Quantum Key Distribution

The Catch With Quantum Keys

8 min

BB84 works. The proof holds, the experiments succeed, and quantum key networks run today in China, across parts of Europe, and over commercial fibre.

And yet the security agencies who would benefit most tell people not to use it. That is worth understanding, because it is more instructive than the protocol.

It does not prove who you are talking to

Here is the one that surprises people.

BB84 needs that ordinary phone line for the comparing step. And it assumes you actually know who is on the other end.

If you do not, Eve just sits in the middle. She runs the whole protocol with Alice while pretending to be Bob, and with Bob while pretending to be Alice. Both of them finish happy. She has both keys and reads everything.

So you still need a way to prove identity — which means digital signatures, which means either keys you shared in advance by some other route, or exactly the post-quantum signatures that quantum key distribution was supposed to save you from.

The proof assumes perfect equipment

Security proofs assume single particles of light, flawless detectors, and no leaks. Real equipment has none of those.

Working attacks have been demonstrated against deployed systems — shining a bright light to blind a detector, exploiting the fact that real lasers sometimes emit two particles instead of one, reading timing patterns. Each has a fix, and each fix costs money and complexity.

The proof was never wrong. The gap was between the proof and the hardware.

And then there is physics

100–400 km

Practical range. Light gets lost, and you cannot amplify it.

Two points only

No routing. Adding relay stations means trusting them.

Special kit

Dedicated fibre and hardware at both ends

You cannot boost a quantum signal, because boosting means measuring and measuring destroys it. Devices that would solve this are still a research topic.

What the experts say

The American NSA and the UK's NCSC both recommend the math-based replacements rather than quantum key distribution for national security systems, for exactly these reasons.

There are real uses — a short, high-value link between two buildings you control. It is not a general replacement, and anyone selling it as one is skipping this lesson.

Worth remembering

  • It does not solve identity, so you still need ordinary digital signatures.
  • Proofs assume perfect equipment; real systems have been successfully attacked.
  • Range is a few hundred kilometres, with no relays and no routing.
  • The NSA and NCSC both recommend the math-based replacements instead.