Live data from Hacker News

Willow quantum chip demonstrates verifiable quantum advantage on hardware

blog.google

191–200 of 281 posts

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#191
post #183

I would be quite worried about advances in quantum computers if I had any Bitcoin after watching this DEFCON talk: https://www.youtube.com/watch?v=OkVYJx1iLNs

Quantum is a known threat. There is enough time to fix it. Folks are working on the fixes. Cryptocurrencies would be the last thing I worry about w.r.t Quantum crypto attacks. Everything would be broken. Think banks, brokerage accounts, email, text messages - everything.

I think that’s backwards: most of the stuff you mentioned is using TLS and can switch to post-quantum algorithms with a config change, and do so incrementally with no user-visible impact - e.g. right now I’m already using PQC for many sites and about half of the traffic Cloudflare sees is using PQC:

https://radar.cloudflare.com/adoption-and-usage

In contrast, cryptocurrencies have to upgrade the entire network all at once or it’s effectively a painful fork. That effort appears to just be getting talked about now, without even starting to discuss timing:

https://github.com/bitcoin/bips/pull/1895

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#192
post #183

I would be quite worried about advances in quantum computers if I had any Bitcoin after watching this DEFCON talk: https://www.youtube.com/watch?v=OkVYJx1iLNs

Quantum is a known threat. There is enough time to fix it. Folks are working on the fixes. Cryptocurrencies would be the last thing I worry about w.r.t Quantum crypto attacks. Everything would be broken. Think banks, brokerage accounts, email, text messages - everything.

The world has already migrated through so many past now-insecure cryptography setups. If quantum computers start breaking things, people will transition to more secure systems.

In HTTPS for example, the server and client must agree on how to communicate, and we’ve already had to deprecate older, now-insecure cryptography standards. More options get added, and old ones will have to be deprecated. This isn’t a new thing, just maybe some cryptographic schemes will get rotated out earlier than expected.

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#193
post #93

Earlier quoted context omitted.

> Has it been demonstrated at all that someone who intercepts a session key is able to somehow inject into a conversation? It seems highly unlikely to me with TCP over the internet. if you can read the TLS session in general, you can capture the TLS session ticket and then use that to make a subsequent connection. This is easier as you dont have to be injecting packets live or make inconvinent packets disappear.

It seems like detecting a re-use like this should be reasonably easy, it would not look like normal traffic and we could flag this to our surveillance systems for additional checks on these transactions. In a post quantum world, this seems like something that would be everywhere anyway (and presumably, we would be using some other algo by then too). Somehow, I'm not all that scared. Perhaps I'm naive.. :}

> It seems like detecting a re-use like this should be reasonably easy, it would not look like normal traffic

I don't see why it wouldn't look like normal traffic.

> Somehow, I'm not all that scared. Perhaps I'm naive.. :}

We're talking about an attack that probably won't be practical for another 20 years , which already has counter measures that are in testing right now. Almost nobody should be worried about it.

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#194

Earlier quoted context omitted.

Every time I mention quantum computing as a threat to crypto (which I have been for years), I get downvoted to oblivion. I guess we have a lot of HODLers here. A bet on crypto is a bet against quantum computing.

I haven't once even thought of investing in crypto, and think that the technology is mostly useless and proof of work schemes should be banned on environmental grounds. Even so, I don't agree that quantum is a threat to crypto. There are already well known quantum-resistant encryption schemes being deployed live in browsers, today. Crypto can just start adopting one of these schemes today, and we're still probably de…

>There are already well known quantum-resistant encryption schemes being deployed live in browsers, today. Crypto can just start adopting one of these schemes today, and we're still probably decades away from a QC that can factor the kinds of primes that crypto security uses.

It's very strange that some people act like switching over to a post quantum cryptography scheme is trivial. Did you watch the video I replied to, which is a talk by an actual quantum computing researcher?

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#195

I would be quite worried about advances in quantum computers if I had any Bitcoin after watching this DEFCON talk: https://www.youtube.com/watch?v=OkVYJx1iLNs

Every time I mention quantum computing as a threat to crypto (which I have been for years), I get downvoted to oblivion. I guess we have a lot of HODLers here. A bet on crypto is a bet against quantum computing.

Unless advances in QC could rewrite the blockchain then there's not much to worry about. If the crypto algorithms are compromised, you coins are pretty much frozen on the chain until a new algorithms are implemented. Are you're arguing QC makes signatures/verification/mining impossible?

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#196
post #191
post #183

Earlier quoted context omitted.

Quantum is a known threat. There is enough time to fix it. Folks are working on the fixes. Cryptocurrencies would be the last thing I worry about w.r.t Quantum crypto attacks. Everything would be broken. Think banks, brokerage accounts, email, text messages - everything.

I think that’s backwards: most of the stuff you mentioned is using TLS and can switch to post-quantum algorithms with a config change, and do so incrementally with no user-visible impact - e.g. right now I’m already using PQC for many sites and about half of the traffic Cloudflare sees is using PQC: https://radar.cloudflare.com/adoption-and-usage In contrast, cryptocurrencies have to upgrade the entire network all at…

Is this a purely server side migration? Do browsers/OSs need updating too?

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#197

Earlier quoted context omitted.

Every time I mention quantum computing as a threat to crypto (which I have been for years), I get downvoted to oblivion. I guess we have a lot of HODLers here. A bet on crypto is a bet against quantum computing.

Unless advances in QC could rewrite the blockchain then there's not much to worry about. If the crypto algorithms are compromised, you coins are pretty much frozen on the chain until a new algorithms are implemented. Are you're arguing QC makes signatures/verification/mining impossible?

Why though? Who is to decide which point of the blockchain is the good one and which blocks to “reject”?

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#198
post #191
post #183

Earlier quoted context omitted.

Quantum is a known threat. There is enough time to fix it. Folks are working on the fixes. Cryptocurrencies would be the last thing I worry about w.r.t Quantum crypto attacks. Everything would be broken. Think banks, brokerage accounts, email, text messages - everything.

I think that’s backwards: most of the stuff you mentioned is using TLS and can switch to post-quantum algorithms with a config change, and do so incrementally with no user-visible impact - e.g. right now I’m already using PQC for many sites and about half of the traffic Cloudflare sees is using PQC: https://radar.cloudflare.com/adoption-and-usage In contrast, cryptocurrencies have to upgrade the entire network all at…

> In contrast, cryptocurrencies have to upgrade the entire network all at once or it’s effectively a painful fork

Bitcoin is much more centralized than the popular imagination would have you believe, both in terms of the small number of controlling interests behind the majority of the transaction capacity, and just as importantly the shared open source software running those nodes. Moreover, the economic incentives for the switch are strongly, perhaps even perfectly, aligned among the vast majority of node operators. Bitcoin is already dangerously close to, if not beyond, the possibility of a successful Byzantine attack; it just doesn't happen precisely because of the incentive alignment--if you're that large, you don't want to undermine trust in the network, and you're an easy target for civil punishment.

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#199

Earlier quoted context omitted.

Unless advances in QC could rewrite the blockchain then there's not much to worry about. If the crypto algorithms are compromised, you coins are pretty much frozen on the chain until a new algorithms are implemented. Are you're arguing QC makes signatures/verification/mining impossible?

Why though? Who is to decide which point of the blockchain is the good one and which blocks to “reject”?

Think twice. Everyone who hosts the blockchain would decide to stop because he invested in crypto, at least with some hardware costs. Beside of the small group of people that owns a quantum computer. I don't expect that this group is >50% of the people that hosts the blockchain.

Re: Willow quantum chip demonstrates verifiable quantum advantage on hardware

#200
post #183

Earlier quoted context omitted.

Quantum is a known threat. There is enough time to fix it. Folks are working on the fixes. Cryptocurrencies would be the last thing I worry about w.r.t Quantum crypto attacks. Everything would be broken. Think banks, brokerage accounts, email, text messages - everything.

The world has already migrated through so many past now-insecure cryptography setups. If quantum computers start breaking things, people will transition to more secure systems. In HTTPS for example, the server and client must agree on how to communicate, and we’ve already had to deprecate older, now-insecure cryptography standards. More options get added, and old ones will have to be deprecated. This isn’t a new thin…

> If quantum computers start breaking things, people will transition to more secure systems.

that's not really the issue, the real interesting part is existing encrypted information that three letter agencies likely have dutifully stored in a vault and that's going to become readable. A lot of that communication was made under the assumption that it's secure.

Post reply on HN