this post was submitted on 14 Mar 2024
101 points (94.7% liked)

Privacy

31921 readers
1140 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 10 points 8 months ago* (last edited 8 months ago) (2 children)

post-quantum cryptography can be compared with a remedy against the illness that nobody has, without any guarantee that it will work. The closest analogy in the history of medicine is snake oil.

Good on them for saying that.

A "remedy against the illness that nobody has" is a good analogy, but it is important to note that it's an illness which there is a consensus we are likely to eventually have and a remedy that there is good reason to believe will be effective.

It isn't a certainty that there will ever be a cryptographically relevant post-quantum computer, and it also isn't a certainty that any of the post-quantum algorithms (as with most classical cryptography) which exist today won't turn out to be breakable even by yesterday's computers. The latter point is why it's best to deploy post-quantum cryptography in a hybrid construction such that the system remains secure even if one of the primitives turns out to be breakable.

That said, I think it is totally wrong to call PQC snake oil because that term in the context of cryptography specifically means that a system is making dishonest claims: https://en.wikipedia.org/wiki/Snake_oil_(cryptography)

[–] [email protected] 4 points 8 months ago* (last edited 8 months ago) (1 children)

I didn't post the part after the "snake oil" quote because my post was getting a bit long but yeah, they basically agree with you. I also get mild ESL vibes (the phrasing on the title is a little off, and I believe a couple of the developers are Russian-born) so I don't think they were trying to be too inaccurate.

[–] [email protected] 4 points 8 months ago

they basically agree with you

yes, I realize :)

I should've made clear in my comment that, aside from a bit of imperfect English and incorrect use of the term snake oil, I think this is an excellent blog post.