The quantum computing era is coming fast
theguardian.com
theguardian.com
The whole D-Wave thing is mostly irrelevant for cryptography, which the article doesn't mention. Even if the D-Wave devices turn out to be useful for some special algorithms, they can't run Shor's algorithm, which is what endangers crypto.
Also calling 1024 bit a "really long key" is a bit strange. They are already endangered by classical computers, no need for quantum computing here.
That said: The call for postquantum crypto is right.
So there is a $500 million price ready for the first operational Quantum computer. http://ba.net/util/bitcoin/design1.html#quantum
The component they lack is that they can not preserve any non-trivial information between their qubits.
This is the original I think: http://arxiv.org/abs/quant-ph/0403090
[1]. http://www.diva-portal.org/smash/get/diva2:680572/FULLTEXT01...
[2]. https://dwave.wordpress.com/2011/05/11/learning-to-program-t...
[3]. https://www.newscientist.com/article/dn21699-controversial-q...
https://www.reddit.com/r/crypto/comments/3ig0xf/does_anyone_...
In 1999 you could break a 512-bit RSA key with a supercomputer, in 2015 you can do it with 4 hours and $75 on EC2: http://arstechnica.com/security/2015/10/breaking-512-bit-rsa...
A 768-bit RSA keys has been factored in a large academic effort: https://eprint.iacr.org/2015/1000.pdf
When you pick a key length, you want it to be long enough to provide security for your communications as far into the future as practicable, and the classical efforts to break RSA are getting uncomfortably close to 1024-bits. Maybe in a few decades it would be practical for some adversaries to break even perfectly made 1024-bit keys.
However, I'm not a cryptographer, so someone please correct me if I'm wrong.
He didn't compare anything.
No, he did:
>>> 1024 bit keys are endangered? .... You can't even break 256 bits
1024 bit key = most likely something like RSA
256 bit key = some symmetric algorithm or ECC
He's implying a 1024 bit RSA key should be safe because a 256 bit key from some other algorithm is.
RSA 1024 is a broken encryption scheme (2010). In Jan 2010 there was already the concern it was broken or quickly to be broken. http://arstechnica.com/security/2010/01/768-bit-rsa-cracked-...
in March 2010 http://www.techworld.com/news/security/rsa-1024-bit-private-...
I took his statement of "Only in some broken encryption schemes" to be a misunderstood reference to stuff like this: http://arstechnica.com/security/2015/10/how-the-nsa-can-brea... or a side channel attack.
Your second link has garbage sensationalized headline. It actually describes a side channel attack that has nothing to do with cryptography algorithms. It's basically equivalent to a clever way of looking over someone's shoulder.
The issue IS not 256-bit it is the password you used to encrypt it with. Using letters, caps, symbols and numbers with 12 that would be an incredibly large budget to get your password.
Think of this as an algorithm on specific hardware for solving a specific problem. You can encode other problems into the specific problem, at a cost. Currently this algorithm on specific hardware is not as fast as state-of-the art algorithms on ordinary hardware (namely Selby's). But the people making this special hardware claim (no proof) that when the special hardware (and the problem size) is scaled up, the special hardware will be much faster than ordinary hardware. So far no-one has disproved this assertion, but no-one has proven or demonstrated it either.
Meanwhile, many other scientists and some companies, who refer to this type of special hardware as "dirty QC", are working on another class of special hardware they call "clean QC". This is mathematically proven to be much faster than ordinary hardware when it is scaled up, but it's very very very difficult to scale it up. But they're working on it and showing progress.
Right now, no-one knows if the "dirty" or the "clean" special hardware will be the first to be actually useful in the real world. It's likely the first useful real world application is more than ten years away. We don't know exactly what the application will be, or how the special hardware then will be programmed. It's also quite likely that most the people commenting here will be retired before access to the special hardware will be given to anyone but scientists.
What is likely going to happen at first is that for very specialized problems there will be large scale quantum computers. Think of them as complex physical experiments, occupying whole rooms with delicate equipment. That will be the reality of quantum computing for quite some time. If they ever end up on a desk is hard to tell, but that's really science fiction, it's like asking whether we'll visit foreign planets in the future.
That means unless you are working in a very specialized environment quantum computers are irrelevant for you as a developer except that you'll likely use different crypto algorithms in the future. But you will use different crypto that still runs on classical computers.
Quantum Computers Entice Wall Street Vowing Higher Returns:
http://www.bloomberg.com/news/articles/2015-12-09/quantum-su...
https://hn.algolia.com/?query=quantum%20google&sort=byPopula...
I would expect, of all places, people on HN to be smart enough to help me understand these news stories. I have no idea what quantum blahblah really means and want to know if this is a real breakthrough or just a news story.
This really is a real breakthrough in quantum computing. Specifically for an approach called 'quantum annealing' which is one of many (there is at least one other) possible approaches to quantum computing.
This result is a breakthrough in two ways.
1: It demonstrates real quantum effects in the D-Wave computer. It had been hotly debated, by experts in quantum computing, whether the D-Wave actually used quantum effects in its computations. 2: It shows a real speedup for a very specific instance of a very specific algorithm. This is great news, and a very good result, for the people working on the D-Wave.
This is just a news story because
1: The D-Wave is much, 100 million times!, faster than the same algorithm running on a conventional computer. But there are algorithms you can run on a conventional computer which are equivalent (If someone could clarify how equivalent they are that would be great) which are as fast as the D-Wave. So they chose an algorithm which is good for the D-Wave and terrible on a classical computer. 2: The problem instance they chose is very artificial and it isn't clear that the speed up wouldn't disappear if they tried to run actual real world instances of the problem.
I would conclude that this is a great result. It increases the understanding of quantum computing. That is very exciting. The D-Wave doesn't appear to be practically useful. Yet.
(I am not even the beginning of an expert in this, everything I wrote above comes from the link below)
In principal, even if the hardware only supports one algorithm, this could tell us something about whether quantum computers are really better than normal computers. Unfortunately the D-Wave machine/algorithm is still not much better than simply simulating a quantum machine in normal hardware (Quantum Monte Carlo) and worse than the conventional algorithm by Alex Selby.
It's interesting, but it still doesn't shed much light on the important questions.
Note: One could also compare to performance of single machine with CPU's, GPU's, FPGA's, and/or ASIC's to be more fair. Just needs to be optimal, classical implementation on HW designed for it vs optimal use of D-Wave.
Although if you are working with an Event-Sourced architecture you may as well just implement with OTS (One-Time Signature) chains.
and also more importantly here https://news.ycombinator.com/item?id=10707442
TL;DR: Google researchers demonstrated that DWAVE2X quantum annealing against one classical (i.e. normal computer) algorithm (on one CPU core) - simulated annealing, was asymptotically (i.e. more than just by constant factor) better, but was not against another classical algorithm quantum monte carlo (QMC) that is, the difference was constant. In fact, it was 10^8 times faster and that is generating all the hype.
Now, it was mentioned in the paper that Selby algorithm on classical computer would actually produce better results than DWAVE2X but it was not compared against it (maybe because it would minuscule the amazing 10^8 times difference).
Also it is worth mentioning that special solutions in silicon (ASIC) are demonstrated to produce about 10^6 faster results compared against the same algorithm on a single CPU core (it does not follow that such speed up is possible for every classical solution).
Quantum computers (the real kind) are still impractical. People are still working hard to make them bigger, but this still gets harder and harder as the computer size increase. And people still don't know if that's an inherent difficulty of the problem, of if some breakthrough will suddenly make quantum computers easy to make.
Or, in other words, there's no visible change for people that is not closely following the area.
The Google/D-Wave stuff is largely without substance, but makes for nice, breathless media reports. See http://www.scottaaronson.com/blog/?p=2555 for an explanation of the latest report.
This should help: http://news.mit.edu/2015/3q-scott-aaronson-google-quantum-co...
Impractical and expensive because:
* You need a glas fiber line. That means no copper, no wifi, no crypto on mobile phones.
* You are limited to some tens to hundreds of kilometers. No transatlantic encrypted qkd. It doesn't work.
* Complex physical tasks with high accuracy like sending and detecting single photons - not cheap.
No, it's not coming. It will stay there where it is now - huge corporations that rule the world and governments. This will just build huge precipice between small companies and people who will run AMD64 for next 20 years and corporations that in 20 years will already have something that will replace quantum computers. We all will be ruled by a few computers. Google technologically runs away from their competitors. Google will gather more data, process it faster, more accurate, will gather more data... Poor will become poorer and rich will be richer. It's not coming fast, not in our direction.
Also we can expect that there would be computing centers what resources the mere mortals can access as a service as they can access the resources of the computer clusters today.
Very likely universities fill have their own quantum computers. Bigger ones first, then smaller ones.
I think that the situation is not that depressing but it definitely will create some disparity in the beginning.
>Very likely universities
I don't mean no one else won't have or rent any, sure they will, there are a lot projects that will need it, we people won't have any. I think I presented my opinion too negatively :<
If we look at the history of computing, then yes, one could be so pessimistic, but would it be really true?
If there will be a breakthrough in the QC, then there will be sudden economic motivation for people (companies) to use quantum computers.
This will generate the need for people who could work with such computers. This will again generate motivation for universities to train such people and the need to access quantum computers.
I think that this will happen much much faster than it happened with the classical computing.
Of course I also believe that there would be no personal QC any time soon if this is what you had in mind.
Edit: I also do not understand why you are down voted. I think that it is an important perspective.
I'm not sure QC can change that.
The only way to get more value would be total 24/7 Orwellian surveillance, and I don't think that's going to be a popular option.
QC for crypto is a no-brainer. QC for anything else, including data mining/ML, is a much fuzzier prospect. I'm not sure anyone really understands what the practical applications could be, never mind how to use QC to make them possible.
Any suggestion that you can take a warehouse full of web logs and tracking stats, give it a quantum shake, and have a few million pre-qualified addicted customers fall out is likely nonsense.
Problems in ML can be mostly proposed as an optimization task and if QC would works out, ML would be likely its main application.
It would likely make an huge difference in solving a classification problems as you could train your ML model with much more data much faster. I t would also make the clustering problem much faster too as it also can be expressed as an optimization problem.
Also there are many other optimization problems that would benefit a lot from the speed up (regardless if it is huge constant speed up or an asymptotic one).