Hacker News new | ask | show | jobs
by the8472 3548 days ago
that is assuming that there is no better quantum algorithm for aes specifically. grover's algorithm is only optimal if brute force search is the only possible approach and there are no other exploitable properties.

considering that there already theoretical attacks that (marginally) faster than brute force on classic computers who knows how much more one could squeeze out with quantum algorithms.

Of course those are fairly speculative concerns.

1 comments

It's very obvious how special structure exists in cryptosystems that use finite cyclic groups, such as in discrete log cryptosystems.

But in AES? that sounds unlikely and really unfortunate.

I think it's more likely that large quantum computers would aid in mathmatical exploration that uncovers currently unknown vulnerabilities that could be exploited by classical systems.