Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> even if quantum computing key factorisation works, key lengths will still have an impact on the difficulty of factorisation, and it may make a difference in terms of practicality.

I mean, the whole thing with quantum computer factoring is it scales well. Getting to 2048 rsa seems really really difficult. But if we ever get there, getting to 4096 is probably just a tiny extra step.



The current state of quantum computing suggests that there is an exponential effort to increase the available qbits. Going from RSA 2048 to RSA 4096 would not just double the effort required on the quantum side.


Wouldn't that effectively prevent a threat to 2048 bit RSA in the first place?


Almost like there's no free lunch. I don't see quantum computing ever really taking off without a fundamental breakthrough in our understanding of physics.

Would love to be proven wrong though if my understanding is incorrect and there's actually a feasible path towards quantum computing at scale.


I dont think there is any fundamental physics reasons preventing quantum computers. My understanding is it is an engineering problem. A hard one no doubt, but not a fundamental physics one.

Anyways, my point was that getting a quantum computer at a decent scale is really difficult. If we manage to overcome that burden somehow, the difference between 2048 bit rsa abd 4096 bit is peanuts.


Well, we can't know. Maybe it would be trivial, maybe it could keep your data safe for 5ore years. Maybe it could double the cost to crack.

No one can know at the moment, hence the trade off, if it costs very little to do a longer key, why not do a longer key?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: