Just a reminder that the IETF is broken:
https://www.metzdowd.com/pipermail/cryptography/2026-June/039613.html
Post
Remote status
Context
14@encthenet that's a rather strong word. Mistakes were made
@rsalz
This isn't the only case. the Tcpenc group and what's happening with the tls pq draft being shoved through as additional examples.
@encthenet didn't know about tcpenc. Disagree with you on the pq draft.
@rsalz @encthenet recent DJB seems informative more than nit picky here: https://blog.cr.yp.to/20260630-risk.html
@darkuncle @encthenet I have known him for about 30 years. Back in the Usenet days. Lately, he will twist and cherry pick people's words to reinforce his point. Sorry, I admit that this may be on me, but I no longer think he is operating in good faith and I do not trust him or what he says anymore. He did it with me, here on this platform, so I am speaking from experience.
i long ago got to considering DJB as a highly intelligent person whose paranoias and fears made useful and collaborative use of said intelligence mostly impossible. a pity.
@paul_ipv6 @rsalz @darkuncle @encthenet
Please read this before treating djb with any seriousness. https://keymaterial.net/2025/11/27/ml-kem-mythbusting/
@feld @sun@shitposter.world @encthenet @paul_ipv6 @sophieschmieg @rsalz nah, they have already happened, just not at sufficient scale for Shor’s (yet). We have seen exponential improvements in error correction and coherence times in just the last couple of years; there is no reason to believe that trend will abruptly cease.
But what we have created is not even capable of doing what we're trying to achieve. Microsoft's latest can only hold a qubit state for 20 seconds. I don't care if someone comes out tomorrow with a quantum cpu that has a billion qubits -- it's meaningless unless they actually can old state indefinitely when actively powered.
This is my favorite quote from last year because it sums up the situation so well:
> 2^64 work that is non-paralellizable isn't a threat. 64 bits of classical security is insufficient because computers can do thousands of operations in parallel, and you can combine the effort of millions of computers. Grover's algorithm gives you a sequential complexity of 2^64, so if you have a quantum comptuer with a clock speed of 20GHZ (current quantum computers are in the khz to low mhz range), and you pretend that the quantum computer can process 14 rounds of AES per clock cycle (in reality it would be hundreds of cycles), it will take a quantum computer running for 30 years continuously to crack a single key (and if the temperature ever rises 1 millionth of a degree or the computer loses power for a nanosecond, you have to start over).
Alright so let's pretend for a second that these problems are mostly solved. We have other hurdles:
- no room temperature superconductors, so they need massive cooling
- This means we need He-3 which we have an alarming shortage of
Also need to find a way to ensure power stays as stable as stated above
- Needs to be paired with a classical CPU, remember. They don't work on their own, so for situations where we're crunching large amounts of data with them we are limited by the speed of our current busses to feed them
- Also we are in a massive hardware crunch so there's no chance anyone is going to build this soon
- We're suffering grid capacity issues, big doubt a datacenter with quantum computers will use less power than an AI datacenter so those hurdles remain
Assuming I live another 50 years, I still don't think they'll be possible by then.
@feld there are about eight hardware modalities for quantum computers right now; only some of them require superconductivity. There are also a great many real-world problems to be solved with quantum computers that have nothing to do with factoring large integers; breaking RSA or ECC is probably not even in the first five major breakthroughs that we will see. I think it’s important to keep in mind that the reality of quantum computing as a paradigm is very much distinct from whether or not someone can spoof a DSA signature or break your TLS 1.2 traffic in something approaching real time.
The problem is, we have been seeing for the last 10 years a series of exponential growth inflection points when it comes to quantum computing capability, and we usually cannot see that those were inflection points until they are in the rearview. Almost all of them were also not in areas that experts had previously predicted we would see breakthroughs.
The other problem is that transitioning the entire installed base of cryptography on the Internet to new standards is something that will take many years of effort. If we wait until we are reasonably certain that Shor’s algorithm at scale is around the corner, we have waited far too long to mitigate that business risk.
I would refer you here to Scott Aaronson’s blog post from a few weeks back; he is both well respected and not prone to hyperbole: https://scottaaronson.blog/?p=9718
> there are about eight hardware modalities for quantum computers right now; only some of them require superconductivity.
there are 6 that I know of but I'm not even sure this list is correct:
- superconducting circuits
- trapped ions
- neutral atoms
- photonic
- spin based / quantum dots
- topological
the only ones with promise seem to be the ones that need superconductors, and that's what IBM, Google, and Microsoft are focused on. AIUI, IBM and Google are doing the superconducting circuits and Microsoft's Majorana is using topological but this requires superconductors as well.
> I would refer you here to Scott Aaronson’s blog post
read this, not convinced. I'm sticking with people like Dr Henry Legg on this:
"My feeling is that they are centuries, not decades away. If it works at all -- and, based on what I have seen, the most likely scenario is that it doesn't work."
He's a professor of quantum physics at St Andrews, you can follow him here:
https://bsky.app/profile/henrylegg.bsky.social/post/3mp26xgvuzk2b
Replies
0Fetching replies…