@matthewdgreen.bsky.social@bsky.brid.gy
Post #3477186
2026-06-29 20:17 UTC
One of my beefs with (research) cryptography is that people are overindexing on quantum threats. We finally got crypto to the point where we can do things efficiently, and now we need to rip it all up and switch to lattice schemes at 11,000x the cost.
Replies (1)
-
@matthewdgreen.bsky.social@bsky.brid.gy 2026-06-29 20:20
This is fine for long-term needs like encryption. It’s silly for short-term stuff like authentication. As long as there’s an upgrade path, your signature scheme or ZKP isn’t going to get smacked by someone’s secret quantum computer. You’ll see the quantum computers coming and upgrade.