I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.
Sayrus 2 hours ago [-]
It really depends on the market you are targeting and your threat model. If your threat model allows future decryption of the data by a passive listener, then you don't need to rush for PQC. If you are worried about your communications being archived for future decryption, then you need to deploy PQC now even if QCs aren't developed for decades (or ever).
The assumption that you care about this is baked into ANSSI certifications, otherwise you would usually not bother certifying your product. They warned in 2022 that they would do this (See Phase 2: https://messervices.cyber.gouv.fr/guides/en-anssi-views-post...) and will allow PQC-only algorithm no earlier than 2030.
jmward01 1 hours ago [-]
You prepare for the 9.0 earthquake that can happen once in 500 years because it is a 9.0 earthquake and if you haven't prepared your society is dead, not because you think it will most likely happen in your lifetime.
plopilop 4 minutes ago [-]
Y2K devs had it easy, they knew the bug would arrive and when.
The problem with PQC is not that nobody knows when a CRQC (cryptographically relevant quantum computer) will appear, but that by the time it appears, you are already ~10 years too late for migrating (5 years of migration time and 5 years of your adversary silently storing all your classical crypto messages to decrypt them at a later time, the "harvest now decrypt later" attack).
Of course the HNDL attack is only relevant for the most critical pieces of infrastructures, 99% of companies are not a real target for that, especially given the storage cost of such an attack.
There is also the "trust now, forge later" attack, in which a CRQC could break a chain of trust (i.e. digital signatures), and that attack does not need any storage besides the logs of past messages. If you want to guarantee authenticity and unforgeability of your logs for, say, 20 years, you better hope that no CRQC appears by 2050 at least. Once again, it only concerns maybe 1% of companies.
But hey, these 1% companies are exactly the ones that are needing specialised crypto equipment so the move from ANSSI tracks.
I personally do not believe a CRQC will appear before 2050 either. I am willing to bet some money on it, despite researchers in quantum computers being quite confident it will appear in the next 15 years, but I am not willing to bet the entirety of Internet security on it.
kibwen 5 minutes ago [-]
Ironically, given that the primary use case for developing quantum computers is breaking classical encryption, switching en-masse to post-quantum schemes may very well ensure that developing a working quantum computer may never be economically viable to develop.
ErroneousBosh 36 minutes ago [-]
> by 2050 when, my bet, there still won't be any remotely viable QCs
I hate to be that guy, but I'm 52 now and I've been hearing about how Quantum Computing is going to revolutionise everything in the next two years, since I was in primary school and ZX81s were state-of-the-art.
At least a couple of manufacturers offered a practical and afforable(-ish) transputer-based system in the 80s that you could have actually gone out and bought.
ginko 18 minutes ago [-]
Transputers have nothing to do with quantum computing. They're completely classical computers.
exmadscientist 2 hours ago [-]
Agreed. This looks from the outside like someone read a report, got unnecessarily spooked, and now the rest of the herd is following along.
But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it.
However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I don't have any particular recent expertise to support that, but I did used to share an office with some serious QC people and go to their talks so... make of my words what you will.
exmadscientist 10 minutes ago [-]
Would anyone downvoting care to explain? I'm genuinely interested in seeing anything that suggests there's either some secret breakthrough (completely plausible, but there's no evidence that I've seen hint of) making quantum computers actually useful, or an argument that they'll be usable by (say) 2050?
Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just why 15 was factored in that famous run of Shor's algorithm and not, say, 21; and why 21 hasn't been factored yet and isn't likely to be any time soon....
colmmacc 55 minutes ago [-]
I was at ANSSI headquarters last year doing a technical presentation and several of their questions were about Post-Quantum Cryptography, "Q day" (when a practical Quantum Computer is expected) and other related things. They keep a close eye on this stuff and it's to their credit. Similarly the BSI in Germany have been promoting Post-Quantum security for some time now.
I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!
The assumption that you care about this is baked into ANSSI certifications, otherwise you would usually not bother certifying your product. They warned in 2022 that they would do this (See Phase 2: https://messervices.cyber.gouv.fr/guides/en-anssi-views-post...) and will allow PQC-only algorithm no earlier than 2030.
The problem with PQC is not that nobody knows when a CRQC (cryptographically relevant quantum computer) will appear, but that by the time it appears, you are already ~10 years too late for migrating (5 years of migration time and 5 years of your adversary silently storing all your classical crypto messages to decrypt them at a later time, the "harvest now decrypt later" attack).
Of course the HNDL attack is only relevant for the most critical pieces of infrastructures, 99% of companies are not a real target for that, especially given the storage cost of such an attack.
There is also the "trust now, forge later" attack, in which a CRQC could break a chain of trust (i.e. digital signatures), and that attack does not need any storage besides the logs of past messages. If you want to guarantee authenticity and unforgeability of your logs for, say, 20 years, you better hope that no CRQC appears by 2050 at least. Once again, it only concerns maybe 1% of companies.
But hey, these 1% companies are exactly the ones that are needing specialised crypto equipment so the move from ANSSI tracks.
I personally do not believe a CRQC will appear before 2050 either. I am willing to bet some money on it, despite researchers in quantum computers being quite confident it will appear in the next 15 years, but I am not willing to bet the entirety of Internet security on it.
I hate to be that guy, but I'm 52 now and I've been hearing about how Quantum Computing is going to revolutionise everything in the next two years, since I was in primary school and ZX81s were state-of-the-art.
At least a couple of manufacturers offered a practical and afforable(-ish) transputer-based system in the 80s that you could have actually gone out and bought.
But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it.
However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I don't have any particular recent expertise to support that, but I did used to share an office with some serious QC people and go to their talks so... make of my words what you will.
Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just why 15 was factored in that famous run of Shor's algorithm and not, say, 21; and why 21 hasn't been factored yet and isn't likely to be any time soon....
I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!
You mean the opposite. PQC-free will be blocked, so by 2030 all products will be PQC qualified.