Live data from Hacker News

Quantum computing bombshells that are not April Fools

scottaaronson.blog

31–40 of 118 posts

Re: Quantum computing bombshells that are not April Fools

#31

Earlier quoted context omitted.

> Crypto signature library written from scratch. That's a sentence every white hat cryptography enthusiast loves to hear lol.

It's a very simple signature algorithm. They're welcome to try and crack it. If there is an issue with it, it shouldn't be hard to identify within those few hundred lines. Nobody found any issues in the last 5 years though. Isn't it a good thing that there exists at least one blockchain in the world which isn't based on the same crypto library used by every other project? What if those handful of libraries have a bac…

> What's wrong with hedging?

To be (an actual) hedge, something needs to be very solidly understood (by the purchaser), a very solid investment in its own right, and either reverse correlated or independently correlated specifically with a particular asset being hedged.

And not based on analysis of one "hedging" scenario, because both are going to be owned over a huge distribution of scenarios.

Probably the worst indicator of an investment being credible, is a promoter who has to stoop to the floor to ask "What's wrong with hedging?", as if that manipulative bon mot was ever in question, or was the relevant question.

If a motivated promoter can only make a very bad case, believe them.

And, if an "expert" attempts to get respect for their work from non-experts, instead of from other experts, there is something very wrong. Because the former makes no sense.

--

If you don't know how to get respect from experts, study more, and figure out how to trash what you have. Counterintuitive. But if you have anything original right, thats how to find it. Identify it. Purify it. And be in a better position to build again, with just a little more leverage, and repeat. Or communicate it clearly to someone qualified to judge it.

You won't have to persuade anyone.

If you have to persuade someone, either you don't have something, or you don't understand what you have well enough to properly identify and communicate it.

You have ambition. You have motivation. You have interest. You follow through and build. That is it. Don't stop. Ego derails ambition. Kill your darlings. Keep going.

Re: Quantum computing bombshells that are not April Fools

#32
post #6

One thing I find rather amazing about all of this is the degree to which the Bitcoin community has tried, for years, to claim that quantum computers will be another other than a complete break. Sure, it takes a pretty nice quantum computer or a pretty good algorithm or a degree of malice on the part of miners to break pay-to-script-hash if your wallet has the right properties, but that seems like a pretty weak excuse…

If Bitcoin is broken then your bank encryption and everything else is broken also. As far as I know quantum computers still can't even honestly factor 7x3=21, so you are good. And the 5x3=15 is iffy about how honest that was either. https://news.ycombinator.com/item?id=45082587 Bitcoin uses 256-bit encryption, it's a universe away from 5x3=15.

You are assuming that progress on factoring will be smooth, but this is unlikely to be true. The scaling challenges of quantum computers are very front-loaded. I know this sounds crazy, but there is a sense in which the step from 15 to 21 is larger than the step from 21 to 1522605027922533360535618378132637429718068114961380688657908494580122963258952897654000350692006139 (the RSA100 challenge number).

Consider the neutral atom proposal from TFA. They say they need tens of thousands of qubits to attack 256 bit keys. Existing machines have demonstrated six thousand atom qubits [1]. Since the size is ~halfway there, why haven't the existing machines broken 128 bit keys yet? Basically: because they need to improve gate fidelity and do system integration to combine together various pieces that have so far only been demonstrated separately and solve some other problems. These dense block codes have minimum sizes and minimum qubit qualities you must satisfy in order for the code to function. In that kind of situation, gradual improvement can take you surprisingly suddenly from "the dense code isn't working yet so I can't factor 21" to "the dense code is working great now, so I can factor RSA100". Probably things won't play out quite like that... but if your job is to be prepared for quantum attacks then you really need to worry about those kinds of scenarios.

[1]: https://www.nature.com/articles/s41586-025-09641-4

Re: Quantum computing bombshells that are not April Fools

#36
post #6

One thing I find rather amazing about all of this is the degree to which the Bitcoin community has tried, for years, to claim that quantum computers will be another other than a complete break. Sure, it takes a pretty nice quantum computer or a pretty good algorithm or a degree of malice on the part of miners to break pay-to-script-hash if your wallet has the right properties, but that seems like a pretty weak excuse…

Call me crazy, but I think if bitcoin is ever broken they're more likely to move to a centralized ledger than a more secure decentralized ledger. Roughly nobody invested in bitcoin cares about the original mission, they just care about their asset prices.

Re: Quantum computing bombshells that are not April Fools

#37

Earlier quoted context omitted.

It's a very simple signature algorithm. They're welcome to try and crack it. If there is an issue with it, it shouldn't be hard to identify within those few hundred lines. Nobody found any issues in the last 5 years though. Isn't it a good thing that there exists at least one blockchain in the world which isn't based on the same crypto library used by every other project? What if those handful of libraries have a bac…

> What's wrong with hedging? To be (an actual) hedge, something needs to be very solidly understood (by the purchaser), a very solid investment in its own right, and either reverse correlated or independently correlated specifically with a particular asset being hedged. And not based on analysis of one "hedging" scenario, because both are going to be owned over a huge distribution of scenarios. Probably the worst ind…

Why would experts care about my product? There's no big money behind it. The big money has to come in first, then the experts come later to tell the big money whatever they want to hear. Maybe they want to hear the truth maybe not... Either way the paymaster always hears what they want.

Besides, I am an expert. I studied cryptography at university as part of my degree. I have 15 years of experience as a software engineer including 2 years leading a major part of a $300 million dollar cryptocurrency project which never got hacked... I know why the experts were not interested in my project and after careful analysis, I believe it has nothing to do with flaws in my work.

If anything, it might be because my project doesn't have enough flaws...

At this stage, I hope you're right. I hope I will find the flaws in my projects that I've been looking for after 5 years.

Re: Quantum computing bombshells that are not April Fools

#38
To put this in context, we've had a streak of improvements to Shor's algorithm that have put the horizon much closer. In 2022, people from Microsoft estimated that it would take more than 10M (physical) qubits to implement factoring. We're now standing at a 1000x improvement. It's still years away for sure, but who can be unhappy with all that progress?

ms paper: https://arxiv.org/abs/2211.07629

Re: Quantum computing bombshells that are not April Fools

#39

Earlier quoted context omitted.

> What's wrong with hedging? To be (an actual) hedge, something needs to be very solidly understood (by the purchaser), a very solid investment in its own right, and either reverse correlated or independently correlated specifically with a particular asset being hedged. And not based on analysis of one "hedging" scenario, because both are going to be owned over a huge distribution of scenarios. Probably the worst ind…

Why would experts care about my product? There's no big money behind it. The big money has to come in first, then the experts come later to tell the big money whatever they want to hear. Maybe they want to hear the truth maybe not... Either way the paymaster always hears what they want. Besides, I am an expert. I studied cryptography at university as part of my degree. I have 15 years of experience as a software engi…

You are leaving something out then. Which you allude to.

Bravo on five years! I recently solved a problem that took me over 30. I originally thought, 3-5 months maybe, then 3-5 years, ... I am happy it didn't take 50. I have killed a lot of my own darlings.

Well apparently you know what you are doing, I am sure you have something.

I have found the best language models are great at attacking things. You may have already done that, but if not its worth a try. Free brutality.

Re: Quantum computing bombshells that are not April Fools

#40
This site is almost impossible to read on mobile unless you have good vision. Normally I can just hit the button in my phone browser to read it in reader mode, but this site doesn’t support that either. It’s a shame.

I am surprised that in 2026 more websites don’t seem so concerned about responsive design, especially when the goal is to read the content.

Post reply on HN