logoalt Hacker News

plopilop • today at 8:32 AM • 2 replies • view on HN

We are migrating all of PKI to the more costly and less efficient postquantum cryptography, even though nobody will reasonably use a quantum computer to snoop on your home IoT daily reports. I mean, I assume that what you are doing on your free time is not worth governmental attention.

The rationale of mass migration is that if you don't impose it, nobody migrates. This has notably been the case with famously insecure SSL parameters (512 bits RSA keys, PKCSv1.5...). And many companies may believe they are not critical, which might be true until it is not.

Case in point: you manufacture walkie talkies and suddenly your products have bombs inside. Or you maintain a compression library for free and suddenly you are shipping a backdoor to all Linux products.


Replies

Iolaum • today at 9:08 AM

> nobody will reasonably use a quantum computer to snoop on your home IoT daily reports

Feel free to tell that to journalists investigating corruption ...

hypfer • today at 9:03 AM

My reply did not exhibit a lack of understanding of this mechanism.

It instead questioned to which degree execution of them is reasonable in a world that does not contain infinite resources.

Everything is a trade-off. Not all of them make sense.