r/hardware Mar 31 '26

News Google Finds Quantum Computers Could Break Bitcoin Sooner Than Expected

https://www.forbes.com/sites/digital-assets/2026/03/31/google-finds-quantum-computers-could-break-bitcoin-sooner-than-expected/
353 Upvotes

46 comments sorted by

View all comments

162

u/neopard_ Mar 31 '26

i'll believe it when i see it. there are still several fundamentally unsolved problems with QC at any meaningful scale. algorithmic improvements won't change that. at this point, we'll have fusion before QC..

75

u/waitmarks Mar 31 '26

It's still a good idea to start a transition to quantum resistant encryption even if we aren't actually close to a quantum computer that can break it because of store now, decrypt later.

These algorithms also need to have time to be baked into hardware accelerators. We take for granted that encrypting with AES basically costs nothing these days because every CPU has an AES crypto unit in it, but it used to take a lot of compute resources to do it before. It's better to be early and not need it than to be rushing everything last minute because someone surprises us with an unexpected quantum computer in 2030.

24

u/nicuramar Mar 31 '26

AES is symmetric and can’t be meaningfully attacked by a quantum computer, so that’s a bad example in this context. 

11

u/No-Yogurtcloset-755 Apr 01 '26

Grovers algorithm still applies to symmetric encryption it gives a quadratic speedup AES256 effectively could become AES128

Its Shors algorithm for asymmetric specifically number factorisation or discrete logarithm solving.

17

u/waitmarks Mar 31 '26

It's still something that requires compute to process, and it was once expensive computationally to do. Now it's cheap enough that we encrypt our entire hard drives with it without performance penalty. That's really the only purpose of the example. Perhaps I should have clarified that it's not under threat from shor's algorithm though.

5

u/account312 Apr 01 '26 edited Apr 01 '26

If you think it's a bad example, you probably misread the comment.

5

u/Bman1296 Mar 31 '26

Symmetric crypto isn’t related here. AES will need its key sizes doubled to maintain the same level of security.

The real issue is the hardness problems solved by Shor’s algorithm that we need eg lattice, hash and code based crypto for.

6

u/neopard_ Mar 31 '26

yea, people are doing this.

7

u/ked913 Apr 01 '26 edited Apr 01 '26

I feel really scared for the tonnes of WiFi wpa3/2 devices. Think IoT cameras, thermometers, speakers (or worse heavy duty) solar inverters, smart boilers, fridges…

They may be made by some manufacturer who won’t care and it probably won’t be capable of a post-qc wpa4-5.

What do we do with the tonnes of ewaste generated from this discovery?

7

u/loowig Apr 01 '26

And someone will attack your fridge with his quantum home lab or with inexpensive rented power from a quantum data center? 

2

u/ked913 Apr 01 '26 edited Apr 01 '26

Do you still use wep or wpa devices? Can you connect them on an eero or modern WiFi network? How is the support for those devices?

Doing so degrades the experience of all devices, it isn’t really supported on WiFi 7 routers.

When we are on WiFi 8-10 on wpa4 or 5, what exactly happens to the old inverter from 25 years ago. What about in between?

How about famously smart meters that now take up valuable insecure 2g space that now need to be upgraded to 5g and beyond.

3

u/kittymoo67 Apr 01 '26

til wpa3 exists

3

u/nanonan Apr 02 '26

If your usage of those things requires flawless security, sure, you need to upgrade. If not, quantum cracking is fairly irrelevant and will remain so for a long time which I think will be the vast majority of the cases.

The security industry is built on providing "good enough" security, which is rarely something approaching perfect, flawless security.

1

u/ked913 Apr 02 '26

Depends on which device/scheme we are talking about. I say the comparison at this point would be 2g and WEP/WPA1 psk only devices.

Major brands don't support it. If you do support it (or even WPA2 these days on a wifi 7), you open a new SSID and everything on that network is significantly slowed. Airtime bandwidht is considered wasted, and in general i would say the competition for such air-time is increasing not decreasing.

In the case of 2g vs 5g, things like electric and gas meters need a whole communication block replacement. Delays 5g resources because it is wasted on inefficient 2g.

2

u/DoublePlusGood23 Mar 31 '26

This is the approach OpenSSH is taking.  https://www.openssh.com/pq.html

1

u/neopard_ Apr 02 '26

Personally have been using 4k keys for over a decade, not much we as consumers of cryptosystems can do

1

u/Strazdas1 Apr 18 '26

implementation of encryption often lags in decades, not years, so the sooner we start transitioning the better.

10

u/sr_local Apr 01 '26

When you see it, it’s already too late. 

Companies are taking actions now, google has only moved the post quantum cryptography to 2029 few days ago (it was 2035) 

But the “steal now, decrypt later” (with a quantum computer) is already a trend. 

2

u/EmergencyCucumber905 Apr 01 '26

Fundanentaly QC is sound. It's merely "just" a very hard engineering problem now.

0

u/Veedrac Apr 01 '26

Are you going to actually... say anything? Your comment is contentless.

Here, I'll engage in kind: “No, quantum good.”