When will #quantumcomputers be able to break encryption like RSA? You need to watch 2 parameter: 1️⃣ Hardware improvements: Number of qubits AND Error rates (success rate of a gate operation, current best hardware from IonQ, Quantinuum IQM Quantum Computers, Google range around 99.9-99.99%) 2️⃣ Algorithmic requirements (more efficient algorithms need less qubits etc.) Key takeaways: 👉 Latest estimates from Craig Gidney do not rely on new, exotic architectures. Assumes a standard grid of nearest-neighbor-connected qubits. 👉 1M qubit target is still ~9,500x larger (13.2 doublings) than today's best physical devices. 👉 Expect lower boundaries around 1024 logical qubits to factor RSA-2048 with surface code distance of at least 10 (or 242 physical qubits for each logical qubit) --> ~242,000 qubits Very nice webpage and objective information from Samuel Jaques -- many thanks!
Over time, which one advances faster: quantum computers or quantum-safe cryptography including protocols and also cryptographic agility? Since both advance with a certain speed, important is to understand how fast quantum computers can catch up with classic and revisited quantum-safe cryptography. By the way very interesting graphics and paper you share here Niklas Hegemann, thank you!
Really insightful post. The pace of hardware improvement is impressive, and it’s encouraging to see parallel progress in post-quantum cryptography too. By the time devices approach the RSA-breaking region, most critical systems should already be using quantum-safe protocols. It’s great to see both sides advancing together!