Re: Post-quantum defaults

"Robert J. Hansen via Gnupg-users" <[email protected]> Mon, 6 Apr 2026 20:24:29 -0400
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
> The other one involves something called neutral atoms. This
> technology has better noise performance. But it is a different
> technology. It appears that we don't know how to run a relevant
> algorithm on it at this time in a useful way. The paper refers to
> "engineering challenges". So I think this is the one to pay
> attention to in the next few months. We need to wait for comments
> from knowledgeable critics.

Yes and no.

Scott Aaronson, a widely respected quantum computational theorist, had 
this to say in December 2025:

	When Frisch and Peierls wrote their now-famous memo
	in March 1940, estimating the mass of Uranium-235
	that would be needed for a fission bomb, they didn't
	publish it in a journal, but communicated the result
	through military channels only. As recently as
	February 1939, Frisch and Meitner had published in
	_Nature_ their theoretical explanation of recent
	experiments, showing that the uranium nucleus could
	fission when bombarded by neutrons. But by 1940,
	Frisch and Peierls realized that the time for open
	publication of these matters had passed.

	Similarly, at some point, the people doing detailed
	estimates of how many physical qubits and gates
	it'll take to break actually deployed cryptosystems
	using Shor's algorithm are going to stop publishing
	those estimates, if for no other reason than the
	risk of giving too much information to adversaries.
	Indeed, for all we know, that point may have been
	passed already. This is the clearest warning that I
	can offer in public right now about the urgency of
	migrating to post-quantum cryptosystems, a process
	that I'm grateful is already underway.

For many years now my own personal, private, rule-of-thumb, educated 
guess, wild hope, semi-informed nonsense, however you want to put it, 
has been "I need to migrate to post-quantum cryptography while the risk 
of breaking RSA-2048 in the next five years feels to be under 1%."

It no longer feels like it's under 1%, and that motivates me to ask when 
GnuPG is going to migrate the standard keypair to PQC.

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQR9jsS4W2/t1sENPHkeepTU6H+R1QUCadROvQUDAAAAAAAKCRAeepTU6H+R1cTe
AP4ttUBMCJ6DTmY7qnsQ77BLHrNOOSdA2ojfMyDhlyd/UgEA9uKxcz9hPM1MewCmemN0RRnC1JEh
Sl3q15JnV+bVkg8=
=2XuR
-----END PGP SIGNATURE-----