Live data from Hacker News

Bitcoin and quantum computing

nehanarula.org

1–10 of 147 posts

Re: Bitcoin and quantum computing

#2
"A CRQC is an existential threat to Bitcoin (you might believe this is very low-likehood). Your measurement of this threat should literally be:

(A) How likely you think it is a CRQC appears by a given time, multiplied by (B) How likely it is you think Bitcoin will not successfully upgrade by that time."

It would interesting to survey people about their answers.

My off the cuff answer is:

2030: A=0.05, B=0.01

2035: A=0.50, B=0.001

2045: A=~1.0, B=~0.0

I reserve the right to change my mind on these answers at any point. This is not a serious prediction.

Re: Bitcoin and quantum computing

#3

"A CRQC is an existential threat to Bitcoin (you might believe this is very low-likehood). Your measurement of this threat should literally be: (A) How likely you think it is a CRQC appears by a given time, multiplied by (B) How likely it is you think Bitcoin will not successfully upgrade by that time." It would interesting to survey people about their answers. My off the cuff answer is: 2030: A=0.05, B=0.01 2035: A=…

Karl Popper calls this a psychological probability(% chance I go to the gym today). This is different from objective probability (% chance a dice lands on 5).

Re: Bitcoin and quantum computing

#4

"A CRQC is an existential threat to Bitcoin (you might believe this is very low-likehood). Your measurement of this threat should literally be: (A) How likely you think it is a CRQC appears by a given time, multiplied by (B) How likely it is you think Bitcoin will not successfully upgrade by that time." It would interesting to survey people about their answers. My off the cuff answer is: 2030: A=0.05, B=0.01 2035: A=…

CRQC = cryptographically relevant quantum computer

Re: Bitcoin and quantum computing

#5
Good article with some questionable remarks like

> Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin?

> A: If you truly believe this, you really should value Bitcoin at 0 – it has many unnecessary components with a lot of overhead, like proof-of-work and digital signatures.

Proof of work is still necessary for two reasons:

1) to fairly distribute all coins (it's not sufficient though, e.g. Bitcoin's halvings still concentrate wealth on early miners/adopters)

2) to provide objective proof for the true transaction history, anchored in energy expenditure.

A related article on Bitcoin Core resistance to upgrading: https://murmurationstwo.substack.com/p/bitcoin-developers-ar...

Re: Bitcoin and quantum computing

#6

"A CRQC is an existential threat to Bitcoin (you might believe this is very low-likehood). Your measurement of this threat should literally be: (A) How likely you think it is a CRQC appears by a given time, multiplied by (B) How likely it is you think Bitcoin will not successfully upgrade by that time." It would interesting to survey people about their answers. My off the cuff answer is: 2030: A=0.05, B=0.01 2035: A=…

Karl Popper calls this a psychological probability(% chance I go to the gym today). This is different from objective probability (% chance a dice lands on 5).

In this case, it seems like we are rolling dice but no one is quiet sure if the dice are fair, how many sides it has and what numbers are written on the dice.

The only thing I am confident in is if it the bigger the fire, the faster the work. I want the Bitcoin community to start the work as early as possible so that it doesn't have to rush because rushing increases the chance of mistakes.

Start early, don't rush.

Re: Bitcoin and quantum computing

#7
post #5

Good article with some questionable remarks like > Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin? > A: If you truly believe this, you really should value Bitcoin at 0 – it has many unnecessary components with a lot of overhead, like proof-of-work and digital signatures. Proof of work is still necessary for two reasons: 1) to fairly distribute all coins (it's not sufficient though, e.g. Bitco…

I guess the argument goes more like: If nobody were to attempt to steal anything, you don’t need security for your ledger anyway.

Re: Bitcoin and quantum computing

#8
post #5

Good article with some questionable remarks like > Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin? > A: If you truly believe this, you really should value Bitcoin at 0 – it has many unnecessary components with a lot of overhead, like proof-of-work and digital signatures. Proof of work is still necessary for two reasons: 1) to fairly distribute all coins (it's not sufficient though, e.g. Bitco…

> 2) to provide objective proof for the true transaction history, anchored in energy expenditure.

Why do you need this if you are willing to trust other people not to steal coins or lie?

> 1) to fairly distribute all coins

Same question as above. If you don't care about perfidy, simply use the honor system for coin distribution.

If you do care about perfidy, then you should probably care about people breaking the law to steal your coins.

Re: Bitcoin and quantum computing

#9
I think we still have a 3-4 years of escape window to reach the necessary qubit range of breaking the encryption. But China is unstoppable and advancing rapidly, So crypto community needs to upgrade to Post-Quantum Cryptography before the threshold breaks.

Re: Bitcoin and quantum computing

#10
>Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin?

I've had this thought for awhile actually: how would reproducing some random number be legally "stealing" under any legal system in the world? Putting aside that cryptocurrencies have always been about "code decides" etc, that they're outside of the legal system entirely, but I'm struggling to see where there's any actual property interest here. Randomly generated numbers are not protected by IP in any way. There's no computer fraud act angle or the like here, nobody would be having so much as the slightest interaction with anyone else's private system. They'd merely be taking publicly available unprotected numbers and doing some math on them with their own quantum computer. Somebody else who has something related to those numbers is never deprived of them or interacted with in the slightest. There is nothing resembling "hacking", no flaws in the software exploited, all just math there from the start.

I can understand how suddenly a lot of proponents might wish to cling to and push the idea that it's "illegal" or "stealing", but doesn't appear to be any meat on dem bones. Maybe they hope to generate support to get laws passed banning it, though hard to see that working out either. As a practical matter seems like they're just going to have to agree on a transition to new version using PQE algorithms and try to convert over before it's too late?

Post reply on HN