Live data from Hacker News

Quantum Resistance and the Signal Protocol

signal.org

51–60 of 135 posts

Re: Quantum Resistance and the Signal Protocol

#51

I am a bit puzzled: governments and big corp are pouring indecent amounts of money in developing quantum computers, which main application, afaict, is to break cryptography. ...and this is defeated by changing our algorithms ? Whats the use in developing quantum computers then?

The use is all the other applications of quantum computers that aren't breaking cryptosystems

Re: Quantum Resistance and the Signal Protocol

#52
post #4

Earlier quoted context omitted.

> Is that a crazy conspiracy idea, or actually a possibility? I am investing in IBM under the assumption that this is an actual possibility. Their public QC roadmap actually looks like a realistic journey now. I strongly believe that the NSA, et. al. currently have access to a very powerful quantum computer - likely constructed by IBM under contract. The game theory around this is such that it is impossible for me to…

You are probably mistaken. The number of people with the right expertise to build QCs is very limited - only a few hundred people with world class PhDs in quantum computing are produced every year across the world. A small fraction are truly innovative - the ones who can act as leaders to build something real. The challenge of building QCs - as evidenced by billions of dollars worth of research in them - is many orde…

Reminds me of how everyone who knew anything about the physics academia scene in the 30s/40s knew what was going on at Los Alamos. Second-order effects are extremely hard to obscure.

Re: Quantum Resistance and the Signal Protocol

#53

That is very well-written, as someone else pointed out, though this common explanation for laypeople needs work (I'm not blaming Signal's blogger, who wrote it more carefully than most): "Instead of bits as in a classical computer, quantum computers operate on qubits. Rather than 0 or 1, qubits can exist in a superposition of states, in some sense allowing them to be both values at once." 'Instead of beads as in a cl…

There isn't really a great way of explaining quantum behavior using everyday (classical) terms. Any analogy you come up with will be deeply flawed yet unsatisfactory opaque to the reader.

The only way is to gear up on math to the level where you can if not reason within the theory then to at least make sense of its presented conclusions.

Re: Quantum Resistance and the Signal Protocol

#55

That is very well-written, as someone else pointed out, though this common explanation for laypeople needs work (I'm not blaming Signal's blogger, who wrote it more carefully than most): "Instead of bits as in a classical computer, quantum computers operate on qubits. Rather than 0 or 1, qubits can exist in a superposition of states, in some sense allowing them to be both values at once." 'Instead of beads as in a cl…

I don't really understand your objection, that description seems like about as well as you can do when trying to summarize quantum mechanics in one sentence.

Re: Quantum Resistance and the Signal Protocol

#56
post #7

Earlier quoted context omitted.

> If current quantum computers were scaled up to more qubits That depends on what you mean by "scaled up". There is a concept of "Quantum Volume" that exists, which basically means the depth of the longest qubit circuit you can pull off. https://en.wikipedia.org/wiki/Quantum_volume 'Simply' (it's never simple ;) ) adding qubits to a machine does not necessarily increase its Quantum Volume. Decreasing the noise typica…

For anyone looking for a "headline figure" from the linked arxiv manuscript, their estimate for breaking 2048 bit RSA is around the order of magnitude of a billion qubits.

[dead]

Re: Quantum Resistance and the Signal Protocol

#57

It is good that they kept the classical crypto along. However, the general tendency towards quantum-resistant cryptography leaves me puzzled. From my perspective as a physics PhD graduate, I firmly believe that a quantum computer capable of breaking public key crypto will never be built. This is because as you add more qubits, there's increased interference between them due to the additional connections required. It'…

Can you explain how qubits are physically implemented in a real-world computer? I just cannot wrap my mind around what they're made of and how they operate in the physical reality.

Re: Quantum Resistance and the Signal Protocol

#58

It is good that they kept the classical crypto along. However, the general tendency towards quantum-resistant cryptography leaves me puzzled. From my perspective as a physics PhD graduate, I firmly believe that a quantum computer capable of breaking public key crypto will never be built. This is because as you add more qubits, there's increased interference between them due to the additional connections required. It'…

I assume you’re not proposing some kind of interference limit in principle? Are you suggesting that limiting interference will be a practical dead end that is prevents advancement? Either way that would be a pretty significant claim. There are lots of research directions being pursued and plenty of smart people think it’s worth trying.

> Are you suggesting that limiting interference will be a practical dead end that is prevents advancement?

This is a hunch I have. Regarding the "plenty of smart people think it’s worth trying", I can only provide an analogy of the 15-14th puzzle known as the Boss puzzle at that time, for which a substantial prize was promised for the first one who could solve it. A lesser-known proof that it is impossible came to surface decades later. There is a lot of inertia in academia along those lines, where grants depend on your ability to make a convincing argument that your path will solve the problem. This sets up PhDs to know only to advance but not to question as the latter does not give the prize.

Re: Quantum Resistance and the Signal Protocol

#59

It is good that they kept the classical crypto along. However, the general tendency towards quantum-resistant cryptography leaves me puzzled. From my perspective as a physics PhD graduate, I firmly believe that a quantum computer capable of breaking public key crypto will never be built. This is because as you add more qubits, there's increased interference between them due to the additional connections required. It'…

Doesn't your argument apply to classical bits too? The more interconnected a classical bit is, the more parasitic coupling it will experience. That used to be an argument used against the feasibility of classical computers in the 40s (until von Neumann published work on fault tolerant classical computing). Both classical and quantum computers (1) can not "scale" without error correction because of analog noise (altho…

To add to the sibling comment, the reason our classical computers work is because the individual transistor errors in your CPU are basically zero.

We do use “error correction” on storage (and do see bit errors creep into data stored on disk and in RAM over time) but not “fault tolerance” on the compute. In fact there is no such thing as fault-tolerant classical compute - the CPU only works if it “perfect” or “near perfect” (or if you had an ancillary computer that was perfect to implement the correction). Note that occasionally computers do crash due to a bit error in your CPU, or you get a “unstable” CPU that you need to replace.

(We do create fault-tolerant distributed systems, where such faults can generally be modelled and remedied as network errors, not compute errors.)

Quantum fault tolerance relies on the fact that you can do “perfect” classical computation - which I find kind of amusing!

Re: Quantum Resistance and the Signal Protocol

#60

It is good that they kept the classical crypto along. However, the general tendency towards quantum-resistant cryptography leaves me puzzled. From my perspective as a physics PhD graduate, I firmly believe that a quantum computer capable of breaking public key crypto will never be built. This is because as you add more qubits, there's increased interference between them due to the additional connections required. It'…

People have already said here most of what I want to say in this comment, but just to make it as explicit as possible: Essentially the only reason anyone thinks that useful quantum computation is possible is because of things called threshold theorems, which state that as long as the noise in each qubit is less than some small but non-zero error rate you can add more qubits and use quantum error correction to make yo…

>...as long as you're below the threshold rate quantum computers scale well.

Last I heard, getting below that threshold was going to take one or two orders of magnitude of noise improvement. That seems unlikely.

Say you were at a VC presentation and the company said that they had this really great system and the only thing stopping their immense success was the requirement to reduce the noise by an order or two of magnitude. Oh, and by the way, we already have the system very close to absolute zero. So you ask them what they are planning to do and they tell you that they don't have the faintest idea. Noise is always the ultimate limit on the information that can be obtained from a system. The most reasonable interpretation of the situation is that a technology doesn't exist and that there is no reason to think it would ever exist.

But when it comes to quantum computers the optimism is boundless. I am not sure why.

Post reply on HN