The Register Home Page

back to article Quantum code breaking? You'd get further with an 8-bit computer, an abacus, and a dog

The US National Institute for Standards and Technology (NIST) has been pushing for the development of post-quantum cryptographic algorithms since 2016. "If large-scale quantum computers are ever built, they will be able to break many of the public-key cryptosystems currently in use," NIST explains in its summary of Post- …

  1. SVD_NL Silver badge

    Wonderful paper

    While it's not my field of research, so i can't comment on the scientific validity, that paper is the best laugh i've had in a while! A+ satire.

    > "Finally, we refer to a dog as “a dog” because even the most strenuous mental gymnastics can’t really make it sound like it’s a computer."

    Also in the footnotes:

    > "We use the UK form “factorise” here in place of the US variants “factorize” or “factor” in order to avoid the 40% tariff on the US term"

    1. b0llchit Silver badge
      Coat

      Re: Wonderful paper

      Now I'm really wondering how much El Reg is paying in tariffs all the time with its business importing and exporting letters and words.

    2. martinusher Silver badge

      Re: Wonderful paper

      Its restored my faith in academia...

    3. vtcodger Silver badge

      Re: Wonderful paper

      > "We use the UK form “factorise” here in place of the US variants “factorize” or “factor” in order to avoid the 40% tariff on the US term"

      Possibly true at the time of publication. However, the tariff changes quite frequently. As of the 1800GMT quote this evening it was either 167% or 13% or suspended until 2400 hours on Halloween depending on which source one chooses to believe.

      ======

      Nifty paper BTW.

      1. Remurkable1

        Re: Wonderful paper

        In other words, the three terms are in superposition and will need a two-bit quantum computer to collapse the wave state. (Or, since it is Halloween, we're talking spooky action at a distance.)

      2. SCP

        Re: Wonderful paper

        "factorize" is a perfectly cromulent British spelling (OED - prefers -ize to -ise). It is the spelling that the US prefers but it is not theirs alone. Not sure where the antipodean preferences lie - but if you want to make a protest I guess -ise is one way to do it.

    4. keithpeter Silver badge
      Pint

      Re: Wonderful paper

      Ethics comment in the footnote to page 11 is a classic of the genre.

  2. Jedit Silver badge
    Boffin

    Bullshit

    I grow increasingly convinced that every new development in computing is bullshit. People don't want to advance anything, they just want to find the exciting new buzzword technology or application that will let them be on the ground floor this time and make the big money. It's been going on since the dotcom bubble. Well, since the invention of money, probably, that being human nature, but that's the point where computer tech development seemed to switch focus from solving existing problems to creating "solutions".

    Perhaps I'm just getting old and cynical.

    1. NoneSuch Silver badge
      FAIL

      Re: Bullshit

      > But when n is a 1,024-bit or 2,048-bit number, finding two prime factors requires a tremendous amount of computational power.

      Which is why the NSA has more computing power then Twitter, Facebook and Amazon combined.

      Parkinson's Third Law of Computing: Encryption can only delay access to information.

      1. Wellyboot Silver badge
        Big Brother

        Re: Bullshit

        Indeed, any electronic based system has an indefinite secure lifetime before mere brute force will rip it apart.

        Any sensible1 bods trying to keep things secret from TLAs will use multiple layers, book code2 buried in gibberish3 and then send it via parcel mail as part of the packing for some bit of tat lost in the vast volume of tat flowing from a really big river... Until the TLAs find one part of the chain they can follow and you’re toast.

        Physical things requires physical intervention. until scanning gets to the resolution needed for reading a closed book via the microscopic differences in signal return between two different visual appearances.

        1 Luckily not that common among fanatics.

        2 trawl 2nd hand bookshops for out of print 1950s pulp, & duplicate

        3 see 2 preferably in foreign language

        did I hear a helecop...

        1. Fruit and Nutcase Silver badge
          Black Helicopters

          Re: Bullshit

          "did I hear a helecop..."

          One day, I woke up to the sound of a low flying Chinook. Curiosity got the better of me and looked up flightradar. From the track, they must have been doing some night time navigation exercise. Otherwise, it would have been a straight line to RAF Odiham

          1. MrBanana
            Black Helicopters

            Re: Bullshit

            I used to live near the Odiham fight path, and also Bourne woods where they do a lot of big movie filming. You have to get used to the sound of helicopters.

          2. Anonymous Coward
            Anonymous Coward

            Re: Bullshit

            I once heard a large blacked out helicopter going overhead and landing on Hampstead Heath... next morning the pages were full of pictures of Prince Harry falling out of a West End nightclub

          3. Anonymous Coward
            Anonymous Coward

            Re: Bullshit

            I lived for a short while near Basingrad, Chninooks were our regular Sunday morning alarm clock :-)

        2. keith_w

          Re: Bullshit

          Currently reading John Christopher's "No Blade of Grass", c1956, trade edition from 1975.

        3. ITMA Silver badge
          Devil

          Re: Bullshit

          " buried in gibberish"

          Finally - a real world use for the House of Lords. :)

      2. Arthur the cat

        Re: Bullshit

        Parkinson's Third Law of Computing: Encryption can only delay access to information.

        Sure, but if it stops the bad guys getting access to my bank accounts for a mere 100 years that's fine by me. Statistically my median life expectancy is 15-16 years(*), with about 5% chance of getting 30 years and 0% chance of getting more than 45. Probate takes < 2 years normally, so 100 years is more than 2 times longer than I need security for.

        As Bruce Schneier keeps reiterating, it's ridiculous talking about absolute security, you have to have a threat model. In reality malfeasance or incompetence by a bank employee is a bigger threat than cracked encryption.

        (*) If my GP or consultants are reading this, they'll be laughing.

        1. Fruit and Nutcase Silver badge

          Re: Bullshit

          Shouldn't you have 9 lives?

          Anyway, when the time comes, may you get to Heaven, half an hour before the Devil knows you are dead

          1. Arthur the cat

            Re: Bullshit

            Shouldn't you have 9 lives?

            I burned through 8 when young and ridiculous(*).

            Anyway, when the time comes, may you get to Heaven, half an hour before the Devil knows you are dead

            Thank you, but I'm not sure I'm temperamentally suited. The Imp of the Perverse is an old friend.

            (*) As opposed to the current old and ridiculous.

      3. Alan Brown Silver badge

        Re: Bullshit

        Not to mention that a rubber hose defeats many forms of encryption

        1. Andrew Scott

          Re: Bullshit

          rubber hose are used by cops who don't want to leave evidence, the people who want your crypto will use pliers on fingernails something equally bloody.

          1. Rustbucket

            Re: Bullshit

            No no, that's old style phone books.

    2. Rich 2 Silver badge

      Re: Bullshit

      I’m with you. it seems that there has been almost no genuine innovation or fresh ideas in the computing world (well, certainly in the software world) for decades.

      And the “innovation” that there has been seems to have the sole purpose of making money (no surprise there), making everything 1000% more complicated than it used to be (I’m thinking about most of the network and user management tools. Oh, and System Dunce), pointless (let’s make a shiny new “skin” for [add application of choice. And System Dunce]) or just plain shit (anything that MS vomit out. Oh and…).

      I appreciate I’m being nostalgic here but the days of Early PCs, Apple IIs, and the countless “home” computers around the same time seemed to show massively more invention and clever thinking than anything else over the last 20 years - they were genuinely exciting times. And all without requiring gigabytes of memory to print “hello world”

      1. Ace2 Silver badge

        Re: Bullshit

        Yeah, well, I can netboot a server I’ve never even seen to install a new OS image, whether or not the current one panics on boot. Some things have improved 10X.

        1. that one in the corner Silver badge

          Re: Bullshit

          Network booting has been available since the 1980s, when it was useful as a way to save money - give your computers a netboot-capable NIC (which could mean buying the BIOS-extension ROM to plug into the card) and then let it boot from an OS image on the one machine on the LAN that hard a hard drive.

          Changing the OS image just needs a settings tweak on the OS server and then reboot the remote - which could be (can be) done in any of a number of ways, depending upon what is running on the remote computer (e.g. just log in via telnet and issue a shutdown -r or have the remote poll for a reboot command or - just wait 'cos it'll crash every 20 minutes anyway and the watchdog will bring it back up).

          > Some things have improved 10X.

          If that were true for netboot then we would all have a really easy way to set it up for everyday use in every situation, whereas we seem to be more wed to every computer having its OS on its own drive than ever before. Yes, some IT departments can set it up, but by now the advantages of having every PC in the office loading a fresh, uncorrupted, totally up to date, copy of The Company OS Image should be seen everywhere. It should have long ago become so easy that every school used it by default.

          Although, as we're now all meant to be "doing it in the cloud", and those are just VMs booting from a prepared image...

          1. David Newall

            Re: Bullshit

            I think you know that "netboot" was meant as "network power switch, cd drive, keyboard, video, mouse". No amount of watchdog timer is going to let you turn the power on remotely, insert a CD, go into BIOS setup and change some settings, boot the CD, run the text or graphical setup program using keyboard and mouse, configuring even the network interface.

            1. that one in the corner Silver badge

              Re: Bullshit

              You are describing IPMI and its ilk (I'll just use IPMI as a blanket term) or the use of a hardware KVM-over-IP, not netboot. If you don't like using the name of a specific implementation, just use "IP KVM" or similar, rather than usurping "netboot". After all, a decently run render server farm will be using netboot as well as a KVM, IP or otherwise.

              Oh, and (actual) IPMI is at least 25 years old, so falls outside of the "some things have got 10x better (within the last 20 years)" claim. And that is just when it is integrated into the main chipset. Bolting an extra computer onto the side of the bigger one, in order to control the latter, is older still: if you needed it, it was available back in the 1980s (at least) as well. So even PiKVM etc are just the current versions of the Old Ways.

    3. Al fazed
      WTF?

      Re: Bullshit

      I agree with you all the way to the end, where I'd like to add:

      it seems now that they are also creating the problems.

      They have perhaps discovered the UK's (secret) Economic Policy. That there's more money to be made fighting ghosts in the future machine, by selling solutions to problems which don't yet exist.

      Really clever shit........

      ALF

      1. Jedit Silver badge
        Thumb Up

        "it seems now that they are also creating the problems."

        Well, yes. If your entire business model is selling ninja repellent, then your business will collapse as soon as people realise there aren't any ninjas. To avert this, there are three paths:

        1) Convince people that the repellent is working really well and that's why they haven't seen any ninjas.

        2) Convince people that they haven't seen any ninjas because ninjas are extremely stealthy and that's why you need the repellent.

        3) Found and train a ninja clan and kill a few doubters to set an example.

        However convincing you are, sooner or later 1 and 2 will both lead to your market realising that they're being fooled. By which time you'd better be far, far away. The typical conman recognises this. But many techbros fall for their own scam and believe they actually can make a working product. And when they can't, they have to try creating a problem that it can fix.

        1. Guy de Loimbard Silver badge
          Pint

          Re: "it seems now that they are also creating the problems."

          Good sir/madam, please have a pint for your japery ==>

          I do love a well constructed and artistic piss take of the tech bro stack we're surrounded by now.

          As for ninjas, where did I leave my sword, shuriken and sneaky attire????

        2. Ian Johnston Silver badge

          Re: "it seems now that they are also creating the problems."

          s/ninja/Y2K\ bug

        3. Alan Brown Silver badge

          Re: "it seems now that they are also creating the problems."

          "But many techbros fall for their own scam and believe they actually can make a working product. And when they can't, they have to try creating a problem that it can fix."

          This is also a decent summary of USA foreign policy for the last 140 or so years

      2. Tron Silver badge

        Re: Bullshit

        The UK doesn't have an economic policy. They are just winging it, week to week.

        Add to Quantum code breaking, nuclear fission, AI that is really AI and honest politicians.

        And yes, we haven't seen much innovation in computing since the blu-ray disk and 3D printer. Everything else has just been a speed/bandwidth bump. We could be using 15 year old computers if GAFA didn't force OS upgrades on us, and for anyone daft enough to subscribe to SaaS webware, 25 year old systems or dumb terminals.

        When tech companies get to a certain point, the innovators cash in and put their feet up. They are replaced by off-the-shelf corporate types who want a quiet life and a big bonus. Innovation dies. Companies are led by lawyers. Maintaining the status quo is just easier. Hence we haven't made the next gen shift to distributed systems, where we could have had an entirely new computing revolution.

        What we are using now is just getting worse. If anyone out there has a few quid, we could go back to the basics of computing and rebuild - a new OS, simpler and more resilient, legacy file format compatibility for uptake, protection from hacking built in by restricting access to system internals from networks, and none of the walled garden crap that GAFA use as a weapon. There would be a world of innovation and new stuff that we could build, including distributed software, distributed DNS, distributed social media and other services, ad hoc networking, and the like. Clustering on retail systems with plug-in processor boards. Self-adaptive processors.

        1. Long John Silver Silver badge
          Pirate

          Re: Bullshit

          Wise words, indeed.

          Taking forward the theme of corporate sluggishness and complacency after the entrepreneurs have left (e.g. BOEING, Microsoft, Apple, and Intel), suggests rethinking the respective roles of market-capitalism and of public/private ownership.

          For instance, Richard Wolff (the prominent Marxist economist), someone to whom I listen with interest, advocates industry and commerce being placed into ownership by workers' co-operatives. I profoundly disagree with that, if it is posed as a blanket solution to many present day ills.

          However, I consider it a sensible imposition on companies which have passed their stage of innovative fervour, and now mostly churn out 'widgets' (or software) into well-established markets. The supposed 'democracy' of co-operatives works in that context, despite 'democracy' overall being an agency for maintaining an unimaginative status quo in the interests of powerful, mainly self-seeking, individuals.

          Yet, we must look to imaginative entrepreneurs, people willing to place their own skin in the game, to seek new opportunities for productive enterprise; albeit under well-regulated market-economics instead of its debased current ethos enshrined in neoliberalism and the psychotic thinking of the late Ayn Rand.

          Taking further the matters raised in your final paragraph, yes, there is the potential for global intellectual/commercial renaissance. A key enabling factor will be the removal of ideas, and the means to further them in practical applications, from walled-gardens: abandon so-called 'intellectual property' (IP) and replace it with entitlement to attribution. The collapse of IP and rentier economics is already in progress: it largely the result of technological advances involving the digital representation of data and their ready access via the Internet. BRICS will hasten the economic revolution. Cottage industries shall replace behemoths, and thrive.

          1. et tu, brute?

            Re: workers' co-operatives

            Could be a solution... do away with faceless shareholding, and workers own the shares in the company, so they are the ones deciding the dividends (to be paid to themselves) and the size of the CxO bonus (i.e. boss does a shitty job, sorry no bonus, or boss did a good job, okay, you can have a bit of a bonus)

            1. Arthur the cat

              Re: workers' co-operatives

              I think you've just reinvented partnerships.

            2. keithpeter Silver badge
              Windows

              Re: workers' co-operatives

              My understanding (which may be wrong) is that worker coops are less tax advantageous than a charity owning a company model. Changes to tax laws that make cooperatives more viable would I think be an excellent idea.

              Example: GreenNet (trigger warning: left wing - but similar structures used for all kinds of organisations)

              https://www.greennet.org.uk/about

              No connection with GreenNet or APC these days, was a customer before Millennium.

        2. Ian Johnston Silver badge

          Re: Bullshit

          My daily driver is a 2010 Lenovo Thinkcentre running Linux Mint. It does everything I need, as fast as I need.

      3. Anonymous Coward
        Anonymous Coward

        Re: Bullshit

        You are just 're-discovering' the oldest game in the house. [Paranoia Part 1 & 2]

        Convince the person at the top that there is a 'risk' to the person staying at the top.

        The 'Risk' is complicated and hard to explain BUT in a nutshell the 'unknown' enemy is working on a 'Wonder Weapon' that will be able to discover all your secrets !!!

        The only defense is to work HARD to create an even harder to crack method of hiding ALL your secrets !!!

        BTW to defend yourself in the meantime, while you create your EVEN BETTER SECRET HIDER, create something that will make your CURRENT secrets harder to get at by the 'Wonder Weapon' !!!

        This paranoia will enable HUGE spending on bigger & bigger toys to KEEP the SECRETS HIDDEN !!!

        [Anything 'AI' can do I can do BETTER !!!! :) KERCHING !!! ]

        :)

    4. Mahhn

      Re: Bullshit

      Reason I agree. I have been a PC gamer since Quake shareware. Bought at least every other generation of video card. All the promises of better graphics with lower power use hasn't happened. It does get faster, but still needs to much power. 4 generations of cards while QC is out, Every card took more power, and small improvements in performance. Not enough to make up the power consumption. And they are only BIGGER cards, should be half the size.

      More power, takes up more room, minor performance increase. Same across all computing except MS, it has gotten slower and slower performance. Office is now the slowest version ever. It even worked better in the '90's. 35 years ago!!! Thats how bad tech is.

      1. David Newall

        Re: Bullshit

        I'm reading your words on my rather inexpensive, Chinese made smartphone, which runs for days on a single, two-hour charge, producing glorious images that were unimaginable outside of a glossy magazine when Quake was new.

    5. Anonymous Coward
      Anonymous Coward

      Re: Bullshit

      You are "old and cynical" and 100% spot on !!!

      Welcome to the Club !!!

      :)

    6. mcswell Bronze badge

      Re: Bullshit

      "Perhaps I'm just getting old and cynical." I resemble that remark!

      And to everyone else, get off my (our) lawn(s).

    7. Anonymous Coward
      Anonymous Coward

      Re: Bullshit

      ... just getting old and cynical.

      Maybe ...

      While I don't consider myself to be old* I have been considered cynical from around age 5.

      And also opine the same as you.

      Yours is the definition of the basic workings of the Bullshit Generation Machine©.

      * ongoing contentious issue with prostate, knees and 50+ year old females.

      .

    8. druck Silver badge

      Re: Bullshit

      I've been calling out the Quatum bull for years. My worry is the PQC snake oil salesmen are getting people to substitute unproven and insecure algorithms, instead of bumping up key sizes of things we know work today.

  3. Anonymous Coward
    Anonymous Coward

    Huh?

    But how are we going to convince people to give us gazzillions of dollars to replace all their existing kit and algorithms if there's no burning platform????

    - Anonymous Qbit sales manager

    1. Caver_Dave Silver badge
      Unhappy

      Re: Huh?

      Ask Microsoft - they seem to be managing the replacement requirement very well at the moment.

    2. Al fazed
      Devil

      Re: Huh?

      Scare the shit out of them.

      That usually works.

      It has since Roman times at least.

      ALF

  4. Anonymous Coward
    Anonymous Coward

    Discredited Gutmann

    So another paper from the same Peter Gutmann who back in the days already discredited himself by writing papers full of nonsense about Windows Vista, Microsoft's upcoming Windows version at that time.

    And he subsequently admitted he did so without even using the specific operating system in question himself, despite it being available at least as public beta version at that time.

    I'm sure there is much to criticise with all the claims around quantum computing, but I'm not sure a borderline fraudster is the best person to do this.

    1. Anonymous Coward
      Anonymous Coward

      Re: Discredited Gutmann

      Harsh. You may be more familiar with his work than I am, but I found his paper (essay? collection of notes?) on X.509 in practice very useful.

      I’m anon because although we recently implemented PQC in a product and we’re hoping for a press release from industry partners fairly soon, so I have a dog on this fight. But I don’t disagree with him.

      PQC is fairly easy for an engineer; we found ML-DSA a drop in replacement for RSA or EC, albeit with a much bigger signature size. But it’s not a magic bullet and a lot of the things I would like to focus on are the deeply unsexy parts of crypto; plugging holes in implementation and process. It’s harder, less rewarding but vastly more useful than PQC on the short term and mid term. But we can’t ignore the long term either, so PQC research needs doing too.

      1. Al fazed
        Happy

        Re: Discredited Gutmann

        But if the adversary is already on the machine, software or hardware, any type of encryption is not going to provide the secrecy you are looking for.

        Stenography is the only thing that I have found which actually works, as long as you don't give the recipient the info via eMail or text, etc.

        ALF

        1. Androgynous Cupboard Silver badge

          Re: Discredited Gutmann

          Whatever use case you have for steganography would probably be fun to describe, but not useful in practice. It’s not going to help you secure comms with your bank or digitally sign a contract.

        2. Throatwarbler Mangrove Silver badge
          IT Angle

          Re: Discredited Gutmann

          Stenography or steganography? While hand coded ciphers using a one time pad would evade electronic decoding, it's rather time consuming for long messages. Conversely, I expect that steganography is bandwidth intensive. I guess you could combine the techniques and employ an animation studio to produce your encrypted messages.

        3. mcswell Bronze badge

          Re: Discredited Gutmann

          Most of the stenographers I know are retired.

      2. Anonymous Coward
        Anonymous Coward

        Re: Discredited Gutmann

        " so I have a dog on this fight"

        And presumably a VIC20 and an abacus ? :)

    2. ChoHag Silver badge
      Holmes

      Re: Discredited Gutmann

      Hmmm... Published paper, or AC?

      --->

      1. This post has been deleted by its author

      2. doublelayer Silver badge

        Re: Discredited Gutmann

        What difference does that make, given that the AC's allegations are verifiable? You could read the criticism of Windows Vista and criticism of that paper and decide what you think. Or you could decide that it's not relevant, read this paper on its own and related information, and decide what you think. But if your logic is that a published paper beats an AC, even when the AC is referring to other information you could find with a search (I had never heard of Gutmann before, but finding those links took at most thirty seconds), then it would surely beat a pseudonymous comment on a forum. Sometimes, comments on a forum can poke real holes in a paper. I'm not convinced that that happened, because the AC's post considered only the reputation of the researcher, not anything particular about the paper, but your rejection appears to be on an even worse basis.

        1. Throatwarbler Mangrove Silver badge
          Angel

          Re: Discredited Gutmann

          I internally assign each poster on this forum an informal reputation score based on what I've seen them post. Since a large number of ACs post bollocks, I mentally downgrade the reputation score of all ACs. This AC is also using an eighteen year old paper to discredit Gutmann's current reputation. The AC could have engaged with the Guttman's current paper and addressed his criticisms of quantum cryptography, but the AC chose instead to engage in questionable ad hominem reputation-bashing. I therefore think it's entirely consistent with the AC's own logic to discount its opinion out of hand since the opinion of most ACs is already suspect.

          1. doublelayer Silver badge

            Re: Discredited Gutmann

            I do that too, but before bothering with the internal reputations of posters, I consider the content of the post. In this case, what I consider is:

            1. No statements about this paper. Negative.

            2. Comments about something I've never heard of. I should look that up. I did.

            3. Comments seem at least somewhat justified. There do appear to be several problems with the Windows Vista paper. Positive.

            4. But, although they have some basis from that short check, they don't appear to have anything to do with this paper. Negative.

            Since an AC can be anyone at all, this provides me more useful information. You are effectively doing the same thing that the AC recommended. They recommend that we reduce our trust in Gutmann's latest paper because he did something wrong before, while you're discounting their views based on what others who have posted anonymously have gotten wrong before. Neither is a very convincing move, but if I had to choose, theirs is stronger because their reputation-based attack is definitely talking about the same person.

        2. vtcodger Silver badge

          Re: Discredited Gutmann

          There's also a Wikipedia article https://en.wikipedia.org/wiki/Criticism_of_Windows_Vista All in all, I'd say Gufmann comes off looking pretty good -- at least compared to his critics.

    3. DancesWithPoultry
      Stop

      Re: Discredited Gutmann

      Sir should quote Arthur C Clarke's 1st Law:

      "When a distinguished but elderly scientist states that something is possible, he is almost certainly right. When he states that something is impossible, he is very probably wrong."

      https://en.wikipedia.org/wiki/Clarke%27s_three_laws

  5. Long John Silver Silver badge
    Pirate

    Points too often forgotten?

    Encryption is reversible obfuscation.

    Given enough time, computing power, and patience, a pathway back to the original message (a sequence of binary digits straightforwardly representable as comprehensible text and/or images) will be found. This may take minutes or millennia. Unless the coding method, e.g. RSA public key encryption, is known, or drawn from a set of documented possibilities, each of which may be tried in sequence or on parallel machines, there is no obvious stopping rule for an attempted decryption other than obtaining intelligible text/images. Therefore, 'brute-force' decryption methods, necessary when the underlying logic of encryption is not pre-specified, require step-by-step scrutiny of results until the output is recognisable.

    'Brute-force' decryption entails human or algorithmic (e.g. an 'AI') input at every stage or, equivalently, scanning a long sequence of results. Even should clear text emerge, its import may be obscure because the sender of the message could have assumed the recipient had prior knowledge of context and intention.

    Also, regardless of the encryption algorithm - public or bespoke - there remains the time period during which the decrypted message retains practical or evidential use. For instance, on the battlefield, transmitted orders may require secrecy for minutes or hours, nothing more when the 'cat is out of the bag'; the fact of an encrypted, but not quickly decipherable, message being intercepted is the only guide for action by its unintended recipients. For other state and for commercial secrets, the essential timescale for secrecy may be longer but, even so, it's not indefinite; that is, unless the reputations of the people deploying secrecy will be at stake: perhaps a political lifespan or two.

    These considerations lead to the not often mentioned application of cost-utility and opportunity-cost for individuals and institutions engaged in eavesdropping.

    1. Guy de Loimbard Silver badge
      Alien

      Re: Points too often forgotten?

      Very well put Long John Silver.

      Encryption is useful for a period of time and that is, as your rightly say, variable by application.

      Having worked in various scenarios that utilize and require the use of cryptographic tools to secure information or data, the hardest thing to really measure, is the value of the information or data, or the expected loss, or impact, if the data or information was decrypted, therefore providing a scale to measure how far up the scale the chosen crypto standard needs to be.

      So, as always in government type applications and scenarios, just whack it up to the top setting, even if the info is only valuable for a few hours.

    2. LVPC

      Re: Points too often forgotten?

      >> unless the reputations of the people deploying secrecy will be at stake: perhaps a political lifespan or two.

      Today's politicians don't have any shame, that's just for us little people, because we're not powerful enough to get away with lies.

  6. Doctor Syntax Silver badge

    WHy does it need a dog? To provide the bollocks?

  7. IGotOut Silver badge
    Joke

    Quantum computing and Fusion is twenty years away...

    ...said Professor Bob in 1953, Dr Dave in 1973, Dr Susan in 1993, Professor Gurjit in 2003.....

    1. Anonymous Coward
      Anonymous Coward

      Re: Quantum computing and Fusion is twenty years away...

      They will need QC to do the billing for the Fusion utilities. :)

      Ironically I suspect the one thing QC will probably never be used for, if it's used for anything, is cryptoanalysis.

      1. Jaybus

        Re: Quantum computing and Fusion is twenty years away...

        Billing aside, QC may well be needed to do fusion at all. Richard Feynman proved that molecular, and particularly atomic, modeling is fundamentally impossible to implement using a Turing machine, meaning a non-quantum computer cannot model a quantum system.

    2. Anonymous Coward
      Anonymous Coward

      Re: Quantum computing and Fusion is twenty years away...

      Oh, they last said that just about 20 years ago?! Should be here any day now!

      *waits*

      1. bernmeister
        Facepalm

        Re: Quantum computing and Fusion is twenty years away...

        The same for many other things, sometimes the time scales are even shorter. Li-ion battery performance increases are a good example. The optimism of some researchers seems to be boundless. I cant even spell "optimism" without using a spell checker.

    3. Brewster's Angle Grinder Silver badge

      It's all bollocks till it's not.

      They used to say that about AI, too. And whatever it's limitations, it's clear we've had a major step change in capabilities.

      1. David Hicklin Silver badge

        Re: It's all bollocks till it's not.

        > it's clear we've had a major step change in capabilities.

        Yeah, they built huge, humongous power eating DC's full of hardware to run the LLM's - in other words they brute forced it for AI

      2. Jaybus

        Re: It's all bollocks till it's not.

        There is no doubt that Shore's algorithm will work to significantly reduce the number of iterations needed to factor a large number. If someone manages to create a quibit that actually works reliably, then QC will suddenly go from bullocks to ubiquitous and Prof. Gutmann's paper will seem even funnier, perhaps ranking with early 20th century mockery of Prof. Einstein's relativity..

  8. Anonymous Coward
    Anonymous Coward

    Probably true, but meanwhile

    The UK NCSC is insisting that folks who run CNI systems implement PQC. And yes it is using up a lot of time, discussion and effort.

    1. Displacement Activity

      Re: Probably true, but meanwhile

      The threat to cryptography from future large-scale, fault-tolerant quantum computers is now well understood.

      I love it. And here was me thinking that the actual threat to CNI was some dork leaving their net-connected RPi in my local electricity substation. Or Cisco. Or everyone putting their bank logins on their mobile phones. Or whatever.

      1. Doctor Syntax Silver badge

        Re: Probably true, but meanwhile

        Of course the threat well understodd. In theory. It's just the practicalities that are proving harder.

  9. Anonymous Coward
    Anonymous Coward

    Fusion

    Quantum Computing seems to be replacing fusion as the saviour of mankind. "Soon it'll be useful". I think "AI" will overtake it but not sure where AI is on the original mathematics front? Probably nowhere and until it can create original mathematics or truly original leaps in anything some humans will remain useful. But it's likely to get very good at optimising. Shouldn't we stop calling it AI and call it Simulated Intelligence? I did read some thought provoking stuff that speculated our innovation of thought arises from quantum effects in our brains. Don't think there was any strong evidence though. Anyone for LLMs with a sprinkling of quantum?

    Maybe evolution got it right with organic computing but illogically there will be more horror and outcry about man-made organic intelligence than silicon. But if it actually is self-aware and feels pain or distress, is there a difference. As for metallic quantum - another money pit without minimal return?

  10. Torben Mogensen

    Agree

    I recently saw a presentation about quantum algorithms. Basically, quantum computers use two operations: Rotation of a single qubit in a Bloch sphere (surface described by two unit-length vectors of complex numbers) and entanglement of two qubits, usually by a controlled negation.

    To factorise an n-bit number, you need rotations to be precise to 1/2^n of a full rotation. So to factorise 15, a 4-bit number, you need rotations that are precise to ca. 22 degrees, which is doable with today's technology. But to factorise a 1024-bit number, you need rotations to be precise to 1/2^1024, which is 1/499359204128421085480362552996951314893882494150640714648416892104812988348613786479745770340020933392000316332976092660163304913373379506924576196220761456604910815069070792434172832225683594776258563755791682691217085228729063559649758640391186769898195863012739717333186794273554767513431545360067289270 degrees. Do you believe that will ever happen? I certainly don't.

  11. Will Godfrey Silver badge
    Meh

    Pah!

    Over the last 60+ years I've lost track of all the fantastic {cough}scientific{cough} advances that were going to revolutionise our lives.

    To quote Joshua: "Strange game. Only way to win is not to play"

    1. Alan Brown Silver badge

      Re: Pah!

      The number of projects which have failed between laboratory demonstrator and commercialisation are beyond couting

      Even worse is when the laboratory demonstrator is used as-is and scaled up (water moderated nuclear power) whilst research into a commercial version gets shitcanned (LFTR)

  12. bernmeister
    Facepalm

    Puzzled

    I have searched for the purpose of the abacus and dog but could not find it. I understand the VIC-20 bit and have used it myself for simple code cracking.

    1. Will Godfrey Silver badge
      Boffin

      Re: Puzzled

      The dog pissed on the abacus which engraged the mad professor. He then immediately designed an encrypted door lock to prevent the animal from returning. Unfortunately (being also absent minded) he forgot the password so is working on quantum mathematics to crack the combination. He is currently debating whether it would be quicker and simpler to invent a time machine to back to when he set the lock.

      Simples, Eh?

    2. vtcodger Silver badge

      Re: Puzzled

      Looks to me like the abacus + dog are used to show you don't even need an electronic computer to factor the numbers QC has managed after a quarter century of effort. Presumably the next quarter century will show further improvement.

      See the post by Torben Mogensen (above) for an idea just how great an improvement might be needed before crypto codes are actually at risk of compromise.

    3. award

      Re: Puzzled

      and is the breed of dog important?

      Can a Border Collie factorize numbers faster than an Afghan Hound?

  13. StewartWhite Silver badge
    Flame

    "We currently have a multibillion-dollar global cybercrime industry that's built on the failure of encryption to provide the protection that it's supposed to..."

    There's a reason why current cybesecurity is oftern rubbish. The vendors need it to be just about useful enough to prevent the most egregious of exploits but not good enough to deal with anything near 100% as if it were then the marks (sorry, customers) wouldn't be willing to shell our their $, £, € or Flanian Pobble Beads (sorry, can't find a symbol for that on my keyboard) on their expensive and unreliable tat. Goose, golden egg and all that.

  14. Excused Boots Silver badge

    "There's a reason why current cybesecurity is oftern rubbish [sic].....’

    Yes, it’s due to people. Even something as simple as ‘don’t blindly click on links in emails’, ‘don’t reuse passwords’, ‘always use MFA where possible’, is often ignored. The CEO who insists on using his or her’s dog’s name as the password on every single one of their accounts (while coughing up said name on every Social Media account known to man, the CEO who insists that everyone else uses 2FA but not him, or other really important people - because it’s too inconvenient. Of course any potential attacker will go for the account of the car park attendant rather than them, won’t they?

    Best practice, in the Windows world is to not work using an account with local admin privileges - oh the arguments that causes when the head of finance can’t install ‘random widget 2.6’ because his mate down the pub told him it was good!

    Now I do get it; lock everything down too much, yes you are better secured but the people can’t do their job, the software they need simply doesn’t work, the company suffers - there is a fine line to walk.

    But the weak link in the Cyber Security chain is and always will be the human sitting in front of the screen.

    1. Anonymous Coward
      Anonymous Coward

      Which Fine Line Is That?

      Quote: "....the weak link in the Cyber Security chain...."

      Assumptions Again!! There wouldn't be ANY CHAIN AT ALL if most work was done on an air-gapped workstation.

      Yup: connect to the internet if communication is needed....but is that REALLY "all the time....24/7"?? I think not!

  15. rskurat
    FAIL

    money train by any means necessary

    "Switching to PQC is just a distraction from having to fix the actual hard problem" - just like 'AI' LLMs, substitute a useless but do-able project for a useful difficult goal, because that keeps the money rolling in from the substandard minds in VC.

  16. Anonymous Coward
    Anonymous Coward

    Misdirection Upon Misdirection.....

    Ha.....encryption!!!

    (1) When bad guys have planted malware on the end point (NSO/Pegasus or Paragon/Graphite)....the bad guys can read everything IN PLAIN on the end point.

    (2) So all the noise about Signal or Telegram or WhatsApp DOES NOT MATTER in the least.

    (3) Then there's the noise about cracking RSA. Huh?? Protocols like Signal use a randomly created encryption key FOR EVERY MESSAGE.

    (4) So all the noise about "published key pairs" and about "key management" is just that....noise.

    (5) And the bowing and scraping about NIST.....this is the organisation which spends ALL ITS TIME trying to get people to use VERY WEAK protocols. Pass the sick bag, Alice!

    .....and now we have more misdirection to get the public to worry about quantum computing!!

    Plain text passed in a dead letter box..........and NO ONE AT ALL will know anything about the message.

    Wake up....smell the coffee!! Misdirection rampant........especially in ElReg!

  17. Atlantic Roller

    Factorising larger numbers

    I have a dog capable of factorising much larger numbers than Scribble is apparently capable of doing. I’m happy for her to assist, but I fear I would still be able to hear her barking all the way from New Zealand.

  18. Anonymous Coward
    Anonymous Coward

    As soon as they're finished migrating from 3DES to AES, the payment card industry will jump on the PQC bandwagon.

  19. QNFO.org

    Not bollocks at all, but the wrong words: "harmonic resonance computing" rather than quantum.

  20. Anonymous Coward
    Anonymous Coward

    More a job for mathematicians than programmers.

    The API to plug new public key algorithms into existing software is well established, once it's agreed a quantum computing resistant algorithm is needed. No one is going to upgrade stable software to a new algorithm until it's been thoroughly tested and standardised, having won at the open competitions that incentivised its development.

    If they build a QC with enough Qbits and low enough noise, a post quantum public key algorithm will be needed. One problem slowing things down will be the increased key size.

  21. NickHolland

    Encryption is good, but it isn't the answer.

    Let's pretend for a moment that Quantum Computers become a real thing, and RSA and friends become trivial to crack.

    From a real-world security standpoint: this probably won't be a big deal. Real data theft has historically not been accomplished by unlocking encrypted data, but by exploiting horribly designed software and poorly managed systems.

    Decryption of data will have to get crazy trivial before it becomes easier than guessing a bad password or exploiting a design flaw. Remember, you still have to get to the encrypted data to decrypt. In many cases, if you can get the encrypted data, there are easier ways to profit or create mischief.

    It would be very nice, in my opinion, if a small fraction of the effort put into so-called post-quantum cryptography went into writing good applications, eliminating bad applications, keeping systems up to date, and laying a beating on managers and sysadmins who do their job wrong. This will solve real problems that exist now AND will still exist if quantum computers become a real thing.

    Encryption is good. Good encryption is better. But it isn't the answer to computer security.

    Unfortunately, "didn't suck at my job" doesn't sound good as good as "Prepared for Post Quantum Cryptography" on a resume.

    1. doublelayer Silver badge

      Re: Encryption is good, but it isn't the answer.

      "Real data theft has historically not been accomplished by unlocking encrypted data, but by exploiting horribly designed software and poorly managed systems."

      Because and only because decrypting data is hard. I don't know whether quantum computing will make this trivial soon or ever, but let's assume it happened and review what would happen in that situation. Now, getting access to your traffic is easy if you use WiFi. Not my WiFi, any WiFi near which I can put an antenna. Or if you use mobile internet, or satellites, or a cable I can monitor. Those aren't major problems now because there are multiple layers of encryption on it, and even if I can crack your WiFi password from next door, I still need to break the HTTPS encryption before I can grab credentials. Not so if encryption is defeated.

      And it's not just copying data. Now that I know the keys, I can also impersonate things and intercept your communications. That's just thinking of me with the stuff I have near me. For someone with more power, like an ISP or government, this is dramatically different. They have the ability to collect a lot more encrypted data and ways to abuse it. They often don't because it's expensive. If it were made cheap or free, we'd get many more chances to see how badly it goes.

      Currently, encryption is like a strong lock. It often makes more sense to try to go around it because people have often not considered that it's not too hard to break a hole in a wall or lift a ceiling and climb over, so they might not have blocked you from doing that. Only when those have proven difficult do you start trying to get through the lock directly. If all secure locks were quickly degraded to those weak ones that get used on internal house doors, there's no need to test the ceiling when a paper clip can get you through that in five seconds.

      1. NickHolland

        Re: Encryption is good, but it isn't the answer.

        There's still a difference in attack surface.

        Back in the modem days, security basically sucked. But dial-up data breaches were infrequent because telephone calls cost money, so you weren't going to "war dial" long distance calls and rack up a charge for each and every failed login attempt unless you had some idea there was a pot of gold awaiting you in a small number of dial attempts.

        To steal information by decrypting it, you still have to get the encrypted data in the first place, which varies from "very local" (WiFi) to "not so local" (long-distance wireless), and often sitting in a place you don't belong...much easier to prosecute for trespassing than data theft. And difficult for North Koreans or russian attackers to get to at all.

        You are right -- you go through the barrier if least resistance. But I have seen little evidence of bad actors getting their hands on a big pile of encrypted data and saying "Blast! Our evil plan is foiled!". Just look at your source a little closer, you'll find the key sitting there in a file named "decryption-key" with world-readable permissions, it is pointed to by the script that starts the application. Oh, to live in a world where encryption was something people attempted to go around, rather than just a gate across a sidewalk, and nothing keeping you from going around it. I just don't think that's where we are (or will be).

        And again -- don't get me wrong. Encryption is good. Required, really, and should be guided by "what is really difficult to break now and in the reasonable future". But it's not the weak spot now, and I don't think it will be any time soon for the majority of data loss events. There are just too many alternative ways to extract data, and too many incentives to not fix them. I've often said, I'd rather my bank skip https and not have crap code than to have https be the end-all of their "security" as I'm pretty sure it is (yes, both would be preferable).

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like