Hacker News new | ask | show | jobs
by timmb 476 days ago
Post quantum - as in designed to resist quantum computer based attacks under which rsa would quickly crumble. Why do you associate this with snake oil?
2 comments

It does sound a bit like the famous "military grade encryption" and it's equally (ab)used by snake oil salesmen.

I can't say anything about TutaCrypt's long-term effectiveness except that CRYSTALS-Kyber is touted as being at the forefront of post-quantum cryptography.

I wouldn't call it snake oil, but right now it appears quantum encryption cracking is only theoretical. I'm not sure how anyone can promise to mitigate attacks that haven't yet arrived.

Global Risk Institute... found that the majority of cryptography experts it surveyed believe quantum computers, more broadly, will be able to break anything encrypted with RSA-2048 within 24 hours within the next 30 years.

https://www.pcmag.com/news/chinese-researchers-reportedly-cr...

Most cryptography experts are probably not experts in quantum computers as well.

We already know the algorithm to break RSA with a quantum computer. We just don't have the hardware yet. Nobody knows when the hardware will be available but a lot of entities are working on it.

It's common in cryptography to mitigate attacks that are known but not feasible without further advances in hardware or algorithms. Nobody wants to wait until an attack is successful. That's why NIST is already working on post-quantum cryptography standardization:

https://csrc.nist.gov/projects/post-quantum-cryptography/pos...