▲ 4 r/u_MohsenFatemiii+2 crossposts

If quantum computers can brute-force passwords much faster, wouldn't the verification step still be the bottleneck?

I keep hearing that quantum computers could eventually break passwords or defeat current cryptographic systems. But there's something about this that I don't fully understand.

Let's say an attacker doesn't have access to the password database or the stored password hashes. They only have access to the actual login system, where they can submit a password and the server tells them whether it's correct or not.

A quantum computer might be able to search through a huge number of possible passwords much faster than a classical computer. But wouldn't the attacker still need to have each candidate password verified by the server?

In other words:

Quantum computer: generates/searches possible passwords extremely quickly

Classical server: checks whether each password is correct

Wouldn't the classical server (and things like rate limiting, network latency, account lockouts, etc.) become the actual bottleneck?

Also, I understand that this is different if the attacker has stolen the database and has the password hashes. In that case, they can perform an offline attack and potentially implement the verification function as part of a quantum algorithm, without asking the real server for every guess.

So my question is specifically about the online attack scenario:

If the attacker only has access to a login/verification endpoint, how would a quantum computer actually provide an advantage? Can a quantum algorithm somehow perform the verification without having direct access to the server for every candidate, or would the classical server fundamentally limit the speed of the attack?

I'm trying to understand where my intuition is wrong here.

reddit.com
u/MohsenFatemiii — 11 days ago