Because peeps are doing HNDL (harvest now, decrypt later) today. They are intercepting your traffic and storing it until they can break crypto. They're doing that today. And they've been doing it for a while.
There are contexts in which that's an unacceptable level of risk.
HNDL can be worth it without the "threat" of quantum computing; for instance we see currently a lot of interest in AI-assisted math, and maybe it could lead to a breakthrough that affect crypto algorithms that are currently considered safe.
Therefore it seems weird to use QC as a benchmark. Rather, if your communications being decrypted in the future is unacceptable, then the logical conclusion is that you must not transmit it in such a way that a third party can intercept it.
Admittedly, it is inconvenient or even impractical, so people do accept the risk anyway without admitting it. They are sweeping the issue under the carpet of supposedly QC-proof crypto - because new quantum algorithms can be discovered too.
I'm personally more worried about flaws in the quantum-safe crypto schemes than in RSA, which is based on the age-old factorization problem of prime numbers.
They can harvest all they want, but if no one ever invents a usable, practical and scalable quantum processor all this will be moot.
What are the odds that a new QS crypto scheme has a fatal flaw or is otherwise intentionally backdoored?
Amping everyone up with fears over quantum breaking classical seems like a fantastic way to get another round of vulnerabilities injected into everyone's infrastructure.
Comments
I too am convinced that RSA-4096 will remain secure for the foreseeable future. Why everyone's mental about quantum-safe encryption is beyond me.
Because peeps are doing HNDL (harvest now, decrypt later) today. They are intercepting your traffic and storing it until they can break crypto. They're doing that today. And they've been doing it for a while.
There are contexts in which that's an unacceptable level of risk.
HNDL can be worth it without the "threat" of quantum computing; for instance we see currently a lot of interest in AI-assisted math, and maybe it could lead to a breakthrough that affect crypto algorithms that are currently considered safe.
Therefore it seems weird to use QC as a benchmark. Rather, if your communications being decrypted in the future is unacceptable, then the logical conclusion is that you must not transmit it in such a way that a third party can intercept it.
Admittedly, it is inconvenient or even impractical, so people do accept the risk anyway without admitting it. They are sweeping the issue under the carpet of supposedly QC-proof crypto - because new quantum algorithms can be discovered too.
I'm personally more worried about flaws in the quantum-safe crypto schemes than in RSA, which is based on the age-old factorization problem of prime numbers.
They can harvest all they want, but if no one ever invents a usable, practical and scalable quantum processor all this will be moot.
It would be ironic if the holes in the quantum-safe crypto meant that they were weaker than the old school options.
Generally people encrypt with both post-quantum crypto and regular crypto in series to prevent that from being a problem.
You can sell them new software because of this. ;-)
Classic odds/stakes. What do the odds have to be of a surprise quantum breakthrough before the stakes are serious? 1 in… a million? A billion?
What are the odds that a new QS crypto scheme has a fatal flaw or is otherwise intentionally backdoored?
Amping everyone up with fears over quantum breaking classical seems like a fantastic way to get another round of vulnerabilities injected into everyone's infrastructure.