Live data from Hacker News

How to compute a 256 bit elliptic curve key with 50M Toffoli gates

arxiv.org

11–20 of 46 posts

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#11
post #7
post #6

"At 10% threshold, assuming a 10-μs code cycle and non-local connections, one key can be generated every 10 minutes using 6000 modules with 1152 physical qubits each." 1152 qubits sounds like the D-Wave chips. So does that mean 6000 D-wave chips ? Even if you reverse the calculation, that would be 60000 minutes on 1 chip, which is about 42 days only, so. Quantum Too Good

Can those even perform shor's? I've read somewhere those are not suitable but I'm limited by a lack of actual knowledge here.

The D-Wave ones surely can't (theoretically unproven if it's doing anything 'useful', even if 'quantum').The ones that others have, theoretically can in the 'awesome future', but as yet can't (too noisy).

Hype aside - the largest number factored using Shor on a physical device is 21 (unclear if they actually used the result of the factoring to design the circuits like they did with 15).

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#12

Earlier quoted context omitted.

In the realm of quantum computing, it always has

> In the realm of quantum computing, it always has No: https://en.wikipedia.org/wiki/Post-quantum_cryptography

PQC is very immature.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#13
post #3

Doesn’t this mean crypto has a major problem ?

Subtext: This is about quantum computers, which have been known to break RSA and ECC for the order of 30-ish years now.

*known to be able to

No quantum computer has ever been used for that purpose in real life, however.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#14
post #7

Earlier quoted context omitted.

Can those even perform shor's? I've read somewhere those are not suitable but I'm limited by a lack of actual knowledge here.

The D-Wave ones surely can't (theoretically unproven if it's doing anything 'useful', even if 'quantum').The ones that others have, theoretically can in the 'awesome future', but as yet can't (too noisy). Hype aside - the largest number factored using Shor on a physical device is 21 (unclear if they actually used the result of the factoring to design the circuits like they did with 15).

That seems like a damning critique, but the reality is that quantum capabilities can and likely will advance as a series of step functions. The quantum machines we can build now are so noisy that we can’t even factor 3 digit numbers. However low nois quantum computers are on the drawing board and would bring many order of magnitude improvements nearly overnight.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#15

Earlier quoted context omitted.

Subtext: This is about quantum computers, which have been known to break RSA and ECC for the order of 30-ish years now.

*known to be able to No quantum computer has ever been used for that purpose in real life, however.

Kind of goes without saying when nobody has built a quantum computer of the type we are talking about. No general purpose error corrected quantum computer has been used to do anything because they don't exist yet.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#16

Earlier quoted context omitted.

> In the realm of quantum computing, it always has No: https://en.wikipedia.org/wiki/Post-quantum_cryptography

PQC is very immature.

Generally true, but Google has started using the stuff in production: https://cloud.google.com/blog/products/identity-security/why...

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#17
post #3

Doesn’t this mean crypto has a major problem ?

So its mostly just public-key encryption and its been a known issue since about 1994. We are still nowhere near making quantum computers that can crack them so its not an urgent thing. There has been a lot of research into alterantives though.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#18

Earlier quoted context omitted.

PQC is very immature.

Generally true, but Google has started using the stuff in production: https://cloud.google.com/blog/products/identity-security/why...

But its still bleeding edge. Its been used for experimental purposes but always in combination with a traditional algorithm (so if its broken the traditional algo still secures things). Its definitely not trusted yet.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#19

Earlier quoted context omitted.

In the realm of quantum computing, it always has

> In the realm of quantum computing, it always has No: https://en.wikipedia.org/wiki/Post-quantum_cryptography

I agree with you that the statement is overly broad, but the person is referring to asymmetric cryptography in the past tense, making me read it as not about PQC because PQC is indeed the fix for the stated problem but must be applied first and until then, indeed we've always known QC are going to be an issue that needs solving.

Re: How to compute a 256 bit elliptic curve key with 50M Toffoli gates

#20
post #15

Earlier quoted context omitted.

*known to be able to No quantum computer has ever been used for that purpose in real life, however.

Kind of goes without saying when nobody has built a quantum computer of the type we are talking about. No general purpose error corrected quantum computer has been used to do anything because they don't exist yet.

I don't think that's common knowledge. It's commonly accepted truth in the industry, but particularly when most people think of military/spies as secretly X years ahead (pick a number) of what the public knows is possible, the tech sector in general can't be expected to know this. It's good to add this in a thread with a headline that sounds like anyone using ecc keys might have a big problem.
Post reply on HN