Live data from Hacker News

IBM Q system in development with working 50 qubit processor

www-03.ibm.com

71–80 of 116 posts

Re: IBM Q system in development with working 50 qubit processor

#71

Quantum computing reminds me of time travel for all the same reasons. This is not a quick win. How would you even validate you built a quantum computer?

If you run something like Shor's algorithm you can validate it using a stopwatch and pocket calculator.

Re: IBM Q system in development with working 50 qubit processor

#73
post #70
post #45

Is this a true quantum computer? The controversy around D-Wave was confusing.

They're definitely referring to a real ("universal") quantum computer, not the quantum annealing devices of D-wave. Their computer will be able to run the Schor algorithm, if it is as advertised. If they have 20 qubits in two months, as they say they will, that seems like great progress compared to where I thought the field was. And if they have 50 within a couple years after that, it would be huge. One caveat is the…

You say "If they have 20 qubits in two months" and "if they have 50 within a couple of years". Doesn't the article say that they have 50?

I'm unclear on this, because I have yet to see a published result talking about running Shor's algorithm on a quantum computer beyond the NMR-based physical simulation and the adiabatic one (which is just annealing). What exactly is IBM claiming to have done here?

Re: IBM Q system in development with working 50 qubit processor

#74
post #67
post #29

Earlier quoted context omitted.

The implication for symmetric ciphers is that key lengths will need to be doubled. 128-bit ciphers like standard AES have 64-bit security against a quantum attack. I expect to see 256-bit keys adopted widely in the not-too-distant future. I don't know off the top of my head what the implication for key exchange would be, but I know that anything that depends on the discrete logarithm problem for security is vulnerabl…

With a quantum computer and Grover's algorithm, 128-bit AES is breakable in 2^64 steps. But the quantum computer still needs to have a 128-bit quantum memory.

I’m not sure if you mean to be disagreeing here or simply adding color, but what you’re saying is the same as the parent comment. Grover’s algorithm allows symmetric key recovery for n bits in 2^(n/2) steps; as the parent commenter said, symmetric algorithm key sizes need to be doubled. A break in 2^64 steps is the same as 64-bit security, so changing the key size to 256-bit will offer 128 bits of security.

Re: IBM Q system in development with working 50 qubit processor

#75
post #74
post #67

Earlier quoted context omitted.

With a quantum computer and Grover's algorithm, 128-bit AES is breakable in 2^64 steps. But the quantum computer still needs to have a 128-bit quantum memory.

I’m not sure if you mean to be disagreeing here or simply adding color, but what you’re saying is the same as the parent comment. Grover’s algorithm allows symmetric key recovery for n bits in 2^( n /2) steps; as the parent commenter said, symmetric algorithm key sizes need to be doubled. A break in 2^64 steps is the same as 64-bit security, so changing the key size to 256-bit will offer 128 bits of security.

Just wanted to clarify that in this case, 64-bit quantum computer is not enough to break said 64-bit security, still need 128 bits of memory.

Re: IBM Q system in development with working 50 qubit processor

#76
post #11

The article appears to be saying that they are offering an actual quantum computer as a service, but as I recall, their previous offering was a simulation of a quantum computing environment. Yet, this same article refers to that thing as if it were a real QC. This makes me skeptical that the thing being offered here is a real quantum computer...Anyone here have any insight into whether this is legitimate?

It's both a real quantum computer and a simulation - at the same time - but you don't know until you observe the results!

Re: IBM Q system in development with working 50 qubit processor

#77
post #70

Earlier quoted context omitted.

They're definitely referring to a real ("universal") quantum computer, not the quantum annealing devices of D-wave. Their computer will be able to run the Schor algorithm, if it is as advertised. If they have 20 qubits in two months, as they say they will, that seems like great progress compared to where I thought the field was. And if they have 50 within a couple years after that, it would be huge. One caveat is the…

You say " If they have 20 qubits in two months" and " if they have 50 within a couple of years". Doesn't the article say that they have 50? I'm unclear on this, because I have yet to see a published result talking about running Shor's algorithm on a quantum computer beyond the NMR-based physical simulation and the adiabatic one (which is just annealing). What exactly is IBM claiming to have done here?

I read it as saying they've passed some development milestones on 50 which is certainly all one could expect before the release of the 20.

Re: IBM Q system in development with working 50 qubit processor

#79
post #37
post #22

Earlier quoted context omitted.

Do you know what the implications are for symmetric ciphers or [elliptic curve] Diffie-Hellman key exchange? I.e. will forward secrecy still hold up against such future quantum computing?

SIDH ( https://en.wikipedia.org/wiki/Supersingular_isogeny_key_exch... ) is one of the few popular post-quantum variants of DH key exchange, and it supports forward secrecy as well.

One nice property of ECC pubkeys is that they easily fit into UDP packets, URIs and other very compact data structures. Currently all post-quantum schemes have fairly bulky pubkeys.

Re: IBM Q system in development with working 50 qubit processor

#80
post #62

Earlier quoted context omitted.

I was responsible for a couple of those parents and I can tell you that's all nonsense. IBM employees are encouraged to patent _anything_, regardless of how useless or silly it may be.

Isn't that kind of the best strategy? You -- as a corporation -- want to make investments for the future. Each patent is a possible income stream in the future if the technology behind the patent somehow becomes "big". So it makes sense to patent everything you can, just for the chance of one of them to go "big". Companies can't just spend money on research expecting no return, at least not for a long time. That's wh…

No I mean I saw some patents on downright silly stuff. Things completely unrelated to IBM's business or even tech. IBM just wants to wave that number around.
Post reply on HN