| ▲ | simonw an hour ago | |
Later in the linked Twitter thread: https://twitter.com/matthew_d_green/status/21082828173438241... > So what does “losing public-key [encryption]” mean? It does not mean cryptography or encryption is impossible, or that we live in Minicrypt. It does mean that we imminently see new cryptanalytic results that substantially improve our ability to attack standardized schemes. > The more modest effect of this would be that several schemes we’d previously agreed were “good enough” (128 bit security level) aren’t. Maybe they’re 96-bit or 108-bit secure. > In any case, honest standards bodies have to step back and deprecate at least those smaller parameter sets, which are already deployed in some live systems. But in principle, we can usually just crank up parameter sizes. Right? > But crank them up to what? Right now we’re saying we have the right numbers, because humans spent 40 years (or 25 years) studying these assumptions. If suddenly it turns out we were off by 26 bits, that’s obviously not something we can lean on. > So then, we could lean on the fact that the machines now say they’re stuck — the assumptions at the new numbers seem pretty robust, and no lab is able to make further progress. > How do you feel about that? I don’t feel great about it. I think nobody will feel good about it. > And what happens if we tentatively agree to trust that progress has stalled, and then some new internal model makes another step-change jump? We could end up losing trust in these assumptions at any security level except for painfully high ones. > So again I’m not saying that any of this will happen. What I am saying is that I would be very surprised and pleased to find out that human cryptanalysis (of the non-classified form) handled by a couple of dozen people, turned out to be the best we could ever do. | ||