Live data from Hacker News

Bitcoin’s race to outrun the quantum computer

decrypt.co

61–70 of 90 posts

Re: Bitcoin’s race to outrun the quantum computer

#62
post #12
post #9

It's worth mentioning that Bitcoin addresses aren't exposed on the blockchain as public keys, but hashes of the public keys. If you want to steal the coins you'll need to turn ripemd160(sha256(sha256(publicKey))) into a private key. Good luck.

Yes, but the public key is exposed when you send from that address. If a quantum computer is quick enough, it could get your private key and issue its own transaction, racing you to get into a block.

There had better be enough money available then after all, if it costs you $1M to steal $100 then you've just lost money.

Re: Bitcoin’s race to outrun the quantum computer

#63
post #9

It's worth mentioning that Bitcoin addresses aren't exposed on the blockchain as public keys, but hashes of the public keys. If you want to steal the coins you'll need to turn ripemd160(sha256(sha256(publicKey))) into a private key. Good luck.

Wrong due to P2PK transactions. But also no matter which hash you use as an address the person has to reveal their public key in a digital signature to transact the coins, and if an individual has access to a quantum computer which solves the ECDLP fast enough they can run a node which monitors transactions and conceivably get your private key and then exploit a race condition by transacting the same coins with a higher fee to steal the coins.

Re: Bitcoin’s race to outrun the quantum computer

#64
post #52
post #45

Earlier quoted context omitted.

So if we extrapolate out the current curve 2 more orders of magnitude, it looks good. Therefore we can conclude it's looking possible? ;)

For historical precedence, see "Moore's Law" Talking to experts in the field, we're doubling the number of functional qbits (ie accounting for error correcting requirements) about every 12 months right now. Looks like current number is 16-qbits, where many algos get "really interesting" around 1000 qbits (and functional even before that). So 5-6 years until a potential total transformation in computing paradigms. Qua…

Exponents don't continue forever in the real world.

It's anyone's guess to how far we go, but generally extrapolating a curve far off the current reading is a case of innumeracy.

Re: Bitcoin’s race to outrun the quantum computer

#65

Earlier quoted context omitted.

> which seems probable, as we are progressing fast in the number of qubits we can keep together Probable? Ridiculous: ×there are still no hardware implementation of a single logic gate despite what? 40 years of research? ×stability of qubits are pathetic. ×no software stack (almost) ×Number of qubits are ridiculous and 40 years of research can't even make a consensus on how much qubits are needed for beating a CPU on…

While I agree that QC is far from cracking any encryption today or in the near future; this > theoretically flawed, based on an interpretation of quantum mechanics needing "parallel worlds" is patently false. There is nothing in QC that would stop working under the good ole' Copenhagen interpretation. In fact, if there was even a theoretical possibility that a QC experiment would work only in some QM interpretations,…

Copenhagen postulates collapse, no? If collapses turn out to happen at problematic times or because of problematic conditions, it could potentially doom quantum computers.

In contrast, many worlds says basically: There is no collapse. Ever.

The fact that no one has found what triggers collapse yet is to me evidence that Copenhagen is false.

Pilot wave theory on the other hand is, afaiu completely equivalent to many worlds, but less philosophically convincing.

Where many worlds says there is only the wave function, pilot wave says there is a wave function but also the material world. And material world is a sort of "view" of the wave function. Continuously rederived from it. But the interesting thing is, this material world has no causal consequences. All causality stems from the wave function and its evolution. This is the compromise to get same predictions as many worlds.

Re: Bitcoin’s race to outrun the quantum computer

#66

Just to be clear, this has barely anything to do with any crypto-currency organization. It is a really regrettable framing for an event that should be of great interest to anyone dealing with cryptography, not just the fairly restricted group of crypto-currentcy enthusiasts. If scalable quantum computers can be built (which seems probable, as we are progressing fast in the number of qubits we can keep together), then…

> which seems probable, as we are progressing fast in the number of qubits we can keep together Probable? Ridiculous: ×there are still no hardware implementation of a single logic gate despite what? 40 years of research? ×stability of qubits are pathetic. ×no software stack (almost) ×Number of qubits are ridiculous and 40 years of research can't even make a consensus on how much qubits are needed for beating a CPU on…

I think it is rather misleading to state "40 years of reasearch" the way you are doing it. It was only in the late 90s that there was theoretical reasons to believe quantum error correction is feasible. And your goalpost of logical gates completely disregards the enormous (more than 6 orders of magnitude) exponential progress in the lifetime of physical qubits (see sibling comments for references). We still need a couple more orders of magnitude before things work out at the "logical gate layer", but it is dishonest to disregard the progress up to now.

Re: Bitcoin’s race to outrun the quantum computer

#67
post #65

Earlier quoted context omitted.

While I agree that QC is far from cracking any encryption today or in the near future; this > theoretically flawed, based on an interpretation of quantum mechanics needing "parallel worlds" is patently false. There is nothing in QC that would stop working under the good ole' Copenhagen interpretation. In fact, if there was even a theoretical possibility that a QC experiment would work only in some QM interpretations,…

Copenhagen postulates collapse, no? If collapses turn out to happen at problematic times or because of problematic conditions, it could potentially doom quantum computers. In contrast, many worlds says basically: There is no collapse. Ever. The fact that no one has found what triggers collapse yet is to me evidence that Copenhagen is false. Pilot wave theory on the other hand is, afaiu completely equivalent to many w…

Various interpretation postulate collapses under specific conditions, while other formalisms postulate something mathematically/observationally equivalent at mathematically/observationally equivalent conditions. In particular "problematic collapses" are a thing all quantum computing researchers have to deal with in their work. It is one of the largest subfields of this research program actually (practical quantum error correction).

Re: Bitcoin’s race to outrun the quantum computer

#68

Just to be clear, this has barely anything to do with any crypto-currency organization. It is a really regrettable framing for an event that should be of great interest to anyone dealing with cryptography, not just the fairly restricted group of crypto-currentcy enthusiasts. If scalable quantum computers can be built (which seems probable, as we are progressing fast in the number of qubits we can keep together), then…

> which seems probable, as we are progressing fast in the number of qubits we can keep together Probable? Ridiculous: ×there are still no hardware implementation of a single logic gate despite what? 40 years of research? ×stability of qubits are pathetic. ×no software stack (almost) ×Number of qubits are ridiculous and 40 years of research can't even make a consensus on how much qubits are needed for beating a CPU on…

There's a very intuitive inductive argument that places quantum computers ahead of classical computers.

Basically that quantum interactions are more fundamental to the universe than more terse ones, stochastic randomness or presence/absence.

If a computing device (in a universe) is built to compute using more fundamental substance (to that universe) it should stand to reason it is more efficient.

If you model a photon, does your model ever move as fast as the photon?

Re: Bitcoin’s race to outrun the quantum computer

#69
post #45

Earlier quoted context omitted.

We definitely are getting closer. Look at any graph of "qubit lifetime" and you will see how we have orders of magnitude improvements. (a quick google search gives me page 9 of https://hpcuserforum.com/presentations/tuscon2018/QCOverview... ). We still need a couple more orders of magnitude before the qubits are useful, but the signs of exponential progress are unmistakable. I would not take any experiment performing…

So if we extrapolate out the current curve 2 more orders of magnitude, it looks good. Therefore we can conclude it's looking possible? ;)

Yes, two or more orders of magnitude of improvement are very much expected by most researchers in this field, simply because the current state of the hardware is infantile compared to what we know is possible (it just takes a lot of work to put all the different improvements in a single experiment).

Re: Bitcoin’s race to outrun the quantum computer

#70

Finally a good use-case for bitcoin: a bounty for the first quantum computer to crack it.

Not really. BTC has no value other than its ability to be exchanged for USD. If BTC is cracked no one will trade their USD for it anymore and it will be worthless.

Yes, but anyone smart enough to run a quantum computer to solve the private keys and steal bitcoin is also likely to be smart enough to first examine the blockchain for balances that would not get complained about. Apparently, something like 20% of all BTC is just stranded inadvertently lost or destroyed keys -- starting with 'accounts' after the closely watched genesis block, but which have seen no transactions for maybe 5-8 years should net a lot of funds without being noticed.
Post reply on HN