X-rays reveal censored portions of Marie Antoinette’s letters to Swedish count
arstechnica.com
arstechnica.com
> On average, to brute-force attack AES-256, one would need to try 2^255 keys. (This is the total size of the key space divided by 2, because on average, you'll find the answer after searching half the key space.) So the time taken to perform this attack, measured in years, is simply 2^255 / 2,117.8 trillion
> Expressed as an exponent of 10, that’s 2.73 * 1061. Written in full format:
>27,337,893,038, 406,611, 194,430,009, 974,922,940, 323,611,067, 429,756,962, 487,493,203 years.
>In English: 27 trillion trillion trillion trillion trillion years.
From-https://scrambox.com/article/brute-force-aes/
I’d love to hear Hacker News opinions on how long that will be valid due to faster computers, quantum computing etc. Or if it will always pretty much be valid in your opinion?
The number they get for all the PCs on earth trying it is still 13,689 trillion trillion trillion trillion years. The universe is only 14 billion years old and estimates of what the universe will be like in even a trillion years are more like science fiction than science because it is so wildly long.
More seriously, GPUs are faster because they are highly parallel, and parallelism can only give you a speedup that is linear with the number of processing units. So unless you're planning to build a GPU with trillions units, that won't help much.
AES is still believed to be quantum resistant.
So encryption will still work in a quantum world. We 'just' have to update the algorithms we use.
See also: https://csrc.nist.gov/projects/post-quantum-cryptography/rou... https://en.wikipedia.org/wiki/Post-quantum_cryptography
Quantum computing could allow an implementation of Shor's algorithm to exist. This algorithm breaks RSA which is the basis of a lot of asymmetric cryptographic implementations such as TLS and SSH. By breaking here we mean that it is trivial to crack. It is unclear right now whether or not an equivalent attack applies to elliptic curve-based algorithms which are gaining in popularity.
As far as symmetric encryption is concerned, the standard right now is AES-128 and AES-256 and might be vulnerable to Grover's algorithm which would effectively half the effective number of bits so AES-128 becomes roughly equivalent to a non-existing AES-64 which would be somewhat trivial to crack. However, data encrypted with AES-256 would simply go down to AES-128 which is still considered "good enough" as of today.
In practice, by the time we have real quantum computers there will be a new standard for both of asymmetric and symmetric encryption so it does not matter as much as one would think.
TLDR: RSA will break, elliptic curves might break, AES will be weakened and the impact on your life will probably be minimal.
There's no indication that it can be used to break several other types of problem that can be used in asymmetric cryptography. These other problems are less efficient and have different trade-offs (some have huge keys, some have huge outputs, some are really slow) and picking appropriate parameters to make them usable while still being secure is a difficult problem. Solving that is the aim of NIST's post-quantum standardization effort.
[1] https://crypto.stackexchange.com/questions/51346/shors-algor...
If it looks like someone is going to build a quantum computer out of the entire mass of the silicon in Earth's crust, I suggest 512-bit keys. That'll keep your secrets safe for about 9E73 years. I'd also suggest finding a new planet to live on, the mining operation would likely be somewhat disruptive.
For a more realistic comparison, perhaps they've only got a computer with as much mass of iron ore as the recent annual world production for the last thousand years (2.5E9 tonnes/year = 2.5E15 kg). Then it'll take around 5000 to run 2^255 operations.
Light speed delays are not relevant to a highly concurrent problem. They would be an issue for a general purpose computer that size running a sequential program.
Either way it's a bit beyond what's economically possible for any human organization right now. And I implicitly assumed the computation is fully reversible and therefore took negligible energy.
“We generalize Grover's”…
“We extend the analysis to the case of a society of k quantum searches acting in parallel”.
Disclaimer: I know absolutely nothing about the topic, but the first link I googled seems to justify my intuition that this decryption could be partitioned so that many quantum computers could run in parallel (thus avoiding the limit on speed of information transfer you are hypothesising).
> Either way it's a bit beyond what's economically possible for any human organization right now. And I implicitly assumed the computation is fully reversible and therefore took negligible energy.
Agree - I’m just being that contrary Internet!
I really enjoyed reading it.
Bremermann's Limit[1] puts a fundamental limit on the rate of computation for any given amount of mass of about 1.36e50 bit changes/second/kg. Unless you get an amount of mass of literally planetary scale (as large as, say, Mercury) to take part in your computation the time will be enormous even for a 256-bit key.
DES, pretty much the first strong civilian encryption algorithm, is crackable due to brute-forcing the 56-bit key space, which has been pointed out as a security problem almost 50 years ago, but in terms of cryptanalysis it's doing ok.
AES will turn 25 soon and the best cryptanalyses today are like a factor four faster than brute-force (but require rather significant memory, which brute force doesn't), which is basically nothing.
The Ars article is terrible at conveying this; you have to get to the 7th paragraph to get even the first hints of this. I usually expect better from them.
[0] https://www.vice.com/en/article/akgb88/viral-jump-humping-ti...
Ah, God bless all the horny teenagers trying to rationalise their way around a belief system derived from an Iron Age society.
Always puts me in mind of a certain Garfunkel and Oates song. (nsfw)[1]
Does anyone know what are the other use cases for these techniques? The article is very interesting! Thanks for sharing
It's not like society is bound to work on one thing at a time...
And I didn't say uninteresting. The authour of the letters purposefully removed the lines from the historical record for modesty's sake. It's similar to digging through a celebrity's trash to find salacious gossip.
How to know before finding out?
If you fail to see the value of how this novel way can be used for other letters beyond this initial test case, then there's not much else to say I feel
This initial test case based on a technique already in practice on other sources of writing? None of my posts have dismissed the technology, just it's use in this case.
Scientific methods relating to historical and archeological discovery are immensely important, this article in particular highlights something that may indicate many other hisorical letters/documents may contain previously missed information that while likely mostly mundane minutae, a shining example could alter how we understand history and the interplay of historical figures.
That said it seems this just referencing a less common use of a specific technology to solve a problem which I suppose is appropriate
I find it unlikely anyone was expecting to find some revelatory details in the letters between Marie Antoinette and her alleged lover. They just wanted to know more about her intimate affairs.
The article on Ars is pretty shit at conveying that - you have to get to the 7th paragraph for any technical details to come up - but that’s an(other) indictment of Ms. Oulette, not the research team.
>So when Fabien Pottier and several colleagues at the Museum of Natural History's Research Center for the Conservation of Collections (CRCC) took on the task of uncovering the censored portions of letters between Marie Antoinette and von Fersen, they naturally turned to similar techniques.
That doesn't sound like developing the method was their primary goal.
I'd put that very differently. Some are interested in what they have, others in what they do, the rest in how they do. And, I don't think that people on HN are predominantly interested in things. I think they're above all interested in acts.
The division is long established in the scientific lit - just highlighting it exists.
The bonds between Swedish and French nobility during this time period are interesting. About twenty years after these events, one of Napoleon's marshals was offered the Swedish crown and became king of Sweden.
The article mentions the process being used on Egyptian papyrus and the Dead Sea Scrolls. There are countless other recovered bits of parchment that the process could be used on from around the world, possibly uncovering more primary sources about antiquity.
Or just like any other of von Fersen's letters would probably be more illuminating about French Swedish relations, though I don't know if they were censored. His fondness of Antoinette was already known.
My argument was never that Antoinette deserves some special privacy, so changing the subject of the act is not a strawman. Why should people enjoy someone else's private correspondence but not yours?
I'm not so selfish and conceited that I pretend to still care about things after death, lol.
> I just heard. What the fuck? I really liked Descartes! I sent him over so we could share, and you go killing him?! Fuck. This is why we can't have nice things.
> Toodles, Marie.