Live data from Hacker News

A cryptography engineer's perspective on quantum computing timelines

words.filippo.io

181–190 of 260 posts

Re: A cryptography engineer's perspective on quantum computing timelines

#181
post #130

> They weirdly[1] frame it around cryptocurrencies and mempools and salvaged goods or something [...] > [1] The whole paper is a bit goofy: it has a zero-knowledge proof for a quantum circuit that will certainly be rederived and improved upon before the actual hardware to run it on will exist. They seem to believe this is about responsible disclosure, so I assume this is just physicists not being experts in our field…

> Given the limited transaction throughput, migrating all vulnerable coins would take years ... How? I just googled: about 55 million addresses with bitcoin in them, about 144 blocks per day, about 3000 to 5000 tx per block. In something like 100 days all the coins would be moved to other addresses. I gotta say it'd be hilarious if to speed up that migration-to-quantum-resistant-addresses process, the Bitcoin communi…

The signatures would be larger than they are today. The article touches on it but doesn't give any estimates. What I read online were claims from 10 to 100 times larger than currently.

This paper claims 60-70% throughput loss with 59 times(!) larger storage space requirements.

https://jbba.scholasticahq.com/article/154321.pdf

Re: A cryptography engineer's perspective on quantum computing timelines

#182
post #179
post #130

> They weirdly[1] frame it around cryptocurrencies and mempools and salvaged goods or something [...] > [1] The whole paper is a bit goofy: it has a zero-knowledge proof for a quantum circuit that will certainly be rederived and improved upon before the actual hardware to run it on will exist. They seem to believe this is about responsible disclosure, so I assume this is just physicists not being experts in our field…

"This is one of the few domains where having access to a quantum computer ahead of others could translate directly into financial gain" Doubt, the moment people get vocal about their fund being stolen that will be it for crypto, it will crash the bank run. The only way it could work is that if you steal too little to be noticed, which will also be too little to finance your venture...

May I introduce you to a concept called "shorting"? You can make money from falling prices without selling the stolen coins. As I said just moving Satoshi's coins would lead to lots of panic selling.

The snarky reply would be that having their funds stolen is not something that seems to discourage people from having cryptocurrencies as it happens all the time:

https://www.web3isgoinggreat.com/

Re: A cryptography engineer's perspective on quantum computing timelines

#183

It should be noted that if indeed there has not remained much time until a usable quantum computer will become available, the priority is the deployment of FIPS 203 (ML-KEM) for the establishment of the secret session keys that are used in protocols like TLS or SSH. ML-KEM is intended to replace the traditional and the elliptic-curve variant of the Diffie-Hellman algorithm for creating a shared secret value. When FIP…

That was my position until last year, and pretty much a consensus in the industry. What changed is that the new timeline might be so tight that (accounting for specification, rollout, and rotation time) the time to switch authentication has also come. ML-KEM deployment is tangentially touched on in the article because it's both uncontroversial and underway, but: > This is not the article I wanted to write. I’ve had a…

[deleted]

Re: A cryptography engineer's perspective on quantum computing timelines

#184

Earlier quoted context omitted.

I agree with you that one must prepare for the transition to post-quantum signatures, so that when it becomes necessary the transition can be done immediately. However that does not mean that the switch should really be done as soon as it is possible, because it would add unnecessary overhead. This could be done by distributing a set of post-quantum certificates, while continuing to allow the use of the existing cert…

How do you do revocation or software updates securely if your current signature algorithm is compromised?

I do not understand the fixation on authentication/signatures. They have different threat characteristics:

You cannot retroactively forge historical authentication sessions, and future forgery ability does not compromise past data, and it only matters for long-lived signed artifacts (certificates, legal documents, etc.), yet the thread apparently keeps pivoting to signature deployment complexity?

I do not get it.

Re: A cryptography engineer's perspective on quantum computing timelines

#185

Building out a supercomputer capable of breaking cryptography is exactly the kind of thing I expect governments to be working on now. It is referenced in the article, but the analogy to the Manhattan Project is clear. Prior to 1940 it was known that clumping enough fissile material together could produce an explosion. There were engineering questions around how to purify uranium and how to actually construct the weap…

>governments are cooking up exotic technologies behind closed doors which I personally tend to doubt. You don't use zero days immediately. You stockpile them for when the time is right. A quantum computer is the ultimate zero day.

Maybe I should be more clear. Quantum computers already exist. Nuclear fission was already known about prior to the manhattan project.

When I say they’re not hiding “exotic technologies” I’m referring to things that would at a minimum win a Nobel prize. Alien technologies like antigravity or faster than light travel that people sometimes talk about. I am not even talking about things like Stuxnet which was impressive but not revolutionary.

Re: A cryptography engineer's perspective on quantum computing timelines

#186

Earlier quoted context omitted.

Can anyone give the next layer of detail here? I understand the implications of this analogy, but looking for the underlying reasons the analogy is apt.

AIUI, the scientists achieved a self-sustaining nuclear chain reaction around 1943. That was the hard part, not even a small bomb yet, but a bomb just needed more fuel and scale. Fault tolerance is the hard part for QC, once it's achieved, the difference between factoring 35 and RSA-2048 is an engineering challenge, not an impossibility.

Fault tolerance is a hard problem, assembling qubits for simultaneous gate operations is another hard problem. There are several dozen others.

It is exceptionally unlikely CRQC will be achieved in our lifetimes, if ever. The closer example is economically-viable fusion power production, which today has better odds than CRQC but remains solidly in the "maybe" zone after decades of global investment. Even though fusion weapons had been achieved half a century beforehand.

The bombs were actually relatively easy problems, in the scheme of things.

It is never wise to listen to people who's jobs and funding are connected to the development of a technology on when that technology will arrive. The answer is always "soon".

Re: A cryptography engineer's perspective on quantum computing timelines

#187

It should be noted that if indeed there has not remained much time until a usable quantum computer will become available, the priority is the deployment of FIPS 203 (ML-KEM) for the establishment of the secret session keys that are used in protocols like TLS or SSH. ML-KEM is intended to replace the traditional and the elliptic-curve variant of the Diffie-Hellman algorithm for creating a shared secret value. When FIP…

Super important: Don't replace traditional (elliptic curve) Diffie-Hellman with ML-KEM, but enhance it by using hybrid key exchanges. Done thusly, you need to break both the classical and post-quantum cryptography to launch an attack.

If you worry about a >=1% risk of quantum attacks being available soon, you should also worry about a >=1% risk of the relatively new ML-KEM being broken soon. The risk profile is pretty comparable. For both cases there are credible expert opinions that say the risk is incredibly overrated and credible expert opinions that say the risk is incredible underrated.

Filippo has linked opinions that quantum attacks are right around the corner. People like Dan Bernstein (djb) are throwing all their weight to stress that anything but hybrids are irresponsible. I don't think there is anybody that says "hybrids are a bad idea", just people that want to make it easy to choose non-hybrid ML-KEM.

Re: A cryptography engineer's perspective on quantum computing timelines

#188
Given that quantum computing (QC) can speed up training of neural networks (LLMs), it would be wise for Google to invest into QC as much as possible.

Google with Softbank invested about $230M into QC last year. Microsoft, IBM and Google have spent on QC $15B combined, through all of the time they researched it. $15B spent in 20 years, less than $1B per year, by three companies.

Google spent upwards of $150B last year in datacenters.

This may tell us something about how close we are to a working quantum computing.

Re: A cryptography engineer's perspective on quantum computing timelines

#189
post #158

I think people have to be extremely careful with this kind of opinion. In particular seeing such a push for post-quantum crypto while the current state of the art for quantum factorisation is 15 and 21 and the fact that current assumptions (for KEM in particular) are clearly not as studied as dlog. It's maybe good to remember that SIDH was broken in polynomial time by a classical computer 3 years ago... I'm really co…

The largest number factorised on a quantum computer is 8,219,999 on a D-Wave machine (a quantum annealer, so not capable of running Shor's, but capable of being an actual shipping product you can use, unlike gate model machines). https://www.nature.com/articles/s41598-024-53708-7 > Overall, 8,219,999 = 32,749 × 251 was the highest prime product we were able to factorize within the limits of our QPU resources. To the…

This is quantum annealing and it has nothing to do with Shor (I should have been precise sorry).

It is not clear at all that quantum annealing provides any speedup compared to a classical computer.

Re: A cryptography engineer's perspective on quantum computing timelines

#190
post #158

I think people have to be extremely careful with this kind of opinion. In particular seeing such a push for post-quantum crypto while the current state of the art for quantum factorisation is 15 and 21 and the fact that current assumptions (for KEM in particular) are clearly not as studied as dlog. It's maybe good to remember that SIDH was broken in polynomial time by a classical computer 3 years ago... I'm really co…

As long as a hybrid approach is taken what is there to worry about? Whereas not adopting PQC in a timely manner is obviously a gamble.

I agree, but the blog post was specifically ruling out hybrid approach.
Post reply on HN