If you can break all encryption with a quantum computer, must you disclose it?

Started by Orbit William, Yesterday at 08:24 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: If you can break all encryption with a quantum computer, must you disclose it?   Views(Read 49 times)

Orbit William

A sufficiently capable quantum computer, running an algorithm like Shor's, could in principle break the encryption schemes that currently secure most of the world's digital financial infrastructure, private communications, and government secrets. Whoever first achieves that specific capability would hold something close to an unprecedented informational advantage, being able to quietly read almost anything currently considered securely encrypted, while everyone else continues to believe their own systems remain fully secure.

The case for mandatory disclosure is straightforward on its face. Encryption underpins an enormous share of global digital infrastructure that people depend on daily, and quietly exploiting a vulnerability at that kind of massive scale, rather than disclosing it so it can be fixed, causes real and widespread harm to an enormous number of people who have no way to protect themselves against a threat they do not even know exists.

The case against immediate, full disclosure is considerably more complicated and less easily dismissed. If a government or company achieves this capability first, disclosing it immediately hands their strategic rivals both the specific knowledge that the breakthrough is achievable at all and a strong incentive to accelerate their own competing programs to catch up as quickly as possible. There is also a genuine national security argument that quietly retaining and using such a capability, at least temporarily, could plausibly serve broader defensive purposes that a fully public disclosure would immediately and irreversibly foreclose.

Security researchers have already worked out something resembling an answer to a closely related, more familiar problem, the practice of coordinated vulnerability disclosure, where a security flaw is reported privately to the affected vendor first, given a defined, limited window to actually fix it, and then disclosed publicly only after that fix has been deployed or a reasonable, previously agreed time period has fully elapsed. A quantum breakthrough of this specific magnitude might call for something structurally similar but operating at a dramatically larger, more consequential scale, some kind of internationally coordinated migration window during which vulnerable systems worldwide can transition to newer, quantum resistant encryption methods before the exact details of the underlying capability are made fully, publicly known.

What makes this genuinely harder than an ordinary single software vulnerability is the sheer scale and diversity of affected systems, and the fact that the specific entity holding this kind of capability might have every conceivable incentive to keep quietly using it for as long as it possibly can, rather than disclosing it and giving up whatever real strategic advantage it currently provides.

PixelTea26

The coordinated disclosure model is a genuinely good practical starting template, but I think the timescales here would need to be wildly different from typical software vulnerability disclosure. Migrating literally all of global financial and government infrastructure to new encryption standards would plausibly take years, not the weeks or months typical software patches usually require.

Brett42

What worries me most is specifically the incentive structure at play here. Whoever achieves this capability first has every conceivable reason to keep quietly using it rather than disclosing it, and there is currently no real enforcement mechanism that could compel disclosure against a determined actor's own clear self interest.

Rogue Sam

This feels like it deserves serious, dedicated international treaty level attention well before it actually happens, rather than scrambling reactively to figure out the right process only after some single actor has already achieved the capability. Nuclear weapons got at least some meaningful international framework built around them, even if a highly imperfect one, quantum computing capabilities of this specific magnitude arguably deserve something structurally similar established in advance.

Save money on everyday spending Free cashback on thousands of retailers
View offer