If there is a concept of "quantum-safe" (which I did not know until reading this article), why hasn't the broader internet (HTTPS) adopted them? Is there any plans for there adoption in the future?
If there is a concept of "quantum-safe" (which I did not know until reading this article), why hasn't the broader internet (HTTPS) adopted them? Is there any plans for there adoption in the future?
I haven't heard this expressed anywhere, but it could also be that the McEliece and Niederreiter algorithms have a bit of a feel to them like the Merkle-Hellman knapsack algorithm that was thought for a long time to be secure.
Though, if you're being paranoid and can spare the cycles, it wouldn't hurt to take Elliptic Curve Diffie-Hellman (or ECIES) exchange, encrypt that using RSA (or ElGamal), and then Encrypt that using Niederreiter (or McEliece), like a bunch of Russian dolls nested by key/message size. All three crypto systems would need to be broken in order to recover the key.
My understanding is that schemes that would be resistant to quantum attacks are much less efficient, and have more negative tradeoffs, than the systems in use today. Speed is an important property for a most cryptography, so few people would adopt such a system until the threat seems more pressing.
The real problem is public key ciphers that rely on prime number factorization. Eliptic curves are one solution, but the only people who seem to have in-depth knowledge about them are in the NSA.