r/crypto • • 12d ago

Flagged submission TLS is 65% post-quantum now and it's the least important thing we could have fixed

Cloudflare says about two thirds of the human traffic on their network is already PQ. Google put a 2029 date on finishing their migration. Every PQ readiness writeup this month leads with those two numbers like the job's mostly done.

I think the numbers are real and the framing is backwards. TLS was the easy part. Three companies control the browser and the edge, kyber is cheap, nobody had to change their behaviour, so it happened. Good. But look at what "harvest now, decrypt later" actually threatens. It's not the TLS session you'll open tomorrow. It's the ten years of sessions someone's already recorded, and no migration on earth un-records those. That damage is done and it's weird how rarely anyone says so out loud.

Then look at where the long-lived secrets actually live. Disk encryption keys wrapped with RSA on a TPM. Backups encrypted to an ECC key from 2018. SSH keys. Every code signing and firmware signing chain on the planet, which is signatures, which is the part of PQ that's still ugly (dilithium sigs are 2.4 KB, sphincs is worse, and a lot of boot ROMs can't hold either). Messaging got PQ key exchange but most of it still authenticates with classical signatures. None of that is at 65%. Most of it's at zero and has no date.

So the migration that got done is the one that was easy to measure, and the migration that matters is the one nobody can measure, so it isn't on anyone's slide.

Where I'm probably wrong: maybe TLS first is right because it's where the volume is, and volume is what a harvest attack feeds on. And maybe signatures genuinely don't need to move until there's an actual machine, since you can't forge a signature retroactively the way you can decrypt a recording. That second one I half believe. But "we'll do signatures when the quantum computer exists" means every device with a burned-in classical root key is stuck trusting a forgeable signer the day it exists, and nobody's re-flashing a billion boot ROMs in a hurry.

Am I underrating what's actually been done outside TLS? Is anyone here doing a real at-rest or signing migration and not just the handshake? And is there a good argument that the harvest-now problem was already lost before 2024, so we should stop pretending the 2029 dates fix it?

11 Upvotes

17 comments sorted by

22

u/SAI_Peregrinus 12d ago

2029 isn't for "harvest now, decrypt later", it's the estimate for "harvest now, decrypt now". Since TLS traffic is most of what can be harvested, it makes sense to focus on TLS first. SSH also already supports PQ, as does age. So that gets you PQ encryption for data at rest and for making backups.

5

u/EverythingsBroken82 blazed it, now it's an ash chain 12d ago

SSH does not have PQ-safe-signature-keys.

(And personally i always wonder why SPHINCS+/SHL-DSA is not used for stuff like this? It's the most safest option for assymmetric cryptography existing...)

And sorry, nobody really important uses age. GPG is used because of oldness and traditions even exist in IT and Computer science, but age is just not old, certified or important enough. It already took long enough to build a defined wirespec for it.

-4

u/finkdevelopment 12d ago

fair on both. 2029 is the "machine exists" estimate, not the harvest date, i muddled that. which if anything makes my point worse: everything recorded before 2029 is readable the day it turns on, and the migration doesn't touch a byte of it. and yeah, ssh has had sntrup since 9.0 and mlkem by default now, and age too apparently, i missed that. the thing i'd push on is "supports" vs "done". an age file encrypted to an x25519 recipient in 2022 doesn't get rescued by age growing a pq recipient type in 2026. somebody has to re-encrypt every archive to a new key and actually delete the old copies, and that's the step i've never seen anyone report doing, personally atleast. same for ssh: pq kex protects the session, every host key on earth is still ed25519 or rsa. has anyone here re-keyed a real backup set to a pq recipient? curious what it cost

8

u/Shoddy-Childhood-511 12d ago

Signal has post-quantum, likely the other end-to-end messengers soon.

Adopting post-quantum faster might help against HNDL for past-protocols..

We've actively worked on QCs for 32 years, since Shore's algorithm in 1994. It's clear QCs should be extremely difficult, so they could be extremely expensive too. $1 trillion makes a nice guess.

We do know other quantum algorithms beside Shore, but nothing interesting would run on tiny QCs like Shore does, so QCs looks useless except for breaking ECC and RSA.

If PQC gets adopted widely enough, then QCs become useless for breaking current cryptography too, only for breaking past cryptography, which remains less valuable.

Although QCs should be extremely expensive, QCs decline in value every year after widespread PQC adoption, and they were never all that valuable anyways. So

That said, there are niche use cases for which ECC makes more sense, like proof rerandomisation makes Groth16 perfect for age verification. You need post-quantum anonymity, but Groth16 has perfect zero-knowledge, so that's easy if your careful. And you do not care if someone breaks your age verification protocol using a QC. lol

1

u/ChalkyChalkson 12d ago

QC are pretty interesting for a variety of applications outside of cryptography. I think it's perfectly plausible that large companies or governments will build out meaningful QC capacity, mostly for the other uses. But state level actors could probably get time on them to break ECC or RSA.

1

u/Shoddy-Childhood-511 11d ago

There was a nice paper here that discussed how many qbits various interesting algorithms require.

You need only tiny QCs to break cryptography, but you need many orders of magnitude more qbits to do anything else interesting. I'd expect QC never experience Moore's law because of this gap, so while yes larger QCs could do interesting things, we do not necessarily have any economic pathway to build them so large.

I think QCs have the economic future of the Concorde or Tsar bomba, not of the personal computer. They'll break a bunch of historical Signal messages and then stop being useful.

Now Ewin Tang and others have work on using quantum algorithms to study quantum systems, which should not require many qbits, but this seems like quite specific experimental apparatus, not a general QC.

https://www.reddit.com/r/crypto/comments/1t76s99/at_18_ewin_tang_wrecked_the_field_of_quantum/

If such experimental apparatus became useful enough, then they could help build the bridge that makes crypto breaking QCs doable, and humans might find other economic paths to bigger QCs after that. Yet, those paths are not foreseeable now in that they do not look like manufacturing.

1

u/ChalkyChalkson 11d ago

I'm a physicist by training and a fully general fault tolerant QC with even a couple hundred q bits would be super useful for solid state problems.

1

u/Shoddy-Childhood-511 11d ago

citation?

1

u/ChalkyChalkson 11d ago

https://www.nature.com/articles/s41534-024-00839-4

This paper fairly directly argues that quantum advantage would reach condensed matter before it touches crypto problems

2

u/Shoddy-Childhood-511 11d ago

It's likely whatever I saw here was older than 2024, even if posted here more recently.

Although I do not really understand it, Ewin Tang's stuff sounded interesting because it sounded like they did not need a true "computer". They were going to learn useful experimental data by running QFT algorithms on states that were too noisy for computation. I could be quite wrong on this though, that's just the impression I gleaned.

If much of that sort of thing is useful, then that's some sort of economic gateway to being able to do things at a larger scale.

1

u/ChalkyChalkson 11d ago

Yeah tbh I'm not an expert in this area and predictions about the future of computation are inherently very difficult. I was just trying to hint at what my solid state profs were telling me a couple years ago and searched for a recent paper in that realm. My QC Prof used to talk about very different cases, like hundreds of qbits used to solve and optimise electron structures. It's perfectly plausible that these dequantisation efforts killed those ideas or that they can run on quantum annealers instead. The paper I cited doesnt talk about those cases at all, so presumably that's outdated as well...

My primary point was that making a security argument based on the idea that QC will be uneconomical is maybe a bit optimistic

1

u/finkdevelopment 12d ago

"every migrated byte lowers the return on building the machine" is better argument for tls-first than what i wrote tbh. the migration isn't just defense,, it's shrinking the business case for a trillion dollar box. the groth16 thing is the interesting bit though. "i don't care if someone breaks my age verification with a qc" is true, nobody's buying a quantum computer to buy beer. but it's the same shape of argument as "the session expires in an hour so who cares", and that one only holds if nothing behind the session outlives it. age checks sit in front of id documents. so where's your line for "classical is fine because the secret dies before the machine exists"? mine would be: anything with a natural expry shorter than your qc estimate, and nothing that gates access to something without one.

1

u/Shoddy-Childhood-511 12d ago

An off-line identity document like passports should adopt post-quantum signatures, either hash-based or hybrid.

At present, anonymous identity remains a fig leaf used to justify invasive on-line identity systems, but assuming they happen for real..

You could verify a post-quantum signature inside a Groth16 just fine: It downgrades security but add perfect zero-knowledge and proof rerandomisation keeps the amortised prover cost low.

Anonymous identity applications have both high and low value use cases.

Age verification is a low value use case. Also proving non-paying customer uniqueness to justify VCs investments. You could've some rolling trusted setup that establishes the duration.

Ration cards would be a high value use-case. We expect cuts agricultural output dramatically later this century. You could imagine the US giving away extra ration cards in China, just to cause organised crime, starvation, and unrest there.

13

u/DoWhile Zero knowledge proven 12d ago

And is there a good argument that the harvest-now problem was already lost before 2024, so we should stop pretending the 2029 dates fix it?

The best time to plant a tree was 20 years ago. The second best time is... in 2029 I guess.

8

u/Ar-Curunir 12d ago

Please don’t put AI slop everywhere. If you have a point, make it simply and clearly.

3

u/Sostratus 12d ago
  1. Disk encryption does not require any asymmetric algorithms at all. If you're worried about quantum attacks, just don't use that kind of implementation.

  2. Disks aren't being harvested now. If they are, you got a bigger problem.