Aaronson is currently back in the skeptical camp after a brief stint of "cautious enthusiasm" in 2012. Umesh Vazirani, Aaronson's PhD advisor and the grandfather of quantum computing, has been largely dismissive of D-Wave and doesn't believe their computers will be capable of much even if they are truly quantum.
The technology is apparently impressive enough that Google, NASA and Lockheed Martin have partnered with D-Wave to test its capabilities, but to date it has not done anything revolutionary. I'm sure they have done something, but it's not clear what trade secrets they have can be separated from marketing, and their public work has been reproduced on classical computers.
There have also been a number of articles in Nature Physics, Science and elsewhere by different authors going back and forth on points 1 and 2 above. The current consensus is that D-Wave is not creating true quantum computers; but they have developed classical, pseudo-quantum computers with legitimate entanglement implemented, and which do not currently offer any real quantum speedup or improvement over classical computers.
That said, I mostly follow quantum cryptography, so I haven't read this research in a while. I am personally happy that D-Wave exists and is trying to push forward the field - I think comparisons to Theranos are uncharitable. But I am skeptical of their real advancements.
Edited to clarify after reviewing the research again.
I down-voted this. I have only a layman's understanding but from what I have read particularly #2 is demonstratively false, D-Wave has not achieved any improvements over classical computers for anything (including it's very own domain problem, which Alex Selby's classical algorithm outperforms D-Wave on). [0][1]
[0] http://www.scottaaronson.com/blog/?p=2555#comment-974407
My main point was that acknowledged experts have gone back and forth on this and there have been conflicting publications about D-Wave's computers. Now that I review the research again, it looks like it's been experimentally shown to have legitimate entanglement implemented in the computers, but the consensus is indeed that there is no quantum speed up or improvement or classical computers.
Thanks for the reply though, I've edited the original comment.
[0] http://www.dwavesys.com/media-coverage/techrepublic-quantum-...
Except not, because constant time speedup isn't interesting, 1000x classical computers will get you the same effect probably for less $ than d-wave. The entire point is that a genuine quantum computer should achieve an asymptotic speed-up not a constant factor one, which no one really cares about.
As someone who has actually worked in the research divisions of NASA and Lockheed, I wouldn't assign this form of social proof any value. There is absolutely nothing to infer from fact that NASA and Lockheed bought prototypes. I don't have personal experience with Google, but it is not unlikely that the same effects are at work.
Which is also a field full of bullshit and nonsensical claims, and it still has to prove that it provides a solution for any real problem.
It might not be mature enough yet for widespread adoption, and it doesn't revolutionize all parts of a cryprosystem, but it is definitely progress in the narrower problems of key distribution and perfect forward secrecy for one-time pads.
Unless I'm misunderstanding you and what you mean is that the field has many people opportunistically using the term for marketing things that are not really quantum cryptography; if that's the case, I agree with you.
I'm not sure. The best minds I've talked to in high-assurance security don't believe it. One, Clive Robinson on Schneier's blog, predicted we'd see classical attacks on it. Something like that happened. I pointed out there would still be software, endpoints, interception, subversion, etc for bypass whereas the tech itself was little understood versus effects of regular electronics. Tried and true beats novel and new if it's high-security I always say.
No, these devices are not trustworthy or even necessary that I can tell. High-assurance key exchange is a solved problem if the organization is the simpler, hierarchical designs likely to use QKD. Many solutions available with the most reliable being a courier and key-handling hardware you can trust that only has part of the secret + another transmitted over various medium with it all using several layers of symmetric to work (eg my polymorphic schemes). All on dedicated, low-TCB devices.
I don't know what QKD costs today but I bet it's still cheaper to courier the pre-shared keys and use tamper-resistant hardware. Do you have numbers on it in terms of amount of keys negotiated over time and at what cost for hardware w/ HA setup?
And I don't see how quantum key distribution solves any problem. It's kinda circular - it requires an existing authenticated channel to work, which needs math-based crypto. At the same time the whole field is built on the claim that they're needed because they don't trust math-based crypto.
If you used that with the meaning "we don't know how to do anything useful with it, but it is worth looking because there may be some use", I would grant you this point. But:
> In fact, it has already been experimentally implemented (Los Alamos, UCambridge, UGeneva, etc).
No. The existing protocol for quantum key distribution is insecure bullshit.
The way their system seems to work is that you have to transform your problem set into a specific D-Wave function that will be topologically graphed into the D-Wave chipset. From there is finds the global minimum immediately. The challenge is really in having a problem that fits this type of transformation and doing it in a way that it's actually valuable. So it's quite a bit of work just to do the transform and we couldn't see an easy way to take some of our general problems and turn them into the graphs needed to work.
In theory their stock functions seem easy to implement but when you investigate further it's a pretty narrow set of problems that fit.
[1] https://www.technologyreview.com/s/544276/google-says-it-has..., "Google Says It Has Proved Its Controversial Quantum Computer Really Works"
[2] https://research.googleblog.com/2015/12/when-can-quantum-ann..., "Quantum annealing significantly outperforms its classical counterpart, simulated annealing. It is more than 10^8 times faster than simulated annealing running on a single core".