The reason why it uses those is because there are no other data points, that's all the progress that has been made in 20 years.

As I said previously, simply repeating "it's wrong, it's wrong, it's wrong" isn't any kind of valid argument.  If it's so wrong you should have no problems providing evidence of progress in breaking PKCs and the imminent demise of RSA or whatever via a quantum computer.
 

Offline coppercone2

  • Super Contributor
  • ***
  • Posts: 13719
  • Country: us
  • √Y√... 📎
Re: What is "quantum safe"?
« Reply #34 on: February 15, 2025, 05:39:58 am »
do they have like a animation or something that was made by quantum computers, like a simulation, for fluids or atoms or strain or whatever

animation, stress diagram.. graph, any output of a simulator that could be used as a 'figure'

like the first useful comptuer plotted a graph which you can take a picture of and put in a book, or they made a animation of something like water across a propeller later that was recorded and shown to others on tape. did quantum computer do this?

or like control a servo mechanism (like a aiming computer?) that you can record with a camera?

like this
« Last Edit: February 15, 2025, 05:45:17 am by coppercone2 »
 

Offline Bud

  • Super Contributor
  • ***
  • Posts: 7922
  • Country: ca
Re: What is "quantum safe"?
« Reply #35 on: February 15, 2025, 05:43:01 am »
Everyone is fixated on using quantum computers to break encryption , but this is only one use case out of many. Quantum annealing comuters such as DWave can't run Shor algorithm at all, meaning they may never be used to break public key encryption, but that does not mean they are totally useless.
Facebook-free life and Rigol-free shack.
 

Offline MK14

  • Super Contributor
  • ***
  • Posts: 5385
  • Country: gb
Re: What is "quantum safe"?
« Reply #36 on: February 15, 2025, 05:56:58 am »
As soon as there is the slightest sign, that Quantum computers, are a thing and successfully cracking encryption.  However, likely or unlikely, that event may be.

It will be just like many of the others (possibly worse in some respects, but probably not, as Quantum computers, would probably take time, to become useful/effective hacking/cracking tools, just like most other new technological developments), in the long list of computer (security) vulnerabilities.

E.g. The following link, seems to say it has 154 pages, of them:
https://en.wikipedia.org/wiki/Category:Computer_security_exploits

Such as:
Quote
Row hammer
Buffer overflow
Drive-by download
Prompt injection

But there have been, hundreds, or thousands, or even many more than that.

So if it happens, we all just get to see it fixed in the various software (and/or hardware) updates/fixes.

Of course, in the ideal world, these issues, would have been fixed and/or not possible and/or accounted for, well before product launch.  E.g. By having much better encryption, and much more powerful testing for vulnerabilities.

But, in practice, just-good-enough, so get the product out of the door, and move on to the next one, seems to be the way many things are done.
« Last Edit: February 15, 2025, 06:16:11 am by MK14 »
 

Online peter-hTopic starter

  • Super Contributor
  • ***
  • Posts: 5990
  • Country: gb
  • Doing electronics since the 1960s...
Re: What is "quantum safe"?
« Reply #37 on: February 15, 2025, 07:23:25 am »
The other thing is that, if needed, RSA/EC can easily move to 16k or 32k bits. Already, most serious applications use hardware acceleration for this.

But it will for ever remain the case that IF somebody finds a way to rapidly factorise, that's the end. So I reckon there will be a move towards crypto which doesn't have this potential weakness.
Z80 Z180 Z280 Z8 S8 8031 8051 H8/300 H8/500 80x86 90S1200 32F417
 
The following users thanked this post: MK14

Offline golden_labels

  • Super Contributor
  • ***
  • Posts: 2438
  • Country: pl
Re: What is "quantum safe"?
« Reply #38 on: February 15, 2025, 07:40:46 am »
Nobody is “obsessed.” This is a reaction to a potential vulnerability, which can be easily avoided. It’s a steady process of improvement, no different than the normal moving away from older cryptographic primitives in favor of better ones. We do this all the time and usually at much faster pace and more radical push than it is with post-quantum cryptography.

Please don’t confuse alarmist articles in news with reality of what the computer security world does.

GCM became the preferred mode and thare was (and is) a strong push for AE(AD). Journalists failed to comment? Nobody cared, nobody seen that as “obsession,” you probably don’t even know the change did happen and your browser and most other TLS clients now use GCM.

Forward secrecy became the norm or even a requirement. Journalists failed to comment? Nobody cared, nobody seen that as “obsession,” you probably don’t even know the change did happen, your browser now prefers it, and some sites will not let you connect with non-FS choices.

ECC certs are now offered as something normal, and preferred where possible. Journalists failed to comment? Nobody cared, nobody seen that as “obsession,” you probably don’t even know if the site you connect to uses RSA or ECC.

OCSP stapling becomes a default built-in in servers? Journalists failed to comment? Nobody cared, nobody seen that as “obsession,” you probably don’t even know about its introduction and can’t tell if it’s in use for your connection.

People 30 years ago noticed there is a potential problem. It affects something that already had foundational issues since the inception. The industry and academia, now two generations of people, slowly work towards finding a better solution. Journalists comment from time to time? Suddenly everybody has strong opinions. :(

I don’t know everything, and my brain also can’t process questions requiring enumeration. But I can’t come up with a single example of any other change in modern cryptography, that would take longer, be slower and less exciting, than the walk towards PQC. Even (general) homomorphic crypto is hotter.


« Last Edit: February 15, 2025, 08:12:57 am by golden_labels »
Why 📎 | We live in times when half of people have IQ below 100.
 
The following users thanked this post: Siwastaja

Online 5U4GB

  • Super Contributor
  • ***
  • Posts: 1734
  • Country: au
Re: What is "quantum safe"?
« Reply #39 on: February 15, 2025, 08:41:37 am »
OCSP stapling becomes a default built-in in servers? Journalists failed to comment? Nobody cared, nobody seen that as “obsession,” you probably don’t even know about its introduction and can’t tell if it’s in use for your connection.

OCSP, and more generally the whole concept of blacklist-based "security", never worked, being the #1 and #2 dumbest ideas in computer security, which is why browsers stopped paying attention to it and major CAs like Let's Encrypt are shutting down their OCSP servers.
 

Offline golden_labels

  • Super Contributor
  • ***
  • Posts: 2438
  • Country: pl
Re: What is "quantum safe"?
« Reply #40 on: February 15, 2025, 10:30:47 am »
Not sure, how the current status of OCSP relates to how people reacted in the past. Even less clear, given I wrote about stapling, but the reply confuses it with clients’ OCSP requests.

But let’s continue, because the reply is somewhat misleading.

Word “blacklist” when describing OCSP has a different meaning than when used in criticism of the “default allow” security. We can’t connect two things simply because the same sequence of letters may appear in their descriptions. There has to be conceptual equivalence. In this case it’s missing. The “default deny (and whitelist)” and “default allow (and blacklist)” approaches are the base security. It’s the mandatory part. If we do that wrong, we don’t have security. And we now know, that a wall can’t be built by putting bricks where the enemy is seen. But OCSP is supplemental security. If we do that right, we get extra protection, but if it doesn’t work, nothing is lost. The use of blacklisting was never criticized,(1) when it’s about those additional solutions.

OCSP is now phased out. But you made it sound, as if the motivation was to remove it due to the “blacklisting” part. Not only it’s not among the reasons, but in fact it’s opposite: it’s being replaced by another blacklisting solution (CRL). It’s also OCSP, not OCSP stapling. The latter is removed not due to any weakness. It goes away because verifying OCSP stapling has lower share among clients than CRL. And — with client OCSP gone and CRL in place — running the service would be wasteful.


(1) Not for its weakness at least. There are other reasons, like being unneeded or poorly executed.
Why 📎 | We live in times when half of people have IQ below 100.
 

Online 5U4GB

  • Super Contributor
  • ***
  • Posts: 1734
  • Country: au
Re: What is "quantum safe"?
« Reply #41 on: February 16, 2025, 07:20:51 am »
OCSP is now phased out. But you made it sound, as if the motivation was to remove it due to the “blacklisting” part. Not only it’s not among the reasons, but in fact it’s opposite: it’s being replaced by another blacklisting solution (CRL).

I was referring to the general concept behind how is-it-valid-now checking is done for certs, which is "this certificate is good unless you hear otherwise", which is default-allow.

In terms of CRLs replacing OCSP, first there were CRLs, which didn't work, so they were replaced by OCSP, which didn't work, so now they're being replaced by CRLs again.  They're still not going to work, which is why many CA's are going to short-lived certs (which also don't work) and then there's also CT, which seems to be the only thing that has a hope of working but also completely defeats the point of certificates since if you're going to do an online query to a CT log you don't need signed certificates and chains of trust and whatnot any more.

CT is actually going back to the original 1970s concept for validity checking where you do an online query to check whether the thing you've got is OK.  Since this would have required dropping the X.25 virtual circuit you were on to do the lookup, Loren Kohnfelder came up with the concept of certificates to avoid the online lookup.  And we've been stuck with this half-century-old offline view of things in an entirely online world ever since.
 

Offline golden_labels

  • Super Contributor
  • ***
  • Posts: 2438
  • Country: pl
Re: What is "quantum safe"?
« Reply #42 on: February 16, 2025, 10:04:46 am »
I was referring to the general concept behind how is-it-valid-now checking is done for certs, which is "this certificate is good unless you hear otherwise", which is default-allow. (…)
No, it is not.(1) And I already explained that in the post to which you reply.

Security of certificates doesn’t depend in a slightest way on OSCP (or CRL). It depends entirely and completely on the cryptographic features and the secret remaining secret. There is no other factor involved, OSCP, CRL, or otherwise, blacklist, whitelist, or otherlist. The principle is no different than that found in symmetric cryptography, ancient ciphers, or even argots.(tabA)

But since there is a secret, there is a problem: the secret may leak.(2) What then? For this an additional mechanism is provided. It’s not a part of the original cryptography. It is addressing a separate issue. For certificates the mechanism is to allow key owners to announce the key has been compromised. CRLs, OCSP requests, and OCSP stapling are how it’s announced. But, I repeat: the cryptography and its security doesn’t depend on those at all. It’s supplementary. Which is also why OCSP requests failure treatment was considered a thing to improve, but never a critical vulnerability. It’s an extra chain placed around Fort Knox.



(1) Not without widening the meaning of “default-allow” by so much, that it unavoidably renders entire cryptography useless. Which would be absurd.
(2) From population/policies perspective “may” is replaced with “will.”

(tabA) A short table depicting parallels. Quickly sketched, so don’t cite me on that:
Code: [Select]
,-------------------+------------------------+----------------+----------------.
| What              | Security feature       | Based in       | Secret         |
+-------------------+------------------------+----------------+----------------+
| Assymetric        | Secret-key encyption,  | Maths          | Private keys   |
|                   |  signatures            |                |                |
|                   |                        |                |                |
| Symmetric         | Symmetric block/stream | Maths          | Shared key     |
|                   |  ciphers, operation    |                |                |
|                   |  mode                  |                |                |
|                   |                        |                |                |
| Espionage (hist.) | Substitution           | Obscurity      | Codebook       |
|                   |                        |                |                |
| Ancient ciphers   | Substitution,          | Obscurity      | Pre-negotiated |
|                   |  scrambling            |                |  procedures    |
|                   |                        |                |  or numbers    |
| Argots            | Substitution, entry    | Obscurity,     | Argot          |
|                   |  barriers, murder      |  dissemination |  itself        |
|                   |                        |  delay         |                |
`-------------------+------------------------+----------------+----------------'
Why 📎 | We live in times when half of people have IQ below 100.
 

Offline coppercone2

  • Super Contributor
  • ***
  • Posts: 13719
  • Country: us
  • √Y√... 📎
Re: What is "quantum safe"?
« Reply #43 on: February 19, 2025, 07:11:48 am »
also a quantum safe hmm could you hide a atom in there?  so you can't find out what atom is in there without destroying it unless you know.. something



its like a really small mystery box? It should also be heavy so its hard for a nanobot to run off with it, it would get a quantum beating from security forces waddling around when its overloaded with a heavy safe
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf