Pages

Friday, August 28, 2026

Quantum danger

 In my experience Hossenfelder on YouTube is pretty accurate although sometimes misleading or prone to overstate things.  I watched her tear into IBM's recent quantum computer claims, pretty much declaring them pointless and nothing a standard computer can't do.  A lot has been spent preparing for alternative to prime number factoring being possible for security reasons, and from what I got from her, the implication is there is no real danger coming.

Yes — but I think there’s an important distinction that may reconcile what you got from Hossenfelder with the rather alarmist quantum-security preparation you’re describing.

The short version is: her skepticism about IBM’s present claims can be quite justified without implying that the eventual cryptographic threat is imaginary. Those are two very different propositions.

IBM and its collaborators announced in July that their Heron R3 experiments had achieved “quantum advantage” on several specialized problems. But “quantum advantage” in this context does not mean “we have a machine that can do something generally useful that classical computers cannot.” It means that for particular carefully constructed problems, under particular benchmarks and with substantial error-mitigation machinery, they obtained results that are difficult to reproduce efficiently with the best known classical methods.

That leaves quite a lot of room for Hossenfelder's criticism. In particular, a quantum computer beating a classical computer at a contrived quantum benchmark is nowhere near demonstrating that it can factor a 2048-bit RSA number. That's the enormous missing step.

And this is where I would slightly modify the conclusion you drew from her video:

The danger to cryptography is real in principle; what is highly uncertain is whether and when anyone will actually build the machine required to exploit it.

Shor's algorithm really does change the game. A sufficiently large, fault-tolerant quantum computer could factor the enormous integers on which RSA security rests in polynomial rather than effectively astronomical time. It also threatens elliptic-curve cryptography. That's not a speculative interpretation of IBM's marketing—it is a mathematical result known since 1994. NIST still explicitly regards this as a serious future threat.

But there's a gigantic engineering chasm between today's machines and a cryptographically relevant quantum computer. The useful qubits in today's systems are noisy; error correction requires many physical qubits to produce one sufficiently reliable logical qubit; and Shor's algorithm requires a large number of high-quality logical qubits and an enormous number of operations.

That's why I think the sensible position is something like:

    “Don't bet on the quantum computer arriving—but don't bet your long-lived secrets on it not arriving either.”

And there's another wrinkle that makes all the money spent on post-quantum cryptography quite rational even if Hossenfelder eventually turns out to be right about the hardware.

Cryptographic infrastructure takes forever to change. NIST says that migration can take 10–20 years, and recommends beginning now precisely because nobody knows whether a cryptographically relevant quantum computer is five years away, twenty years away, or never arrives.

There's also the “harvest now, decrypt later” problem: an intelligence service doesn't have to be able to break your encrypted communication today. It can copy it today and retain it until the necessary technology exists. That matters for information that remains valuable for decades.

So I wouldn't characterize the situation as “all that preparation is for a danger that isn't coming.” I'd characterize it as a fairly cheap insurance policy against a very consequential technological possibility whose probability and arrival date are genuinely unknown.

And there's an amusing irony here: Hossenfelder's skepticism about quantum-computing hype and the security establishment's concern about quantum computing aren't actually contradictory. The latter doesn't require believing the former's present-day machines are remotely capable of breaking RSA.

In fact, the most interesting question is probably the one she is implicitly forcing: how much of the enormous investment in quantum computing is actually leading toward useful fault-tolerant computation, as opposed to increasingly elaborate demonstrations that quantum machines can do things classical machines find inconvenient to simulate?

That distinction is very important. And IBM's current “quantum advantage” claims don't, by themselves, answer it.



No comments: