ScramFS

I’ve heard that quantum computers will break many cryptosystems. What does this mean for the long term security of my encrypted data?

By Scram Software 11 September 2017

Personal data stored at rest should be encrypted with a long-term view. Even if you do not intend to store the data for the long term, your encrypted data may be copied during a security breach and an attacker may attempt to decrypt it in the future. Or your cloud provider may retain an archive or backup, even after you have deleted the data. For personal data, we should consider the security of data for the duration of the person’s life, which may be 100 years.

We cannot know what will happen centuries from now, but there are developments we can expect in the coming decades. Quantum computing and the continued exponential decrease in the cost of computation are well understood development that we must anticipate. Other developments can be imagined, such as the discovery of a mathematical weakness in existing encryption algorithms, but we cannot mitigate against such threats and can only hope for their continued security.

For the moment, the main concern in the cryptographic community is the threat that Quantum computers pose to many kinds of cryptography used commonly today.

It is known that many ciphers such as RSA and ECC are vulnerable to attack from quantum computers – “quantum-breakable”. What this means is that most forms of security in use today (such as TLS) will be easily broken by quantum computers.

It is estimated that by the year 2029, a quantum computer will have been built that will be capable of breaking RSA-2048.

The state-of-the-art of quantum computers is not known because research and development into quantum computing is likely to be a trade secret or classified information. However, it is believed by top cryptographers that we should transition away from using encryption techniques that are known to be vulnerable.

This is relevant to all customers of cryptography because data stored in the cloud can live for decades or even posterity. The data that’s stored in the cloud may be encrypted and safe for now, but could be easily broken in a number of years.