The basis of much of modern security relies on cryptography, with the ability to keep data shielded from prying eyes.

RSA, the company behind the big RSA Conference 2023 held this week in San Francisco, was literally built on the foundation of the RSA cryptographic algorithm. A highlight of any given year at the RSA Conference is the Cryptographer's Panel, where experts debate issues and have been known to go on long tangents about security issues. During the 2023 event, the panel tackled a dizzying array of topics including the enduring impact of the Snowden NSA data leaks, the relevance of blockchain and the risks of artificial intelligence (AI).

[ Follow SDXCentral’s complete RSA Conference 2023 coverage ]

The panel spent the most time on the issue of Quantum computing and what it actually means for enterprise security today and in the future.

"Thirty years ago there were three new promising technologies  one of them was AI, the second one was cryptography and the third one was the the invention was quantum computing," Adi Shamir, the 'a' in RSA and professor of computer science at the Weizmann Institute in Israel said.

While both AI and cryptography have delivered tangible benefits to the world, Shamir argued that to date Quantum computing has done little.

"If I'm trying to characterize what has been delivered in practice in quantum computing. I must say that the main thing which has been delivered is more promises," Shamir said. "Almost nothing in practice has been delivered, in the sense that as of today, not a single technical problem has been shown to be solvable by one of the available quantum computers faster than a classical computer."

Does Quantum Computing pose a real risk to cryptography?

There have been concerns expressed in Academia and by governments that quantum computing could pose some form of future risk to existing cryptography.

Shamir, however, isn't worried, at least not today. In his view, though quantum computers exist today, it won't be for another 30 or 40 years until they are able to pose a risk.

"So it's not an immediate threat at the moment but things you say today using all the algorithms such as RSA or elliptic curve cryptography might become decryptable in the future," Shamir said.

Anne Dames, distinguished engineer at IBM argued that there is in fact a need to look at the risks of quantum computing today.

"When we think about the current systems that we have, we have to think about what systems might be threatened as a result of a potential quantum computer," Dames said. "Right now we understand that the public key cryptography system are the ones that are most vulnerable."

Multiple U.S government agencies, including most notably the National Institute of Standards and Technology (NIST) have been working on developing so-called, post-quantum cryptography. The goal of post-quantum cryptography is to have algorithms that are considered to be resistant to potential decryption by a quantum computer

"We are in an interesting position. because powerful organizations explicitly NSA and NIST are both seeing a threat of quantum computing and calling for quantum resistant algorithms," cryptographer Whitfield Diffie said during the panel. "So whether or not quantum computing ever comes along, there's a significant likelihood that we're going to face requirements for designing systems that call for quantum resistant algorithms."

Snowden, AI and Blockchain (oh my!)

A decade ago in 2013, NSA contractor Edward Snowden leaked information about secret government snooping efforts across the internet.

Radia Perlman, fellow at Dell Technologies, argued that from her perspective there hasn't been a long-term enduring impact from the Snowden leaks.

"The notion that the government is kind of using all the metadata in order to spy on us, it was kind of obvious that they would do that," Perlman said.

She went on to note that in comparison to the expansive volume that merchants and vendors of all types collect on users today, she's not too worried about data tracking.

As usual, Shamir took a contrarian viewpoint, noting that in his view the Snowden leaks continue to have an impact. He noted that as a result of the leaks U.S. intelligence lost a large fraction of the  sources of information they had. Shamir commented that sources and methods are considered the crown jewels of spycraft.

The panel also briefly touched on AI with Shamir admitting he was wrong about a prediction he made in 2022 that AI wouldn't be widely used by attackers. As a result of the pervasiveness and effectiveness of ChatGPT, Shamir now expects to see AI misused on a massive scale. In particular he expects to see it used in social engineering campaigns to defraud users.

Blockchain has also been the subject of debate for multiple years on the cryptographers panel and the 2023 event was no exception. Once again panelists were less than enthusiastic about the technology.

"I try to really urge people when you're working on something, start with what problem are you solving, look at different ways of doing it and then choose the best thing," Perlman said. "If blockchain happens to be the best thing, which is unlikely, you know…. by all means."