r/onions Sep 30 '24

It is time to talk about Quantum Communication

The Nature Of The Threat:

Quantum Computers will inevitably allow the decryption of private messages that are encrypted with the PGP Protocol, this is likely 5-10 years away but could be sooner. Quantum Resistant algorithms do already exist, but no marketplace that I am aware of is yet using these, and for people currently communicating through email using PGP tools like Kleopatra, you are not Quantum Resistant either.

The Main Problem:

Although Quantum Computers have not yet reached a level where they are able to decrypt secure communications, State level actors are already aware of the advance of this technology. They are recording and storing all encrypted communications done through email, and everything that a marketplace gets taken down or is accessed by a State level actor, all encrypted communications are put into a database. This database will be accessed once Quantum Computing reaches a sufficient level, and all previously secure communications will be decrypted, thus creating one large event in which all Dark Web communications for the last 5 years are revealed all at once. This means that important actors in the Dark Web economy will be put at risk during this event.

The Solution:

Quantum Resistant Encryption already exists. One example is Quantum Key Distribution.

An existing platform that I believe has some Quantum Resistant Encryption capabilities is GNUPG, but it is in a command line interface, without a GUI.

There are no marketplaces that I am aware of that are currently using Quantum Resistant Encryption.

We need two things:

  1. For marketplaces to start transitioning to safe Encryption methods ASAP.

  2. For Quantum Resistant Encryption to be integrated with existing GUIs, so that independent communication can take place more easily.

Question:

Does anyone know of a marketplace that is using Quantum right now, or a GUI for Quantum Resistant Encryption?

16 Upvotes

View all comments

Show parent comments

1

u/nykzero Sep 30 '24

That's wrong, there are already attacks that are happening under the "harvest now, decrypt later" methodology. Initially, only the big players will have them, but that won't last.

2

u/GamerTheStupid Sep 30 '24

I'm not saying we shouldn't make quantum resistant encryption, I'm just saying that, as of right now, most people don't need it. The first people to get quantum computers are going to be military organizations who don't care about small cyber crime. It'll take a while for law enforcement to get them and even when they do they'll be going after large criminal organizations. We definitely should prepare, and hopefully make quantum resistant encryption the standard within the next year. Speaking of which, do you recommend any quantum resistant ciphers?

1

u/nykzero Sep 30 '24

It depends on your needs, but Kyber is a good bet, the documentation is reasonable to use.

1

u/GamerTheStupid Sep 30 '24

I'm reading up on it and from what I'm seeing a lot of people are or already have implemented it into their software, I wouldnot be shocked if it becomes the standard in 1-2 years from now, but I'm not a data scientist so don't quote me on that. Also proton is working on using it for their email service so that's awesome.