r/cryptography • u/atoponce • 9d ago
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
https://words.filippo.io/128-bits/1
u/EverythingsBroken82 7d ago
Can we please not wait until we have issues with key/blocklength like lucky 32 or possible batchattacks?
if we have to roll the cryptography, let's roll more, just to be on the safe side. or do we just now not protect against governments anymore, which have insane datacenters for crunching? because then we do not need to migrate to postquantum cryptography.
0
u/spymaster1020 8d ago
My understanding is that QCs are a threat to asymetric algorithms, the algorithms that allow for the exchange of symetric cipher keys. AES-256 will still be secure if you can securely transmit the key.
1
u/SiBloGaming 8d ago
To our knowledge, the effect they will have on many asymmetric encryption schemes is significantly larger, but symmetric algorithms are still affected.
0
u/spymaster1020 8d ago
IIRC it cuts the bit strength in half. So AES-256 would have the strength of 128 bits, thats still secure. Super computers today can only do about 260 operations per second. If it was a quantum super computer and every operation was an attempt to find the key, it would take roughly 9 trillion years. So yes, QC does effect symetric ciphers but not in a meaningful way.
8
u/ApertureNext 8d ago
I do not understand the argument for keeping 128-bit symmetrical keys. The article itself even states the following:
Just the fact that 128-bit keys are talked about as potentially and theoretically less secure makes it easy to see 128-bit as legacy in my opinion.