Live data from Hacker News

Bitcoin and quantum computing

nehanarula.org

31–40 of 147 posts

Re: Bitcoin and quantum computing

#31
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

BTC thrives on hype and hope that others will buy in. A successful quantum attack would obliterate the value and future value.

Re: Bitcoin and quantum computing

#32
post #29
post #22

Earlier quoted context omitted.

A hard fork implies a difference in consensus rules, and what do you propose that difference be? Existing wallets need to actively commit to some PQ signature mechanism, prior to Q-day.

Even if Q-day means there is a way to deterministically retrieve any private key from a public key (is that what it means? or is the blast radius of q-day contained? This is a bit above my level of cryptography), I’m sure we could come up with something to minimize the damage. In the worst case, it might involve a claim process with an authority or consensus mechanism to prove who the rightful owner of the funds is a…

> Q-day means there is a way to deterministically retrieve any private key from a public key

That's exactly what it means. (Note also that under ECDSA you can retrieve a public key from a valid signature).

How do you prove anything, after the key material is compromised?

Re: Bitcoin and quantum computing

#33
post #23
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

In theory nothing prevents that but it would be so contentious that the backlash (e.g. 90% drawdown) may be even worse than just letting the hacks stand.

Letting the hack stand means the chain comes to a halt and all value is destroyed? Even if you’re a staunch bitcoin purist, I don’t think that’s the path you want to go on.

Re: Bitcoin and quantum computing

#34
post #23
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

In theory nothing prevents that but it would be so contentious that the backlash (e.g. 90% drawdown) may be even worse than just letting the hacks stand.

The Bitcoin “value overflow incident” on August 15, 2010 is probably the closest thing and that didn't affect the price much (though one BTC was around 8c at the time)

Re: Bitcoin and quantum computing

#35
The thing that supposedly sets Bitcoin apart from other cryptocurrencies is that it's deflationary and 'immutable', in that Satoshi is gone forever and any deviation of Bitcoin from his golden idea will result in undermining its essence. If Bitcoin can get quantum-attacked then, from a technical point of view, nothing will be lost. The Bitcoin core devs can issue a word-of-god statement stating that they'll roll back the chain to before the attack, and all is well. Then they'll change the cryptography. But at that point, is it still Bitcoin? Because you've undermined the immutability. If the core devs can just say "this core property of Bitcoin is now something completely different", who's to say that they won't change their minds about the deflationary nature in the future? All credibility will be lost. Now, if you accept that, is perhaps all credibility lost already? ...

Re: Bitcoin and quantum computing

#36
post #29
post #22

Earlier quoted context omitted.

A hard fork implies a difference in consensus rules, and what do you propose that difference be? Existing wallets need to actively commit to some PQ signature mechanism, prior to Q-day.

Even if Q-day means there is a way to deterministically retrieve any private key from a public key (is that what it means? or is the blast radius of q-day contained? This is a bit above my level of cryptography), I’m sure we could come up with something to minimize the damage. In the worst case, it might involve a claim process with an authority or consensus mechanism to prove who the rightful owner of the funds is a…

> How do you prove anything, after the key material is compromised?

It’s a blockchain, so the simplest would be chain of custody until the chain points undeniably at you. This is not a pure cryptographic device, some social intervention might be needed here.

Re: Bitcoin and quantum computing

#37
post #26

Somewhat ironic question, but as ETFs holdings of BTC continue to grow, is there a possibility that the custodians of those ETFs start to have a backup plan for ETF holders or create an alliance to push a fork forward? The management fee those companies generate is non-trivial, so they're incentivized to stay ahead of this. Now, of course, the irony here would be traditional finance infrastructure winning out over de…

Yes, if you read the fine print on the ETFs they tell you what they will do in case of a fork. Usually their custodian picks the "winning" chain at their discretion. There's a similar (although reversed) situation with stablecoins.

Re: Bitcoin and quantum computing

#38
Apparently bitcoin foundation is already working on SHRINCS and SHRIMPS. But whether they will forcibly revoke keys of satoshi and all early bitcoin whales or not is another question!

Re: Bitcoin and quantum computing

#39
post #11

As was alluded to in the comments, my colleagues at Blockstream Research are doing some work on this with mechanisms called SHRINCS and SHRIMPS. Of course, inventing and demonstrating a quantum-resistant signature mechanism isn't the same thing as deploying it in consensus or upgrading everyone's UTXOs to it, and it's fair to say that there are many steps in between!

Also, LetsEncrypt is very cool! Thanks for working on it.

Re: Bitcoin and quantum computing

#40
post #33
post #23

Earlier quoted context omitted.

In theory nothing prevents that but it would be so contentious that the backlash (e.g. 90% drawdown) may be even worse than just letting the hacks stand.

Letting the hack stand means the chain comes to a halt and all value is destroyed? Even if you’re a staunch bitcoin purist, I don’t think that’s the path you want to go on.

The chain wouldn't halt because mining won't be affected by quantum. If you see hacks happening you could race to move your coins into a PQ wallet before the hackers do. I'm assuming that PQ software will be available before the hacks. I agree that this is a very bad scenario.
Post reply on HN