12 ms·
IIUC, NTRU is only "quantum proof" because there is no (publicly known) quantum algorithm for breaking it, while there is Shor's for everything discrete logarit
by floatboth 4y ago
IIUC, NTRU is only "quantum proof" because there is no (publicly known) quantum algorithm for breaking it, while there is Shor's for everything discrete logarithm based (both RSA and elliptic curve anything).
- bawolff 4y agoUntil we prove P!=NP that (i.e. its only secure because we dont know how to solve it) is pretty much true of all crypto algorithms, even classically.
- gpm 4y agoThis is true, but we don't know even more for quantum computers, because we have spent a lot less time studying quantum algorithms, so not yet having found an algorithm is much weaker evidence that the algorithm doesn't exist.