I think we might lose public key cryptography
meken
58 points
34 comments
October 08, 2026
Related Discussions
Found 5 related stories in 92.8ms across 8,906 title embeddings via pgvector HNSW
- Going Dark, and the era of law enforcement hacking vslira · 284 pts · August 14, 2026 · 51% similar
- Shutting down our public encrypted DNS mywacaday · 306 pts · September 04, 2026 · 50% similar
- Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub connorboyle · 20 pts · August 11, 2026 · 50% similar
- Internet freedom is fading in the new era of social control arrowsmith · 11 pts · July 12, 2026 · 48% similar
- Anthropic publishes a practical key-recovery attack on HAWK-256 bakigul · 57 pts · July 28, 2026 · 48% similar
Discussion Highlights (12 comments)
jauntywundrkind
some already refuted speculation online about what this was, that i found informative & interesting & real to our times [edited, originally intro text read: "to clarify"] > folks, Matt Green is not predicting that public key crypto will be cracked, he's predicting it will be regulated out of existence because LE will have no means to break into systems once we fix all the bugs https://bsky.app/profile/ver.ooo/post/3mxfbhrmk2c2u socializer has already shown up in comments to correct this, and has a good twitter link from an hour ago, clarifying the post was really about ai math attacks possibly damaging some of the rare couple of cryptoanalysis attacks out there: > These problems (right now basically MLWE and ECDLP with LWE and syndrome decoding as backups) have been extensively analyzed by humans. We felt good that the best known attacks were the best attacks. But we’re learning that human mathematical analysis isn’t the gold standard. ---- thankfully i think it's unrelated what else has happened in the last 24hr: > If you haven’t asked abliterated GLM 5.3 to hack the Internet’s core routers, then you’re a happier person than I am right now. https://bsky.app/profile/matthewdgreen.bsky.social/post/3mxd... and then oh look, a couple hours latter: Critical Cisco Nexus Flaws Let Unauthenticated Attackers Execute Code With Root Privileges https://cybersecuritynews.com/critical-cisco-nexus-flaws/
xyzsparetimexyz
Counter theory: No we won't.
tux3
https://nitter.kareem.one/matthew_d_green/status/21082788505...
caaqil
> betting against models and in favor of human intelligence being the limit has not worked well for any of us. The thread has no coherent argument or new evidence at all but this simple truth must be drilled into the heads of the mathematicians, and whoever is next on the chopping block. Stochastic parrot with high gF will emerge one way or another, and you will like it.
antics
Just to be absolutely clear, the giant OpenAI math dump replaces two (2) already efficient probabilistic algorithms with deterministic ones. Neither affects encryption as it is deployed today (one is a quantum algorithm, and the other is factorization over prime fields). I think it's fair to say that in the last month we have learned 0 things that would specifically confirm or disconfirm this stated view, either directly or indirectly. And that is not really Matthew's concern, anyway. His actual concern is that computers are really good at math, and if we point them at something like Module LWE or ECDLP there is a real chance that it (essentially magically) breaks them. See his statement at [1]. For better and for worse I think we are in a crisis of empiricism. As a community we are worried enough about the outcomes of breaking something like encryption that we're willing to admit statements like this one, even though we have no real, actual, concrete evidence that would indicate whether they're true or not. The line of thought Matthew articulates here ( i.e. , we can solve millennium problems thus "optimism [related to encryption] is a very opinionated bet") may be defensible from a risk management perspective, but it is absolutely not defensible as a statement of knowledge. Internally that's fine, but the public (including the technical public) is not going to make that distinction. They will interpret it as knowledge. That does not help us. [1]: https://x.com/matthew_d_green/status/2108281944291393983
abhv
i hope we first lose people who post dumb essays on twitter. at least he agrees that "he can't see the future" there is just as much evidence for the opposite stance: AI can help us improve and formally verify every security reduction we use. As long as math allows some kind of trapdoor function, AI can help us produce the best crypto we can achieve from it.
Mistletoe
Markets are down today over nonsense stargazing like this. If we lose cryptography, we lose everything in a sort of blackout level event like on Blade Runner 2049. It won’t matter what you buy or sell to. I see no signs we are even close to that.
swerve3815
This is essentially a guess that P probably = NP. Way more likely is that every existing cryptocurrency implementation contains bugs outside of the core cryptographic algorithm that would allow stealing coins without having to break that encryption. Cybersecurity is an arms race, as it always has been.
moralestapia
What a deeply ignorant statement. There are no shortcuts to factoring a (sufficiently large) number, and that's not even touching on other kinds of PKC. But this is a great example on why appealing to authority is a mistake and how academia is full of charlatans. Only way I see that happening is if (big f... if) P = NP and some superintelligence devises a general algorithm to solve one on the other; but he's obviously not referring to that, as the timeline in that context is the next 1-5 years, i.e. the models we have now. Edit: Lmao, the guy namedrops MLWE and ECDLP to save face, under the argumentation that he's worried about the public key algorithms out there when the "market share" of those algos is like 5%. RSA and ECC still rule the world and no amount of AI will "break" them. To be generous to the guy, he had a point, but went hyperbole, and also packing that into a scant sentence didn't help make his case.
hn_submit
This is just clickbait. Nothing to see here. Move along.
LoganDark
I've always used key lengths that are significantly longer than anyone ever recommends. I don't really believe in the trade-offs that lead people to choose the shorter ones. The only way I've been pressured to use a shorter key length is when the longer one for some reason is treated as an entirely separate algorithm that is randomly unsupported (looking at you, P-521)
Incipient
While "stop making stupid people famous" doesn't quite apply here, "stop making stupid posts famous" probably does. After he clarified and recanted a HUGE number of implied points in the first comment, my take is it comes down to "currently used encryption may be vulnerable" - essentially an evergreen statement, either due to weakness in the implementation (eg weak iv) or weakness in the maths (eg new mathematical attacks). Neither of these are new or honestly even worth pointing out. Other than crypto with immutable hashes, the rest of the internet would simply update their systems to mitigate any broken encryption (depending on the risk of the 'break'). TLDR: scary implications make a post popular, regardless of substance.