Quantum computers move closer to the assembly line
axios.com
axios.com
Add to that the facts that error correction will clearly require exponentially more qubits than are programmable; power requirements for cooling or lasers are outlandish and unlikely to shrink significantly; and we don’t even have all that many particularly good quantum algorithms.
Worst of all, all the announcements for the past few years have been in the form of press releases talking about “plans” for new developments and “five year horizons”. Every academic article and new university QC lab is co-sponsored by a VC-funded corporation with every incentive to lie and mislead until a good exit point. This is not the behavior of a highly promising field.
Now, I understand building quantum computers in research settings, even if just for the secondary theoretical and technological outcomes of learning how to build them (similar to how creating gravitational wave detectors led to a greater development of seismometers, quantum noise theory and techologies, control systems, etc.) However, I honestly can't wrap my head around the value proposition for companies to make these things. The only cases I can see is making them in order to sell to research groups who want to use them to implement quantum communication strategies and basic quantum simulations. On second thought, that might be enough, but it is a very small market.
Apart from some strange cases (usually using quantum fourier transform, such as prime number factorisation) they are not good replacements for classical computers at all.
* HHL algorithm for solving (sparse & insensitive) systems of linear equations
* Grover's search algorithm for determining black-box inputs
* Shor's algorithm for factoring primes
* Quantum fourier transforms
The above have various potential applications such as:
* Deep learning [0]
* Finance [1]
* Solving large-dimensional differential equations [2]
* Solving constraint satisfaction problems [3]
I also came across a webpage called Quantum Algorithm Zoo [4] which looks like it answers your question in much more detail.
[0] https://arxiv.org/abs/1806.11463
[1] https://www.google.com/books/edition/Quantum_Machine_Learnin...
[2] https://arxiv.org/abs/1512.05903
HHL: Here's a quote from Ewin Tang [1]: "We know that quantum computers can “efficiently solve” high-dimensional linear algebra problems; however, this assumes that we have some way to evolve a quantum system precisely according to input data, a much harder problem than the linear algebra itself."
[1] https://ewintang.com/blog/2019/01/28/an-overview-of-quantum-...
Grover's search: This is a speed-up from 2^n to 2^sqrt(n). Impressive, but there's not a lot of exp-time algorithms that people ever run. They go for heuristics instead.
Quantum fourier transforms: This is a tool, it's cool, but needs an application. I haven't seen a serious proposal for using it somewhere where a classical algorithm wouldn't do better.
That's a fair point. I guess I was interpreting OP's question as "what can we do once we have engineered quantum computers", and would categorise this "harder problem" as an engineering problem.
I'm not sure what your relation to the field is, but I have found that a lot of things that look like engineering problems from the outside, end up being theoretical and fundamental problems from within. This is often the case when I discuss quantum noise of gravitational wave detectors. I often see people say things like "I wouldn't want to be the guy who has to make these gravitational wave detectors less noisy", almost implying it's just a case of one guy sitting there turning some knobs, but in reality it's thousands of physicists coming up with entirely new theoretical frameworks, often discovering fundamental issues of quantum measurement and control theory (quantum non demolition measurements, quantum squeezing, back action evasion, etc.), or coming up with the most sensitive seismometers ever, or developing new mirror coatings, etc.
Everyone thought that Apple's cancelled wireless charger was just an engineering problem, but it turned out that it seems to be physically impossible to achieve what they wanted.
That said, perhaps in this case you are right, but it's not often obvious what is simply a matter of time and what requires whole new paradigms.
For reference I am out of my depth! My doctorate was in quantum information theory but I've been out of academia for many years now.
[A] https://www.quantamagazine.org/researchers-achieve-absurdly-...
It is indeed interesting that it's even theoretically possible to create quantum algorithms that are better than classical ones, but that doesn't mean it's practically useful. The latter is the relevant metric for bothering with "the assembly line". What you are talking about is still firmly within the realms of academia.
I remember being at the SAT conference 2 years ago (co-located with all other formal methods conferences), and I raised my concern about the BS that was accepted as a research paper again doing some nonsense quantum stuff, and the person from Intel was like, we are almost at 100 qbits, end of the year! Pinky Promise! Of course none of that happened. They promised 1000s of qbits in just a decade 20 years ago.
Best part is that even when they have 10s of thousands of qbits they can't show me a single, actually useful, revolutionary application other than breaking RSA, which is laughable (yada-yada some optimization problems, sorry, but no, the more you dig, the more it's obvious it is nonsense). Billions of EUR into this fever dream and they got completely blind-sided by deep learning (which they _also_ under-funded until industry picked it up and made it work). It's the same idiots who demoted Katalin Kario who recently got the Nobel recently for mRNA vaccines. I sometimes really get tired of Academia.
But that doesn't mean that it's bad to continue funding research into it at some level, in the same way that we fund fusion research, and all-optical computing, etc. It's just a question about balance. Unlike, say, blockchain, we know there _are_ useful applications for a quantum computer; cryptography, as you noted, but also things like quantum chemistry, and possibly some optimization problems. But they're also quite far off and many require stable qbits way beyond what we can build today.
It's a shame that funding at some levels requires excessive hype. It's as much a condemnation of our science funding system as anything.
Changing cryptographic algorithms takes a long time - there are a lot of systems with this stuff embedded in them. Taking some modestly low-cost efforts _now_ to be prepared for a potentially "really bad" future event is more like buying insurance than anything else.
Is it a good choice? I dunno; I have no bets on the likelihood of a working crypto-breaking QC emerging in the next 30 years. But it's not really an irrational thing to worry about on a 10-30 year time horizon, and to simultaneously think that some of the computer systems we design and build today will still be running then.
Would it be a good idea for signal to double the key size?
In the article, Apple explains why they choose to use Level 3:
> At Level 2, the application of post-quantum cryptography is limited to the initial key establishment, providing quantum security only if the conversation key material is never compromised. But today’s sophisticated adversaries already have incentives to compromise encryption keys, because doing so gives them the ability to decrypt messages protected by those keys for as long as the keys don’t change. To best protect end-to-end encrypted messaging, the post-quantum keys need to change on an ongoing basis to place an upper bound on how much of a conversation can be exposed by any single, point-in-time key compromise — both now and with future quantum computers. Therefore, we believe messaging protocols should go even further and attain Level 3 security, where post-quantum cryptography is used to secure both the initial key establishment and the ongoing message exchange, with the ability to rapidly and automatically restore the cryptographic security of a conversation even if a given key becomes compromised.
Article link: https://security.apple.com/blog/imessage-pq3/
Other than that, I don't think anything fundamentally changed during the last 10-20 years.