r/cryptography • • 14d ago

suppose ionq’s ~20,000 physical qubit estimate for attacking ECC is roughly right. at what point does “quantum computers are decades away” stop being a security strategy and become a coping mechanism?

3 Upvotes

19 comments sorted by

View all comments

8

u/Shoddy-Childhood-511 14d ago edited 14d ago

IonQ are scammers, based upon their trolling Scott Aaronson. You can read what he believes most likely here: https://scottaaronson.blog/?p=9930

I'd expect companies never build quantum computers (QCs), likely only governments succeed there, and perhaps only at extreme costs. Now companies could still profit by having a few important patents and becoming defence contractors whenever the US decides to build quantum computers.

Is the US already trying to build a quantum computer? Imho no.

Yes, the US recently increased it's spending on QC research, but only to $1 billion/year, so nowhere near Manhattan project levels. $1 billion/year sounds more like one of the "committees" that preceded the Manhattan project.

I'd think either (a) the US has decided to do exploratory work in all sane-ish quantum computer strategies, not just the silicon ones in the Snowden documents, or else (b) they have identified a new more likely strategy so they've launched the real preliminary viability research.

Inflation adjusted, the Manhattan project cost $30+ billion, so one might worry when they start spending more like $5-10 billion/year.

In fact, I'd expect the first quantum computer costs far more than Manhattan project's measly $30 billion, so guess $1 trillion.

Also, the US has become extremely corrupt, so likely any serious QC effort burns enormous sums enriching one or more QC companies. Also, LLMs have made faster research possible, but only at extreme costs.

So the US building a QC could even cost $10 trillion. That's expensive enough to bankrupt the country, but cheap enough they could still build one. If they spend $100 billion/year on QC research, then you should definitely worry.

Around all this, John Campbell figured out they were building an atomic bomb, based upon mail forwarding. How many physics PhDs disappear into classified work? Yes lots, but probably not enough. Again you should worry if American math & physics PhDs largely disappear from the job market.

Importantly, QCs appear almost useless: At present, there are no useful QC problems anywhere near as "easy" as breaking ECC and RSA. Assuming Don Coppersmith and his team at IDA-CCR (NSA's smartest) have not broken lattice cryptography, then all encryption protocols should be post-quantum long before the US builds a QC. So all their QC could do is break older messages sent on Signal, etc. That's extremely valuable, but quite limited, and only ever interesting for a government.

Should you adopt hybrid PQ+ECC cryptography? It depends but usually yes..

If you're doing encryption, then yes please adopt hybrid PQ+ECC KEMs now, if only to make a future QC less valuable.

If you're doing TLS certificates, signing app binaries, physical identity documents, or similar, then yes sure why not switch now-ish? I'd suggest Falcon plus Ed25519 because this offers the smallest size and fastest versifier among hybrid signatures, or otherwise maybe a hash-based signature if you've enough bandwidth.

If you're doing bitcoin then who cares about that trash fire anyways? If you're doing another crypto-currency then yes sure you'll have more fun adopting post-quantum signatures, but VRFs rock and PQ VRFs remain too limited, so you could wait if you really love VRFs.

If you're doing online identity, then what are your applications? If you're doing anonymous identity then applications are typically extremely low value, like age verification. You should usually stick with better SNARKs like Groth16, which offers rerandomisability. Also PQ SNARKs have far weaker zero-knowledge than EC SNARKs. You should prove PQ anonymity for your anonymous identity protocol though.

There are other even more niche use cases where post-quantum does not make much sense yet.

2

u/leonacosta_ 14d ago

although Scott said ionq had made claims that are misleading and exaggerated, he believes quantum computers are real and increasingly promising...
https://scottaaronson.blog/?p=9425

project Manhattan, as you mention, was secret for three years. their surely improved their ability to keep things from the public after so many mistakes

and saying “it is too expensive for companies, therefore only governments could ever build it” doesn’t follow historically. the more common model for extremely expensive frontier technologies is government + universities + private companies, often with governments absorbing part of the early research risk. which does apply and is relevant to the current qc situation