Live data from Hacker News

Quantum Resistance and the Signal Protocol

signal.org

131–135 of 135 posts

Re: Quantum Resistance and the Signal Protocol

#131

Earlier quoted context omitted.

Good point, I said computation, but I was thinking more of the storage and routing pieces of that rather than the gates, likely because I don’t understand quantum gates very well. Most of the quantum ecc I have read about was in the storage lifetime and retrieval process. Basically what I mean is that classical computing can split things up during storage or routing to reduce coupling, but quantum can’t do this becau…

WiFi, 5G, PCIe, Ethernet, QR codes, and pretty much any other classical communication protocol uses error correcting codes where classical bits need to be sent in blocks, e.g. for PCIe6, blocks of 256 physical bytes are sent, but only 242 of information is transmitted because the rest is used to enforce some classical correlation for the purposes of error correction. We can not send smaller packets of data (unless we…

What makes qbits valuable is that they scale superlinearly the more of them you have entangled together. This means 8 individual qbits can store less information than 8 entangled qbits. Since they have to remain entangled to do valuable work, you can't physically separate them to prevent interference the way you could with classical bits. This is actually really well demonstrated in all the protocols you mention. None of those protocols operates on a bus that can send 256 bytes of data all together at once. They all chunk the data and send a small number of symbols at a time.

For example in PCIe each lane can only cary one bit at a time in each direction. In typical consumer equipment, there are at most 16 lanes of PCIe (eg a graphics card socket) meaning there can only be at most 16 bits (2 bytes) on the wire at any given time, but the bits are sent at a very high frequency allowing for high transfer rates. This only works because taking those 256 bytes and sending them one by one (or 16 by 16) over the wire doesn't lose information.

Re: Quantum Resistance and the Signal Protocol

#132

Earlier quoted context omitted.

WiFi, 5G, PCIe, Ethernet, QR codes, and pretty much any other classical communication protocol uses error correcting codes where classical bits need to be sent in blocks, e.g. for PCIe6, blocks of 256 physical bytes are sent, but only 242 of information is transmitted because the rest is used to enforce some classical correlation for the purposes of error correction. We can not send smaller packets of data (unless we…

What makes qbits valuable is that they scale superlinearly the more of them you have entangled together. This means 8 individual qbits can store less information than 8 entangled qbits. Since they have to remain entangled to do valuable work, you can't physically separate them to prevent interference the way you could with classical bits. This is actually really well demonstrated in all the protocols you mention. Non…

I believe there are a couple of misconceptions in your first paragraph (but it is also plausible that both of us are talking past each other due to the lack of rigor in our posts). Either way, here is my attempt at what I believe is a correction:

- Both classical probabilistic bits and qubits need exponential amount of memory to write down their full state (e.g. stochastic vectors or kets). The exponential growth, on its own, is not enough to explain the conjectured additional computational power of qubits. This is discussed quite well in the Aaronson lecture notes.

- Entanglement does not have much to do with things being kept physically in contact (or proximity), just like correlation between classical bits has little to do with bits being kept in contact.

- Nothing stops you from sending/storing entangled bits one by one, completely separate from each other. If anything, the vast majority of interesting uses of entanglement very much depend on doing interesting things to spatially separate, uncoupled, disconnected, remote qubits. Sending 1000 qubits from point A to point B does not require a bus of width 1000, you can send each qubit completely separately from the rest, no matter whether they are entangled or not.

- Not even error correction requires you to work with "big" sets of qubits at the same time. In error correcting codes, the qubits are all entangled, but you still work with qubits one by one (e.g. see Shor's syndrome measurement protocol).

- I strongly believe your first sentence is too vague and/or wrong: "What makes qbits valuable is that they scale superlinearly the more of them you have entangled together". As I mentioned, the exponential growth of the "state descriptor" is there for the classical probabilistic computers, which are believed to be no more powerful than classical deterministic computers (see e.g. derandomization and expander graphs). Moreover, Holevo's theorem does basically say that you can not extract more than n bits of information from n qubits.

- Another quote: "Since they have to remain entangled to do valuable work, you can't physically separate them to prevent interference" -- yes, you can and very much do separate them in the vast majority of interesting applications of entanglement.

Re: Quantum Resistance and the Signal Protocol

#133

Earlier quoted context omitted.

Can you explain how qubits are physically implemented in a real-world computer? I just cannot wrap my mind around what they're made of and how they operate in the physical reality.

Disclaimer: No where close to an expert. My understanding of the more popular superconducting types is that a bit of superconductor is connected up to a junction that allows quantum tunneling of electron pairs. The number of electron pairs that tunnel through the junction determines the state and the state is read out by an exotic electrometer. As for how the chip itself is made, as far as I know it's a relative stan…

I need to find a video illustrating all this aha

Re: Quantum Resistance and the Signal Protocol

#134

Very well written and digestable. I have much respect for the Signal people. However I'd like to mention using usernames instead of phone numbers has been met with the classic "soon™" response for years now. When will they actually do it? This the the only thing I really really dislike about Signal - their lack of communication on oddly specific things. Like them holding back the codebase for months on GitHub so as t…

As much as I hate cryptocurrencies and the MobileCoin effort (that should never have been part of Signal IMO), I think that "playing with MobileCoin" was low-risk as a side project (that never took off as far as I know?).

However, moving from phone numbers to username seems very tricky to me.

- They have built their system around the idea that they can use the address book that already exists in users phones and not learn about it. It works (at least in theory), it's just that some people don't trust them for that. Or some people have a threat model that is incompatible with that, I suppose. Changing their whole system for a very small minority of very vocal users is a risk. Also if going for usernames makes them collect more metadata, then other users will complain (or maybe even the same that currently complain about the phone numbers).

- Most people use WhatsApp, of which Signal is an improvement in terms of privacy. Those people don't give a damn about sharing the phone number, so the reason why they don't move to Signal is surely not this (because Signal certainly doesn't do worse with the phone number). So changing that would be a risk.

Moving to usernames is a cost, and a risk. All for a few very vocal users who probably have a threat model that requires it. I would understand if they never moved to username, and I would be fine with it.

Re: Quantum Resistance and the Signal Protocol

#135

Earlier quoted context omitted.

Yet if you followed the money those programs are funded by government adjacent entities that usually have 3 letters.

None of those researchers have been subverted by academic grants.

But those grants specifically influence that which is researched
Post reply on HN