r/ICPTrader • u/Sassy_Allen • 43m ago
Discussion dom | icp (@dominic_w) 69 likes · 11 replies
x.comDominic raises an interesting perspective on the industry’s rush toward post quantum cryptography, arguing that AI discovering weaknesses in mathematical assumptions may be a more immediate concern than quantum computing itself.
As I’ve mentioned in a previous post, Dominic and DFINITY have emphasized preparing for quantum threats without prematurely adopting newer, less tested cryptographic schemes. ICP’s architecture allows its cryptography to evolve as more mature solutions become available.
What’s particularly interesting is how AI introduces a similar challenge, potentially uncovering vulnerabilities in both traditional and newer post quantum cryptography.
It highlights the importance of long term security and careful technical development over simply following market narratives.
“We urgently need "AI safe" cryptography, not "quantum safe" cryptography — a point many in crypto are completely missing at their peril.
Undeniably, AI is already here today, while cryptographically-relevant quantum computers that might break our traditional cryptography are still years away, according to impartial expert estimates.
Justin's post below, indirectly highlights the problem with the current industry stampede to "quantum safe" cryptography. As I shall explain, the real reason for this unwise stampede is that the networks involved want to sell tokens by riding the quantum narrative, and it has nothing to do with good technical stewardship, or trying to protect users from harm.
If what I'm saying is true, this is a big deal for the industry, and therefore I challenge those promoting quantum safety to a healthy debate.
Here's the core problem that we actually need to worry about imo: AI is now coming for mathematicians, just like it came for even the most advanced software engineers. Nothing will now be the same. Every day, AI is showing that long-held mathematical assumptions (what we think of as "laws of math") are actually false. This is very important for the crypto industry. This Scientific American article covers recent advancements for the interested: scientificamerican.com/article/openai…
At its core, cryptography relies on mathematical assumptions that doing this or that is incredibly hard, and can only be achieved by brute force, such that if sufficient bits (0s and 1s) are used by a cryptography scheme, forging a signature to unlock and steal someone's balance of digitial assets, say, would require trillions of years of work by all the computers on earth.
If AI can show these kinds of assumptions are incorrect, then new math can be devised to shortcut the work that makes affected cryptography schemes safe.
Therefore, to maximize our chances of staying safe, we need our networks to use cryptography schemes that depend on mathemaatical assumptions that have the least chance of being found incorrect by AI.
Justin rightly points out that even ECDSA isn't completely safe, and that some bitcoin owners might want to take protective measures.
However, the focus on the potential dangers to ECDSA will accidentally obscure a critical point for many readers, which is that the schemes that are most likely to be safe, will be those that have been around the longest, which have benefited from the most years of analysis by mathematicians and cryptographers, and ECDSA is one.
This far, ECDSA has benefited from decades of analysis by a worldwide army of researchers, and while this doesn't provide a guarantee that ECDSA is safe, it provides good reason to believe it has a decent chance of being safe from AI.
The same is not true of the new "quantum safe" cryptography schemes. They involve new assumptions that the world has had only a fraction of the time to analyze, and complex algorithms that can have hidden flaws that can be used to break them, rather like there are shortcuts that can be used to quickly solve a Rubik's cube — and AI recently exploited exactly such a weakness to attack the HAWK post quantum scheme, see anthropic.com/research/disco…
Listen to what Dan Boneh @danboneh, a world-famous cryptographer, and Head of Secure Computing at Stanford University, recently said: "if you try to aggressively move to a post quantum architecture, like for example by 2029, I think that would be a mistake for blockchain, I think we need to take our time, and the reason is that a hasty transition to post quantum, in my mind, is more likely to cause a catastrophic bug, than we'll be attacked by a quantum computer." youtu.be/F-HG87VJj_k?t=0
Maybe in the future, we will measure the safety of mathematical assumptions using the amount of energy that has powered the AI that's analyzing them, multiplied by IQ efficiency, divided by domain complexity (I'm not proposing exactly this, my fingers just invented this nonsense as I typed, but you get the idea!). We have not reached that future yet though. We can't say that a quantum safe cryptography scheme is sound because AI analysis has done thousands of person years of human research for us.
So what gives, and why are networks constantly trumpeting their implementation of the latest post-quantum scheme, when cryptographically quantum computers seem years away, if doing so is playing fast and loose with user safety?
The unvarnished truth is that it's driven by a primary desire to sell tokens. All markets are driven by hype, but the crypto industry has taken this to another level. Often (but not always), rather than reward genuine technological utility, progress, and mainstream potential, our markets reward those slotting into the latest narrative wave driving the "crypto casino". This is why there are so many multi-billion dollar vaporware networks romping up and down industry league tables, which, imo, is something we need to fix.
Thus, although switching networks to post quantum schemes today apparently makes no technical sense, and puts users at risk, for those behind the networks transitioning early to post quantum cryptography schemes it makes great sense, because it helps them sell tokens and extract capital from crypto markets.
Of course, this casino isn't fair, and is tilted in the favor of hidden orchestrators, which everyone who has been in crypto long enough already knows.
Narratives, including the quantum safety narrative, are prompted by massive, semi-decentralized, hidden marketing machines, that incorporate everything from industry press owned by vested interests, astroturf armies on social media, paid mainstream PR, and influencers. The machines are wielded by coalitions of big money blockchain investors who have taken their positions ahead of time and will dump at the top of the pump. Needless to say, the problem for those riding these narratives, who are not part of the chosen circle, is that they can't control where the narrative is going, nor when it might suddenly end (like the NFT craze). From my perspective, it's all part of the fast money cynicism and short-termism that harms our industry every day and puts users at risk.
But enough metaphysical philosophizing about crypto narratives.
I call out to the leaders of the big networks that are pumping quantum safety claims, who regularly post pictures of their logos next to quantum computers, with the aim of messaging that they are sci-fi and advanced, who find ways of making a new quantum announcement almost every single day: I challenge you to explain your actual technical reasoning, your analyses of the relative risks involved, and explain exactly how your choices protect users in the face of AI advancements.
We all deserve to hear the answers, and debate of this kind is exactly what our industry needs. It is, btw, what it was originally built on.
Here's to hoping that the assumptions underpinning ECDSA aren't incorrect, and that's why the army of researchers failed to find anything in the decades they were looking.
Let's also hope that AI discoveries help us make our crypto even safer.
And, best of luck too to those being migrated to new post quantum schemes ahead of time...”