8 ms·
Understanding Google's Quantum Error Correction Breakthrough
- terminalbraid 2y agoNote the paper they are referring to was published August 27, 2024 https://arxiv.org/pdf/2408.13687 https://arxiv.org/pdf/2408.13687
- dangerlibrary 2y agoI'm someone not really aware of the consequences of each quantum of progress in quantum computing. But, I know that I'm exposed to QC risks in that at some point I'll need to change every security key I've ever generated and every crypto algorithm every piece of software uses. How much closer does this work bring us to the Quantum Crypto Apocalypse? How much time do I have left before I need to start budgeting it into my quarterly engineering plan?
- griomnib 2y agoThe primary threat model is data collected today via mass surveillance that is currently unbreakable will become breakable. There are already new “quantum-proof” security mechanisms being developed for that reason.
- sroussey 2y agoYes, and people are recording encrypted conversations communications now for this reason.
- bawolff 2y agoPerhaps, but you got to ask yourself how valuable will your data be 20-30 years in the future. For some people that is a big deal maybe. For most people that is a very low risk threat. Most private data has a shelf life where it is no longer valuable.
- bdamm 2y agoI'm not sure anyone really knows this although there is no shortage of wild speculation. If you have keys that need to be robust for 20 years you should probably be looking into trying out some of the newly NIST approved standard algorithms.
- er4hn 2y agoYou'll need to focus on asym and DH stuff. If your symmetric keys are 256 bits you should be fine there. The hope is that most of this should just be: Update to the latest version of openssl / openssh / golang-crypto / what have you and make sure you have the handshake settings use the latest crypto algorithms. This is all kind of far flung because there is very little consensus around how to change protocols for various human reasons. At some point you'll need to generate new asym keys as well, which is where I think things will get interesting. HW based solutions just don't exist today and will probably take a long time due to the inevitable cycle of: companies want to meet us fed gov standards due to regulations / selling to fedgov, fedgov is taking their sweet time to standardize protocols and seem to be interested in wanting to add more certified algorithms as well, actually getting something approved for FIPS 140 (the relevant standard) takes over a year at this point just to get your paperwork processed, everyone wants to move faster. Software can move quicker in terms of development, but you have the normal tradeoffs there with keys being easier to exfiltrate and the same issue with formal certification.
- dylan604 2y agoMaybe my tinfoil hat is a bit too tight, but every time fedgov wants a new algo certified I question how strong it is and if they've already figured out a weakness. Once bitten twice shy or something????
- jiggawatts 2y agoThe NSA has definitely weakened or back-doored crypto. It’s not a conspiracy or even a secret! It was a matter of (public) law in the 90s, such as “export grade” crypto. Most recently Dual_EC_DRBG was forced on American vendors by the NSA, but the backdoor private key was replaced by Chinese hackers in some Juniper devices and used by them to spy on westerners. Look up phrase likes “nobody but us” (NOBUS), which is the aspirational goal of these approaches, but often fails, leaving everyone including Americans and their allies exposed.
- dylan604 2y agoYou should look up the phrase "once bitten twice shy" as I think you missed the gist of my comment. We've already been bitten at least once by incidents as you've described. From then on, it will always be in the back of my mind that friendly little suggestions on crypto algos from fedgov will always be received with suspicion. Accepting that, most people that are unawares will assume someone is wearing a tinfoil hat.
- bawolff 2y ago> But, I know that I'm exposed to QC risks in that at some point I'll need to change every security key I've ever generated and every crypto algorithm every piece of software uses. Probably not. Unless a real sudden unexpected breakthrough happens, best practise will be to use crypto-resistant algorithms long before this becones a relavent issue. And practically speaking its only public-key crypto that is an issue, your symmetric keys are fine (oversimplifying slightly, but practically speaking this is true)
- computerdork 2y agoDoes anyone on HN have a understanding how close this achievement brings us to useful quantum computers?
- kittikitti 2y agoThis is another hype piece from Google's research and development arm. This is a theoretical application to increase the number of logical qubits in a system by decreasing the error caused by quantum circuts. They just didn't do the last part yet so the application is yet to be seen. https://arxiv.org/abs/2408.13687 https://arxiv.org/abs/2408.13687 "Our results present device performance that, if scaled, could realize the operational requirements of large scale fault-tolerant quantum algorithms." Google forgot to test if it scales I guess?
- wholinator2 2y agoLol yeah the whole problem with quantum computation is the scaling, that's literally the entire problem. It's trivial to make a qbit, harder to make 5, impossible to make 1000. "If it scales" is just wishy washy language to cover, "in the ideal scenario where everything works perfectly and nothing goes wrong, it will work perfectly"
- wasabi991011 2y agoIt's the opposite of a theoretical application, and it's not a hype piece. It's more like an experimental confirmation of a theoretical result mixed with an engineering progress report. They show that a certain milestone was achieved (error rate below the threshold), show experimentally that this milestone implies what theorists predicted, talk about how this milestone was achieved, and characterize the sources of error that could hinder further scaling. They certainly tested how it scales up to the scale that they can build. A major part of the paper is how it scales. >> "Our results present device performance that, if scaled, could realize the operational requirements of large scale fault-tolerant quantum algorithms." > Google forgot to test if it scales I guess? Remember that quantum computers are still being built. The paper is the equivalent of > We tested the scaling by comparing how our algorithm runs on a chromebook, a server rack, and google's largest supercomputing cluster and found it scales well. The sentence you tried to interpret was, continuing this analogy, the equivalent of >Google's largest supercomputing cluster is not large enough for us, we are currently building an even bigger supercomputing cluster, and when we finish, our algorithm should (to the best of our knowledge) continue along this good scaling law.
- xscott 2y agoWhile I'm still eager to see where Quantum Computing leads, I've got a new threshold for "breakthrough": Until a quantum computer can factor products of primes larger than a few bits, I'll consider it a work in progress at best.
- kridsdale1 2y agoThere will be a thousand breakthroughs before that point.
- xscott 2y agoThat just means that the word "breakthrough" has lost it's meaning. I would suggest the word "advancement", but I know this is a losing battle.
- Suppafly 2y ago>That just means that the word "breakthrough" has lost it's meaning. This. Small, incremental and predictable advances aren't breakthroughs.
- UberFly 2y agoI guess like most of these kinds of projects, it'll be smaller, less flashy breakthroughs or milestones along the way.
- Terr_ 2y agoPeople dramatically underestimate how important incremental unsung progress is, perhaps because it just doesn't make for a nice memorable story compared to Suddenly Great Person Has Amazing Idea Nobody Had Before.
- dekhn 2y agoquantum computers can (should be able to; do not currently) solve many useful problems without ever being able to factor primes.
- vlovich123 2y agoIs this an actually good explanation? The introduction immediately made me pause: > In classical computers, error-resistant memory is achieved by duplicating bits to detect and correct errors. A method called majority voting is often used, where multiple copies of a bit are compared, and the majority value is taken as the correct bit No in classical computers memory is corrected for using error correction not duplicating bits and majority voting. Duplicating bits would be a very wasteful strategy if you can add significantly fewer bits and achieve the same result which is what you get with error correction techniques like ECC. Maybe they got it confused with logic circuits where there’s not any more efficient strategy?
- outworlder 2y agoThat threw me off as well. Majority voting works for industries like aviation, but that's still about checking results of computations, not all memory addresses.
- _yb2s 2y agoECC is not easy to explain, and sounds like a tautology rather than an explanation "error correction is done with error correction"- unless you give a full technical explanation of exactly what ECC is doing.
- marcellus23 2y agoRegardless of whether the parent's sentence is a tautology, the explanation in the article is categorically wrong.
- vlovich123 2y agoYeah, I couldn't quite remember if ECC is just hamming codes or is using something more modern like fountain codes although those are technically FEC. So in the absence of stating something incorrectly I went with the tautology.
- bawolff 2y agoCategorically might be a bit much. Duplicating bits with majority voting is an error correction code, its just not a very efficient one. Like its wrong, but its not like its totally out of this world wrong. Or more speciglficly its in the correct category.
- bawolff 2y agoDoesn't feel like a breakthrough. A positive engineering step forward, sure, but not a breakthrough. And wtf does AI have to do with this?
- wasabi991011 2y agoIt's not a major part of the paper, but Google tested a neural network decoder (which had the highest accuracy), and some of their other decoders used priors that were found using reinforcement learning (again for greater accuracy).
- cwillu 2y agoWow, they managed to make a website that scales everything except the main text when adjusting the browser's zoom setting.
- rezonant 2y agoThere should be a law for this. Who in their right mind wants this?
- essentia0 2y agoThey set the root font size relative to the total width of the screen (1.04vw) with the rest of the styling using rem units Ive never seen anyone do that before.. It may well be the only way to circumvent browser zoom
- rendaw 2y agoWhy don't browsers reduce the screen width when you zoom in, as they adjust every other unit (cm, px)?
- zamadatix 2y agoThey effectively do. All css absolute units are effectively defined as ratios of each other and zoom*DPI*physicalPixels sets the ratio of how many physical pixels each absolute unit will end up turning into. Increase zoom and the screen seems to have shrunk to some smaller 'cm' and so on. For things like 'vh' and 'vw' it just doesn't matter "how many cm" the screen is as 20% of the viewing space always comes out to 20% of the viewing space regardless how many 'cm' that is said to be equivalent to.
- rendaw 2y agoOh duh, right. Thanks!
- imglorp 2y agoWhy is it so desirable to circumvent browser zoom? I hate it.