Skip to content
Eight mathematicians_Website header
Roberta FauxOct 5, 2026, 11:02:44 AM5 min read

Forty People. One uncomfortable Question

Forty People. One uncomfortable Question
6:59

Forty people, one uncomfortable question

The slides stopped on Tuesday. By Wednesday morning the workshop had scattered into working groups across classrooms in the Alan Turing Building, and Roberta Faux, Arqit's Chief Cryptographer, had chosen her room. Eight people in it, give or take. One question on the table: how much noise does it take to kill a quantum algorithm?

Nobody knew, which was rather the appeal. Stating the problem properly took real effort, and progress looked impossible for most of the day. So the group talked, read, wrote code, and kept going on the assumption that structure stays invisible until someone goes looking for it.

Who was in the building

Around forty people, most of them academic: mathematicians, quantum information scientists, a handful of computer scientists, many funded by the organising universities of Manchester, Lancaster, Bristol and Royal Holloway. There was a deliberate effort to fund early-career researchers, which matters, because recruitment into this field is its own quiet problem.

Industry was there by design. Faux attended with Daniel Shiu, Cryptomathematics Professor at the University of Manchester, and the difference in perspective is sharp. Academics are motivated by whether a problem is hard. Her question is hard for how long, hard enough for what, and what it costs if the answer turns out to be wrong. Her job in the room was translation, turning "this attack is exponentially hard" into a plan and a price.

The word being tested was "belief"

Public-key cryptography is the mathematics that lets two parties who have never met agree on a secret over an open connection. It sits underneath online banking, secure messaging, software updates and the padlock in the browser. Two schemes do almost all of that work today, RSA and elliptic curve cryptography, and both rest on calculations that are easy to perform and, as far as anyone can tell, impractical to reverse.

A large enough quantum computer would reverse them. Shor demonstrated that in 1994. Post-quantum algorithms are the replacements chosen to survive that machine, and the workshop existed to put pressure on those choices."

The replacements have theorems, and good ones. What they do not have is a proof that the underlying problem is genuinely hard, and there will not be one. RSA has always been in the same position. This is the ordinary condition of the field, and the only variables are how many people tried to break it, and how long they spent trying.

Which is why Faux went. Anyone can read a standard and see the phrase "no known efficient attack." What no document records is where the cryptanalysts hesitate, and hesitation is where the risk lives.

A week of very classical mathematics

Day one covered foundations before moving to the hard cases: quantum cryptanalysis, attacks on the HAWK signature scheme, Kuperberg's algorithm against isogeny-based schemes, lattice sieving over quantum mesh networks. On Wednesday Faux joined the group working on Learning Parity with Noise and an approximate Simon algorithm.

Simon's algorithm is Shor's ancestor, the 1994 paper Shor read before he broke RSA. It does not hand over a secret directly. Each run yields one clue, and once enough clues are collected the secret falls out as ordinary algebra. Fast, and completely devastating.

Introduce even slight corruption and the picture changes. Every clue is now wrong with some probability, and a pile of clues that are occasionally wrong is the problem called Learning Parity with Noise, which nobody knows how to solve efficiently. The noise is the security. HQC, the scheme NIST picked as its backup, draws its hardness from that kind of deliberate error, and where the boundary sits between recoverable and hopeless is what the group spent the week chasing

Two surprises

The first was scale. Forty people in a building, many of them postdocs, representing a meaningful fraction of the world's working capacity for this question. "Well-studied" in cryptography means something closer to the twenty-five years of sustained attacks that AES has absorbed. Confidence here is manufactured out of years of failed attempts, and post-quantum cryptography is early.

The second was how little of the week was quantum. Almost all the hard work was classical mathematics, the quantum part a layer on top. A break will most likely come from a number theorist rather than a physicist, which makes qubit counts the wrong indicator to watch. The right one is the publications of a small community.

What the casualty list actually shows

No NIST selection has fallen. ML-KEM, ML-DSA, SLH-DSA and HQC all stand, and nothing in the HAWK result touches them. The candidates that did not make the cut are a different story. Rainbow broke in February 2022, SIKE that July, cracked on a single processor core in about an hour after years of public exposure, and now HAWK. Three since 2022, all late in the process, none of them by a quantum computer.

Faux reads that as a signal about failure modes. Sudden collapse of a deployed standard is the dramatic scenario and anunlikely one. The more probable outcome is a scheme quietly becoming uncompetitive: same algorithm, bigger keys, worse performance, an unplanned retuning of something already rolled out. Insurance against should look like diversity, two schemes resting on different mathematical foundations, which is why HQC sits alongside ML-KEM.

Still open

Three questions came out of the week without answers. How to properly cost a quantum attack, since the gap between counting operations on paper and counting what a real machine would pay is wide enough to swallow whole security levels. Whether noise tolerance in Simon-type attacks degrades smoothly or falls off a cliff, the one Faux would most like to see settled.

The findings are posted with the workshop materials and several threads continue as collaborations. This format produces follow-on papers rather than tidy conclusions.

The takeaway for security teams

Not a new deadline. NIST's transition guidance is already clear: deprecation of RSA and elliptic curve by 2030, removal by 2035. The point is that migration should be designed as something repeatable. Know where your cryptography sits, and own the ability to change an algorithm or a parameter across an enterprise without a rebuild.

The current selections are excellent and provisional, and the people analysing them treat them that way. Assessments move faster than migration programmes can, which makes agility the actual deliverable. Design for the possibility of being told something new.


 

RELATED ARTICLES