Re: Post-quantum defaults
"Robert J. Hansen via Gnupg-users" <[email protected]> Mon, 6 Apr 2026 20:24:29 -0400
| Newsgroups | gmane.comp.encryption.gpg.user |
|---|---|
| Message-ID | <[email protected]> |
> The other one involves something called neutral atoms. This > technology has better noise performance. But it is a different > technology. It appears that we don't know how to run a relevant > algorithm on it at this time in a useful way. The paper refers to > "engineering challenges". So I think this is the one to pay > attention to in the next few months. We need to wait for comments > from knowledgeable critics. Yes and no. Scott Aaronson, a widely respected quantum computational theorist, had this to say in December 2025: When Frisch and Peierls wrote their now-famous memo in March 1940, estimating the mass of Uranium-235 that would be needed for a fission bomb, they didn't publish it in a journal, but communicated the result through military channels only. As recently as February 1939, Frisch and Meitner had published in _Nature_ their theoretical explanation of recent experiments, showing that the uranium nucleus could fission when bombarded by neutrons. But by 1940, Frisch and Peierls realized that the time for open publication of these matters had passed. Similarly, at some point, the people doing detailed estimates of how many physical qubits and gates it'll take to break actually deployed cryptosystems using Shor's algorithm are going to stop publishing those estimates, if for no other reason than the risk of giving too much information to adversaries. Indeed, for all we know, that point may have been passed already. This is the clearest warning that I can offer in public right now about the urgency of migrating to post-quantum cryptosystems, a process that I'm grateful is already underway. For many years now my own personal, private, rule-of-thumb, educated guess, wild hope, semi-informed nonsense, however you want to put it, has been "I need to migrate to post-quantum cryptography while the risk of breaking RSA-2048 in the next five years feels to be under 1%." It no longer feels like it's under 1%, and that motivates me to ask when GnuPG is going to migrate the standard keypair to PQC. _______________________________________________ Gnupg-users mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-users
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQR9jsS4W2/t1sENPHkeepTU6H+R1QUCadROvQUDAAAAAAAKCRAeepTU6H+R1cTe AP4ttUBMCJ6DTmY7qnsQ77BLHrNOOSdA2ojfMyDhlyd/UgEA9uKxcz9hPM1MewCmemN0RRnC1JEh Sl3q15JnV+bVkg8= =2XuR -----END PGP SIGNATURE-----