Will you heed my warnings NOW?

Holy crap … yesterday I was elected to the US National Academy of Sciences! If you don’t believe me, click the link and keep scrolling down until you hit the name “Aaronson.” But then continue scrolling to see 144 other inductees, including my IAS postdoctoral classmate Maria Chudnovsky, my longtime friend and colleague Salil Vadhan, and even Janet Yellen. I’m humbled to be in such company.

Years ago, somewhere on this blog, I mused that, if I were ever invited to join NAS, I hoped I’d follow the wisdom of Richard Feynman, who famously resigned his NAS membership, comparing it to an honor society back at his high school that spent most of its time debating who should be a member of the honor society. Feynman was also annoyed at having to pay dues.

But now that I’m actually faced with the choice, it’s like, dude! At my advanced age of 44, I’ve encountered so many people who dislike me or even sneer at me, and so many clubs that won’t have me as a member, that I feel mostly gratitude and warmth toward a fine club like NAS that will have me as a member. Anyway, I’ll certainly try it out to see what it’s like—even Feynman did that!

A few hours after I started getting congratulatory emails, for which I was thankful, someone from UT Austin’s press office asked me how I feel about this “culmination” and “capstone” of my entire research career. I replied, look, I know I’ve slowed down a lot since my nubile twenties, but I still hold out the hope that this isn’t any kind of “capstone”!

In any case, I’m ridiculously grateful to all the friends, family, colleagues, and readers who believed in me and helped me reach wherever this is.


Now for a totally different topic, but that will ultimately loop back to the first one:

Last week, I did an Ask Me Anything about quantum computing and blockchain for stacker.news, a forum devoted to bitcoin. Thanks to Will Scoresby for organizing it.

As a longer-term commitment, I also collaborated with my colleagues Dan Boneh, Justin Drake, Sreeram Kannan, Yehuda Lindell, and Dahlia Malkhi, in a panel convened by Coinbase, to put out a detailed position paper about the quantum threat to cryptocurrencies and how best to respond to it. Take a look!

Notably, the situation evolved even while we were writing our position paper—for example, with the major recent papers from Google and Caltech/Oratomic that I blogged about a month ago.

I’d now like to add a few words of my own, not presuming to speak for my fellow Coinbase panelists.

See, some of the most reputable people in quantum hardware and quantum error-correction—people whose judgment I trust more than my own on those topics—are now telling me that a fault-tolerant quantum computer able to break deployed cryptosystems ought to be possible by around 2029.

Maybe they’re overoptimistic. Maybe it will take longer. I dunno. I’m not a timing guy.

But here’s what I do know: the companies racing to scale up fault-tolerant QC, have no plans to slow down in order to “give cybersecurity time to adapt” or whatever. The way they see it, cryptographically relevant QCs will plausibly be built sometime soon: indeed, it’s ultimately unavoidable, even if people’s only interest in QC was to do quantum simulations for materials science and chemistry. So, given that reality, isn’t it better that it be done first by mostly US-based companies in the open, than by (let’s say) Chinese or Russian intelligence in secret? And besides, haven’t there already been years of warnings and meetings about the quantum threat to RSA, Diffie-Hellman, and elliptic curve cryptography? Aren’t many in cybersecurity still in denial about the threat? Haven’t these slumberers shown that they won’t wake up until dramatic achievements in fault-tolerant QC roust them—the way Anthropic’s Mythos model has now jolted even the most ostrich-like about the cybersecurity risks of AI? So, mixing metaphors, mightn’t we just as well rip this Band-Aid off ASAP, rather than giving foreign intelligence agencies extra years to catch up? Indeed, when you think about it that way, isn’t racing to build a cryptographically relevant QC, as quickly as possible, the most ethical, socially responsible thing for an American QC company to do?

Is the above line of reasoning suspiciously self-serving and convenient? Does it remind you of the galaxy-brained arguments that AI company after AI company has offered over the last decade for why “really, if you think about it, accelerating toward dangerous superintelligence is the safest course of action that we could possibly take”? I.e., the arguments that led to the current frenzied AI race, which some believe imperils all life on earth?

It’s not my place here to answer such questions; I leave further ethical and geopolitical debate to the comment section! My point is simply: whether or not anyone likes it, this is how some of the leading QC companies are now thinking about the Shor of Damocles that they genuinely believe now hangs over the Internet.

And I’d say that that makes my own moral duty right now ironically simple and clear: namely, to use my unique soapbox, as the writer of The Internet’s Most Trusted Quantum Computing Blog Since 2005TM, to sound the alarm.

So, here it is: if quantum computers start breaking cryptography a few years from now, don’t you dare come to this blog and tell me that I failed to warn you. This post is your warning. Please start switching to quantum-resistant encryption, and urge your company or organization or blockchain or standards body to do the same.

Yea, heed my warning, for it comes not from some WordPress-using rando, but from the inventor of BosonSampling and PostBQP and shadow tomography, the Schlumberger Centennial Chair and Founding Director of the Quantum Information Center at the University of Texas at Austin, and (wait for it) new member of the US National Academy of Sciences, that august and distinguished body brought into being by President Abraham Lincoln in 1863.

Because, you know, none of this is about me. It’s only about you. And whether you’ll listen to me.

86 Responses to “Will you heed my warnings NOW?”

  1. Domotor Palvolgyi Says:

    You should copyright Shor of Damocles!

  2. David Glenday Says:

    Shor of Damocles is good. I even wondered if it was original and it is. At least this what Gemini is saying:The phrase “Shor of Damocles” is a punning metaphor used in the field of quantum computing, coined by researcher Scott Aaronson on his blog Shtetl-Optimized.

  3. gentzen Says:

    Let me be honest: What worries me about current approaches to quantum-resistant encryption is that they are (mostly) based on mathematical problems involving dihedral groups instead of abelian groups. And dihedral groups don’t feel very different from abelian groups. In fact, one could even say that dihedral groups are the non-abelian groups closest to abelian groups.

    And this feeling has provided motivation in the past for “generalizing” descriptive complexity results (https://cstheory.stackexchange.com/questions/47932/is-descriptive-complexity-dead) from abelian groups to dihedral groups. Here I am thinking especially about
    https://arxiv.org/abs/2010.12182 (Canonization for Bounded and Dihedral Color Classes in Choiceless Polynomial Time)

  4. Scott Says:

    gentzen #3: Dihedral groups are “so close to abelian, yet so far.” The project of generalizing Shor’s algorithm to the hidden subgroup problem over the dihedral group has now been stalled for 30 years—ie, the majority of the way back to the invention of RSA and Diffie-Hellman themselves. I’m not saying it’s impossible—in the current state of complexity theory, every cryptographic hardness assumption is ultimately a leap of faith—but the decades of failure by excellent mathematicians have to put some lower bound on the difficulty of the problem, don’t they?

  5. OhMyGoodness Says:

    Congratulations, very nice honor. I imagine the endeavor for conversion to quantum computing resistant cryptography will be extremely gratifying. A right place at the right time synchronicity.

    I looked at resignations from NAS, following your comment about Feynman. The first departure (Josiah Whitney resigned 1874) was interesting. His career was marked by strident disagreements with other geologists and he was inevitably on the losing side.

    He certified a human skull found by miners as genuine and 50 million years old but it was found to be a hoax perpetrated by the miners. He was adamant that California had low prospects for oil production just prior to a California oil boom. He opposed John Muir’s explanation for the origin of Yosemite Valley due to glacial scour just before Muir’s model was widely adopted as the correct interpretation of the data. No surprise that he resigned.

    I first thought capstone was a euphemism for gravestone and was associated with a vow of silence for the secret handshake but then settled on a more prosaic interpretation. 🙂

  6. Phillip Says:

    But Scott, doesn’t the technology in question accelerate research in biochemistry, medical science and life extension? Every year the technology is delayed costs millions of lives — if we develop it quickly enough we might even become immortal!

  7. Mark Stavaski Says:

    Thank You for all you do. Ski

  8. gentzen Says:

    Scott #4: “but the decades of failure by excellent mathematicians have to put some lower bound on the difficulty of the problem, don’t they?”

    Yes, but I would worry even less if there were something similar to Joshua Grochow’s evidence that Graph Isomorphism is not in P (https://cstheory.stackexchange.com/a/32168/20340) back in 2015.
    Joshua Grochow himself would still be a good candidate to provide such evidence. But Pascal Schweitzer or Moritz Lichter might be even better candidates, because they actually succeeded to beat dihedral groups into submission. I guess that was the point in 2015, that there was somebody who was not just an excellent mathematician in general, but one who worked on the specific problem and proved his excellency by related successes with “the most critical group structure” blocking further progress.

    Also, the decades of failure might be misleading, because the importance of dihedral groups only became apparent much later.

  9. Scott Says:

    Phillip #6: I don’t know whether you’re serious or trolling, but certainly people often make that argument for AI, and one could indeed also imagine making it for quantum simulation. How to balance that with the risk of breaking the Internet is a question I’ll leave for the commentariat!

    Let me add one thing, though: when Leonid Levin emailed me yesterday to congratulate me on the National Academy thing, he reaffirmed that, for him, quantum computing remains 100% a hoax and garbage, and none of the experimental progress of the past quarter-century has moved him even a nanometer.

    For me, then, what really needs to be balanced against the risk of destroying the Internet, is the sheer joy of Leonid Levin living to see a quantum computer factor 2048-bit integers.

  10. David Karger Says:

    I think you’re worrying too much. Once we achieve AGI we’re going to be living in a utopian post scarcity society where money won’t matter anymore. So we won’t need cryptocurrency.

  11. Illusory Factoid Says:

    Talking about the now, here’s another piece of wisdom from Alan Watts

  12. Martin Aulbach Says:

    Congratulations, Scott! I’m really happy for you to be elected to the NAS. Though I never commented here before, I’ve been following your blog and research intermittently for over 15 years and really think that you deserve that honor. Too few fellow scientists realize that AI and QC come with a lot of risks and even dangers. Thank you for sounding the alarm! Maybe someday you’ll be an influential voice for the ethical usage of AI and QC. 😉

  13. Craig Gidney Says:

    It’s kind of wild, looking back, how much people kept doubling down on quantum-vulnerable cryptography despite Shor’s algorithm being known. Shor published his algorithm in 1994. He showed fault tolerant quantum computation was possible in principle in 1996. Bitcoin started over a decade later, in 2009. It chose quantum-vulnerable cryptography. Ethereum started in 2015, a full two decades later. It chose quantum-vulnerable cryptography. Website certificates, satellite control systems, cpu microcode updates, on and on and on… everyone kept choosing quantum-vulnerable cryptography. There are products coming out *today* that use quantum-vulnerable cryptography! It’s maddening!

    Now, to be fair, quantum-secure cryptography standards didn’t exist until 2024 (!!!). And quantum-secure cryptography is more expensive. In isolation each of those individual choose-quantum-vulnerably-crypto decisions is understandable; in some cases arguably even correct given other considerations like network effects. But I think in hindsight this will all be seen as a massive societal blunder.

  14. John K Says:

    And you are assuming you are not getting fired by the administration tomorrow …

  15. Scott Says:

    John K #14: Fired by the UT administration? Why would they want to?

    Fired by the Trump administration? How would they (even now) have the power, and why would I be any sort of priority for them?

  16. Greg Says:

    Congratulations! Well deserved.

    That position paper is also very interesting, particularly section 1 which discusses the state of quantum computers. Quite a lot of that section will probably be familiar to any reader of this blog — but other parts, notably the taxonomy of five different approaches to QC hardware, were new to me on account of not having followed the technical details at that level. I appreciated the crisp overview.

  17. OhMyGoodness Says:

    Illusory Factoid #11

    After Watts excised the past and the future he must have found even the present to be exceedingly difficult. It is reported that he drank copious amounts of alcohol and died an alcoholic (this in addition to four packs of cigarettes per day). It was actually the cigarettes that killed him. He was cremated and considering his reported alcohol consumption his body must have burned for a few days.

    I haven’t read any of his books. The only book I have read in this category (call it) was “Zen and the Art of Motorcycle Repair”. Good book in my view that is partly a discussion of quality and state of mind as it applies to quality of work.

  18. John K Says:

    Apparently my joke was a little too subtle and related to the administration firing of the National Science Board yesterday.

  19. Joshua Zelinsky Says:

    @Scott #6,

    “Let me add one thing, though: when Leonid Levin emailed me yesterday to congratulate me on the National Academy thing, he reaffirmed that, for him, quantum computing remains 100% a hoax and garbage, and none of the experimental progress of the past quarter-century has moved him even a nanometer.

    For me, then, what really needs to be balanced against the risk of destroying the Internet, is the sheer joy of Leonid Levin living to see a quantum computer factor 2048-bit integers.”

    Pretty much the only reasons I wouldn’t say I’m not 100% confident that large scale quantum computers aren’t inevitable (barring things like nuclear war or existential risk) is that both Leonid Levin and Gil Kalai, who are both smarter than I am, and have thought much more about these things, seem so convinced that quantum computing isn’t going to be a practical thing ever. Yann LeCun occupies a similar role in reducing my confidence about where capabilities are going where AI is concerned.

  20. Patrick Dennis Says:

    OhMyGoodness #17

    For the sake of completeness, it’s “Zen and the Art of Motorcycle Maintenance” by Robert Pirsig.

    Yes, agreed, a *very* good book, one that I was in awe of at at the time (1974), and one that helped conceive and then birth the publication this year of “Maintenance of Everything: Part One,” by the indefatigable Stewart Brand.

    It looks as though Bitcoin is in need of some maintenance!

  21. Prasanna Says:

    Adding on to optimism of AGI utopia, the great physicist Leonard Susskind just dropped a video on why Aliens will never arrive on earth. No matter how advanced their civilization is they cannot engineer their way to earth, simply because of the current known laws of physics simply make it overwhelming, even in principle. The best exposition I have seen on this subject, so one more reason not to lose sleep 🙂

  22. Brian Slesinsky Says:

    It’s starting to feel like arms races are just inevitable, between drones in Ukraine, AI, and quantum computing. And of course many historical examples.

    The difference seems to be that now we see them coming further in advance? People talk about them all the time. But apparently nothing can be done other than to prepare defenses.

    What would you tell a student who is considering studying quantum computing?

  23. OhMyGoodness Says:

    Patrick Dennis #20

    Thanks for the correction. I haven’t thought abut this book specifically in some years (read it in the early 90’s) but know it contributes to how I think. I agree fully with your addition of “very”.

    Thanks so much for the reference to “Maintenance of Everything…”. I will check it out.

  24. Pat Says:

    When are you going to write posts about

    Claude Mythos

    The latest assassination attempt

    The Iran War

    If you’re planning on shutting down the blog, please let me know, to save me the trouble of checking after every world-shattering event and finding nothing.

  25. Scott Says:

    Pat #24: You unwittingly provide a strong argument for resisting the temptation to blog about current events. Namely, whenever I do, commenters like you then assume that I’ll respond to all the other current events (something that’s not going to happen, because of both my temperament and my harried life circumstances), and get upset at me when I don’t.

  26. Illusory Factoid Says:

    Patrick Dennis

    I personally like even more Pirsig’s follow up book “Lila: An Inquiry into Morals”.

    OhMyGoodness

    Watts never made any claim about being perfect and saw self-improvement as a fool’s errand, in the sense that one can’t pull himself from his own bootstraps, any change is a result of the universe doing exactly what is meant to happen (some call it “grace”), he derided activities like jogging.
    He admitted he had flaws, like everyone else, but he never thought there was any need to drive himself nuts over it. He never pretended to be a guru, all he wanted was doing what he enjoyed and was good at: giving inprovised speeches on philosophy (and I never saw evidence that his drinking was interfering with that).
    So he really lived according to his own values, that his life is what it is, with its good and bad, and was very finite, and it’s not a matter of how many years you live, because life is an endless continuous process – humans beings constantly die and are born, which is fundamentally the evidence for what some call reincarnation (when stripped of all the bs):

    https://youtu.be/Mt5D2y-naz4

  27. gentzen Says:

    Prasanna #21: “Adding on to optimism of AGI utopia, the great physicist Leonard Susskind just dropped a video …”

    No, that channel is not associated with Leonard Susskind in any way. From its description: “Welcome to Susskind Physics, … in a powerful lecture style inspired by Leonard Susskind.”

  28. Illusory Factoid Says:

    It’s also helpful to keep in mind that Alan Watts lived from 1915 till 1973 (born during WW1 and died during the vietnam war), in an era where chain smoking and boozing (and also womanizing) were pretty much the social norm (accepted, if not encouraged), with the psychedelics revolution going on.

  29. Pat Says:

    If it’s not already clear, the problem with that is if you’re silent about, not just “current events,” but events of Earth-shattering importance, your blog readers will fill in the gaps and conjecture about your real opinions. For instance, because of your silence about the assassination attempt, I wonder if you tacitly support it, because if Trump is the existential threat to democracy that you claim, then why shouldn’t it be a moral imperative to kill him? And because you’re not publicly supporting the war in Iran, I also wonder whether your support for Israel is waning, and you no longer believe the US should protect Israel from existential threats. I’m not saying I think you believe these things. I’m saying that in the absense of any commentary whatsoever, my mind can’t help but try to fill in the gaps.

  30. OhMyGoodness Says:

    Illusory Factoid #26

    I wasn’t sure about your personal beliefs about Watts and strongly support your right to believe what it is that you believe, so forgive my earlier tone. My view is that he suggested to the public that he knew of a path to achieve greater happiness and fulfillment. My view then is that this path infofar as he followed it resulted in a wreck of a human being in his personal life. He It wasn’t that he was imperfect but that he was consumed by vices to the detriment of his personal relationships and to his health. If he started his stand up philosophy presentations by noting his uncontrolled alcoholism, his inability to maintain a marriage, and his four pack a day cigarette habit then I would have more respect for his basic decency.

    I have a distaste for the pop-science-psychology-philosophers of that period. Timothy Leary also comes to mind. Ethical? Hardly, the Weather Underground broke him out of prison (low security I think) and spirited him away to Algeria. Once he is back in prison he makes a deal with the FBI providing information on the Weather Underground, gets released from prison and goes in to witness protection. Before he was fired from Harvard he refused to follow the reasonable standards that the school imposed for experimenting on students with hallucinogenic drugs. He was estranged from his son and a daughter committed suicide. His life was a mess but publicly a psychologist philosopher guru persona.

    Thanks for the reference to the later Pirsig book. I respect Pirsig’s open honesty about the severe problems in his personal life.

    Again, my purpose is not to belittle your beliefs but just explaining the rationale for my own.

  31. Felipe Guerra Says:

    Interesting shift in tone. This reads less like a distant warning and more like “this is happening, deal with it.” The part about not waiting for QC progress – even if it sounds a bit convenient – actually lines up with how incentives work in practice.

    Also interesting to see how this contrasts with projects that already assume this future by default, like Quantum Resistant Ledger, instead of planning to migrate later. Not saying that’s the winning approach, but it does avoid the whole “we’ll handle it when the time comes” mindset.

  32. Jean Archambault-White Says:

    Reading this made me realize how urgent the conversation around quantum computing and cryptography is becoming, especially as experts suggest that breaking current encryption might not be as far off as people once thought. It’s striking how the post shifts from a more cautious, “someday” tone to a clearer warning that organizations should already be preparing for quantum-resistant systems.

  33. Matteo Vitturi Says:

    First of all, my warmest congratulations on your well-deserved election to the US National Academy of Sciences! It is a truly wonderful and richly deserved recognition.

    Regarding the “harvest now, decrypt later” issue, I keep thinking that if cryptographically relevant quantum computers arrive in a few years, the biggest practical headache may not only be protecting new communications, but dealing with the enormous quantity of already-encrypted data accumulated over the past decades — both online and stored offline. What worries me even more is the possibility that this could become a massive intelligence operation, with various state actors quietly hoarding encrypted data, waiting for the right moment to decrypt it — a bit like a real-world version of a 007 plot, but on a global scale. I’m curious to know whether you see this “retrospective” part, and its intelligence implications, as the more difficult challenge in the long run.

    Thank you as always for your clear and honest perspective.

  34. Illusory Factoid Says:

    OhMyGoodness

    no problem! Your comments on Watts’ “vices” don’t belittle my beliefs, because what Watts offered isn’t really a matter of belief but pretty much direct observation, although from some unusual “angle”, his only interest was to open the Western mind to the views of the Asian mind (on nature, death, etc).
    So the fact that he was flawed has really no bearing on what people learned from him, quite the opposite… as he often said, don’t trust Goody Two-Shoes! (he was actually very rarely passing judgment on others)
    He viewed himself as an entertainer, not some guru having “answers” and he didn’t give very practical advices besides living in the moment: if you’re smoking 10 packs a day with whiskey, well, at the very least make sure you’re present and you enjoy every second of it!…
    he didn’t advocate that people ought to believe in Buddhism, Zen, Taoism, or Hinduism, he just explained how they compare and how they give an alternative interpretation of the world (eg the West tends to think the universe is an artifact created by God, and he dropped us in it… the East thinks the universe just “grows” like a tree and we came out of it, like how the tree grows fruits). He was also very aware of physics, often giving interpretations that rested on quantum field theory (without anything added).

  35. Illusory Factoid Says:

    It’s maybe understandable that the advent of nuclear weapons didn’t make us rebuild all our cities 2km underground, or that the clear signs of global warming still don’t make us seriously consider transitioning to clean energy…
    but switching encryption implementation seems like a low hanging fruit in comparison.
    The last time something was universally done was for y2k… maybe it went too well and we think tech disasters can’t happen. Which is also why nothing’s getting in the way of the AI arms race.

  36. Scott Says:

    Pat #29: Very well, troll.

    Just like I have in the past, I unequivocally condemn all attempts to assassinate President Trump, the members of his administration, or pretty much anyone else two or more steps above “literal Hitler” on the evil scale. Even setting aside deontological considerations, we can see empirically that these sorts of assassination attempts (whether they succeed or fail) have consistently made the world worse.

    Regarding Iran, my feelings remain exactly what they were at the beginning: namely that, as Sam Harris put it, the war to overthrow the murderous regime in Tehran is “the right war being waged by the wrong people”—people whose motivations are craven and self-interested rather than moral, and whose strategic abilities barely extend beyond the next five minutes, like a toddler’s. I nevertheless pray for the liberation of the wonderful people of Iran, and indeed all the people in the Middle East terrorized by the Ayatollah regime, despite the cravenness and incompetence of the leadership of their would-be liberators.

  37. Dave Chapman Says:

    Dude!!!
    I had no doubt!
    You are most definitely worthy!

  38. Treasure Carp Says:

    The biggest thing standing in the way of migrating to PQ for me right now is a lack of an equivalent to threshold BLS12-381 signing. There’s some prototype schemes for threshold, but none that are 2/3+1 instead of 1/2+1, none that support noninteractivity, and only the very latest support large party numbers like 43. We may be completely doomed, because even if we get a scheme just barely before we run out of time and just barely have enough time to implement it, it’ll be new and untested and likely to have a flaw.

  39. Adam Treat Says:

    Pat,

    Pound sand.

    Sincerely,
    The rest of us

  40. Illusory Factoid Says:

    Scott has commented a lot on Iran on his blog, a simple search isn’t that hard to get a sense of his (complex) opinions on this topic:

    https://scottaaronson.blog/?p=8458

    Now Kamala is not Winston Churchill. But at least she doesn’t consider the tyrants of Russia, China, and North Korea to be her personal friends, trustworthy because they flatter her. At least she, unlike Trump, realizes that the current governments of China, Russia, North Korea, and Iran do indeed form a new axis of evil, and she has the glimmers of consciousness that the founders of the United States stood for something different from what those tyrannies stand for, and that this other thing that our founders stood for was good. If war does come, at least she’ll listen to the advice of generals, rather than clowns and lackeys.

    https://scottaaronson.blog/?p=8410#comment-1991674

    But crucially, that doesn’t mean the US should declare war against those regimes right now—i.e., that such wars would be winnable at an acceptable cost! That would still be a huge question, even if the quagmires of Afghanistan and Iraq (and before that, Vietnam) hadn’t underlined the question of whether the US still has the abilities it had in WWII.

    https://scottaaronson.blog/?p=8172#comment-1983878

    Furthermore, while I’m sure Bibi would be thrilled for the US to lead a preemptive war against Iran, most of my Israeli friends wouldn’t be. They know that such a war, even if Israel didn’t start it, would precipitate the worst assault on Israel in its (post-1947) history, and that Israel might or might not survive.

    Look, I want the murderous Ayatollah regime gone as fervently as anyone does, with the possible exception of my Iranian friends. But it’s totally unclear to me that launching a “regime change” war against Iran in the near future would be wise. The US’s recent record with such wars is famously less than sterling. Our uneasy semi-truce with Iran has lasted since 1979. In the case of the Cold War, we basically just waited it out for 45 years until the Soviet Union (which had thousands of nuclear weapons) collapsed from its own internal decrepitude and the bravery of its internal dissidents. Iran, too, has staggering amounts of both internal decrepitude and brave dissidents. Probably 2/3 of its people despise the Ayatollahs. So maybe the right strategy is again to wait it out, while making clear that, if the secular majority tries again to revolt like it did in 2009, the West will be ready this time with money and weapons and aid?

    https://scottaaronson.blog/?p=3766

    My conversations with Iranian friends sometimes end with us musing that, if only they made them Ayatollah and me Israeli Prime Minister, we could sign a peace accord next week, then go out for kebabs and babaganoush

  41. Illusory Factoid Says:

    How does absolute opposition to political violence square with the idea (often brought up in this blog) that it’d be morally right to go back in time to assassinate Hitler?

    Is it a matter of knowing the future with certainty?
    Like depicted in the movie The Dead Zone, where a psychic (played by Christopher Walken) knows that a POTUS candidate will unleash nuclear armageddon if elected, and he decides to resort to political violence to stop him? (I do recommend the movie, from a Stephen King book).

    Or is it just a matter of doing it in a non-violent way by just disturbing the coitus that lead to Hitler’s conception?

    But even if changing the past was feasible you can’t be sure that changing the past won’t lead to an even worse long term outcome!

  42. Scott Aaronson’s View of my View About Quantum Computing | Combinatorics and more Says:

    […] must prepare for it.  Scott himself goes beyond these joint conclusions and expresses his personal warning that quantum computers may start breaking cryptography a few years from […]

  43. Ralph Kelsey Says:

    Adam Treat #39:

    Excellent summary.

  44. Anon Says:

    congrats! very well deserved.

    it is nice to see young scientists joining NAS.

  45. Anon Says:

    #10

    lol

    Karl Popper:

    “The attempt to make heaven on earth invariably produces hell.”

    “Those who promise us paradise on earth never produced anything but a hell.”

    Gemini:

    Why Building “Heaven” Can Create “Hell”

    – Utopian Disasters: Attempts to force a perfect society (heaven) usually require overriding free will and forcing conformity, which produces misery and totalitarianism (hell).

    – Human Limitation: Humans are flawed, and attempts to manufacture a perfect paradise often lead to catastrophic failures and suffering.

    – The Problem of Evil: The world contains brokenness; trying to ignore this by imposing an unnatural perfection can exacerbate pain.

    – Different Visions of “Heaven”: Because humans cannot agree on what a perfect world looks like, one person’s heaven is inevitably another’s hell.

  46. Roger Schlafly Says:

    The joint paper on the quantum threat stops short of saying that a crypto disaster is inevitable. It says: “the position that quantum computing is impossible in principle … could be true, … we can say with extremely high confidence that … people should not pin their hopes … on the belief that QC is impossible for some fundamental reason.” It also stops short of claiming that the threat is imminent.

  47. Scott Says:

    Roger Schlafly #46: Good reading comprehension! 🙂

    Even in this post, where I used stronger language, I stopped short of saying that I know for sure that this will happen, let alone happen in a few years. Nevertheless I think the risk is now more than clear enough to justify switching to PQC.

  48. Anon Says:

    #47 Re: the risk is now more than clear enough to justify switching to PQC

    I get the rationale for long‑term secrets, but could we switch later for short‑term ones? Or is it not really worth it, since paying for the first more or less covers the second as well?

    #36 Re: Regarding Iran, my feelings remain exactly what they were at the beginning

    Really? I would have thought you’d move from “I’m not sure, maybe a US military intervention could actually help” to “Alright, now we know it actually made things worse. Again.”. Or is that exactly why you said feelings, not rational updating?

  49. JimV Says:

    RE: ” I’m humbled to be in such company.”

    I’m sorry but I have to say this: no, you aren’t. You are honored. Humbled is when somebody grabs you by the back of the neck and rubs your nose in the dirt.

    Why does everybody say humbled now instead of honored? I guess because it sounds more humble, but there are a lot more effective ways to make you humble than giving you a reward for merit. Ways none of us want to experience.

    Congratulations on the honor!

  50. Vladimir Says:

    Illusory Factoid #40

    > Furthermore, while I’m sure Bibi would be thrilled for the US to lead a preemptive war against Iran, most of my Israeli friends wouldn’t be. They know that such a war, even if Israel didn’t start it, would precipitate the worst assault on Israel in its (post-1947) history, and that Israel might or might not survive [https://scottaaronson.blog/?p=8172#comment-1983878]

    I wonder whether this turning out to have been spectacularly detached from reality has caused Scott to revise any of his opinions.

  51. Scott Says:

    Vladimir #50: Wow, that comment of mine does seem pretty detached from the realities of 2026! Almost as if I was addressing some different, earlier reality.

    And it turns out that I was! Following the links, I see that I wrote the comment in August 2024—so, a month before Israel’s spectacular pager attack against Hezbollah, and a few months before the downfall of Assad.

    Before Iran’s proxies had been defanged, starting a war against Iran could’ve indeed led to exactly the consequences for Israel that I described. Imagine Hezbollah firing all 150,000 of its missiles at Israel, overwhelming Israel’s interceptors: the effect could’ve easily been as bad as a nuclear strike against Tel Aviv.

    So, it was only the downfall of Iran’s proxy empire that made a war against Iran itself even conceivable. Alas, that still doesn’t mean such a war will be successful! If it’s going to be waged at all, it would still be vastly preferable to have it waged by leaders able to think at least five minutes ahead, and who value the freedom of the Iranian people more than their own electoral fortunes.

  52. Paul Crowley Says:

    Scott, you clearly need a subscription to Condemnr https://readscottalexander.com/posts/acx-sources-say-bay-area-house-party

    As for the huge delay between the publication of Shor’s algorithm and the standardization of PQ algorithms, I think a huge amount of credit is owed to Bernstein in particular for coining the term “post-quantum” and coalescing a research community around the topic.

  53. AC Says:

    Congratulations, Scott!! …and Shor of Damocles is a very nice metaphor 🙂

  54. Illusory Factoid Says:

    The two topics of Iran and Political Violence actually meet.

    “May we give the Ayatollah the martyrdom he preaches, and liberate his millions of captives.”

    (https://scottaaronson.blog/?p=9481)

    Is violence to force regime/political change acceptable as long as it’s applied to another country?

    As I wrote above, the actual problem is that you really never know whether forcing change through violence won’t actually lead to a worse outcome, because violence begets violence in a spiral that’s very hard to control and stop.
    Here the warmongers got us a new Ayatollah whose father, mother, wife, a two children they have murdered, and he would be expected to even more ruthless as a result (unless he’s some kind of living Buddha).

  55. William Gasarch Says:

    (I’m surprised nobody brought up this point, though perhaps I did not read the comments carefully.)

    If a Quantum computer can factor 2048-bit integers quickly then if people switch t o 4096-bits will security be safe (at least for a while)?

  56. Vladimir Says:

    Scott #51

    Hezbollah never had 150,000 missiles, or even 150,000 rockets. The vast majority of the rockets it did have had short ranges (incapable of reaching Haifa, never mind Tel Aviv) and low warhead weights (very unlikely to kill people who’ve taken precaution). If it had magically launched its entire arsenal simultaneously in August 2024, it might’ve killed a couple of thousand people. You can easily convince yourself of this if you’ll take about half an hour to look into it using your favorite AI; for a shortcut, see here a Twitter thread from February 2024:

    https://x.com/danielbachmat/status/1761367678021763228

    Setting aside the reasonableness of your belief that Hezbollah could inflict damage as bad as a nuclear strike against Tel Aviv, do you see anything problematic with your and most of your Israeli friends takeaway from that being “oh well, guess there’s nothing to be done about Iran” rather than e.g. “Israel and the US should make sure they defang Hezbollah before proceeding to deal with Iran”?

  57. NotLeonardSusskind Says:

    Hey Scott, iirc you are actually in contact with Leonard Susskind – could you bring to his attention the youtube channel from #21 so that he could take action, and maybe remove it from here so as not to deceive people?

  58. Jacob Oertel Says:

    Congratulations on the wonderful news!

    Accelerationism seems like an unnecessarily fancy way to say “all gas, no brakes” in some given context and its proclivity for structural failure isn’t primarily logical; it’s that the logical apparatus is doing psychological work the speaker isn’t accounting for. The reasoning bypasses the axiomatic layer (who is racing whom, on behalf of what, with what discount on the future) and the bypass serves a function: keeping the speaker from having to sit with the dissonance underneath. The Durants give us the field; competition is real, scarcity is structural, racing is sometimes the right move. Krishnamurti gives us the discipline; there’s a difference between arriving at “race” as an answer and using “we have to race” as a way to avoid the question. The propositional content can be identical; the interior posture is opposite. One is a conclusion someone has sat with. The other is a deflection wearing a conclusion’s clothing. The critique isn’t of speed. It’s of speed in service of avoidance. And the same critique can apply to those who critique accelerationism: noticing when our critique is doing the same psychological work in reverse, generating certainty about the racers so we don’t have to sit with our own dissonance about being inside a system partially shaped by racing.

    This suggests where the leverage actually is. Voluntary lab-level coordination runs into capital structure (funding terms written for continued capability progression), talent markets (researchers exit visibly-slowing labs for racing ones), information asymmetry (no verification mechanism exists for whether competitors are actually slowing), and identity binding (for some senior researchers, racing toward the next capability threshold is not simply a strategic position but an identification, and asking them to coordinate is asking them to disidentify from what they take their work to be for). The other three constraints respond to incentives; identity binding doesn’t because the racer isn’t reasoning toward “race” as the better strategy. “Race” is already the answer to a deeper question about what their work is for. This is why external constraints succeed where internal restraint fails: a compute cap or treaty threshold lets the racer keep the identification intact rather than asking them to revise it.

    These constraints reinforce each other: capital flows to racers; talent identity-bound to racing follows the capital; information asymmetry compounds because non-racers can’t see what racers are doing; capital flows further to where the visible progress is. These constraints operate whether or not lab leadership wants to coordinate. Which means the binding question isn’t whether labs can coordinate — they mostly can’t, structurally — but whether coordination mechanisms exist outside the racing system that don’t depend on lab cooperation.

    Three categories look tractable. First, compute governance: frontier capability requires concentrated compute, compute requires geographically-concentrated fabrication, and that concentration creates an enforceable chokepoint. Multilateral thresholds on FTQC scale-up or on frontier training runs, with verification through compute-provider attestation, are technically possible. Second, verification infrastructure for state-level coordination: this kind of work doesn’t yet have the equivalent of test-ban verification. Building that equivalent, technical mechanisms by which adversary states could establish the state of each other’s art at agreed capability thresholds, is one of the most important infrastructure projects currently underfunded. Third, brake infrastructure that thickens the margins the racing depends on: post-quantum migration, dependent-system resilience, public literacy about contemporary technological capabilities. These are leverage points on different parts of the same system and none of this requires labs to cooperate. All of it makes the cascade less catastrophic if cooperation fails. This blog post is itself an instance of the third category.

    The reflexive critique applies here too: brake-building can be its own form of deflection, a way to feel responsive without sitting with whether the racing should be happening at all. I think the racing here is genuinely worth braking against, but the reflexive flag matters for my own proposals as much as anyone’s.

  59. Paul Crowley Says:

    #55 Making the key twice as big makes breaking it take four to eight times as long.

    By way of an elaborate practical joke, some cryptographers carefully worked out what RSA would have to look like to resist quantum attack. It’s doable if you don’t mind the private key taking a *terabyte* of storage… https://eprint.iacr.org/2017/351

  60. OhMyGoodness Says:

    Illusory Factiod #54

    “violence begets violence”

    This, true to your screen name, is an oft quoted illusory factoid. Violence can beget violence but no universal law that it will beget violence. Some counterexamples follow-

    Third Punic War-Carthage defeat was everlasting
    Constantinople defense against Umayyads in 8th century
    Martel’s victory over Umayyads in Europe
    Norman conquest of England
    American Revolution
    American Civil War
    Leipzig and Waterloo Napoleonic Wars
    WW II Germany
    WW II Japan
    WW II Italy
    Capture of Noriega in Panama invasion
    Capture of Maduro in Venezuela

    Someone mentioned that the wrong people are running the war and like most I would run it differently. The current strategy is much different than previous administrations sending pallets of currency. I thought about what American President I would choose to run this war if a swap could be made. My list of potential replacements would be something like-

    Washington
    Lincoln
    Grant
    Franklin Roosevelt
    Truman

    These presidents faced the test and aced it. We should be so lucky now.

  61. Tom Says:

    Hi Scott,

    I’ve got something of a bee in my bonnet to write a book called ‘Quantum Physics for Your Dad’, based on conversations I’ve had with my own father and other 50-80 year old highly educated but non-technical individuals. Much of what has arisen is the kind of misconceptions you’re rightfully antagonistic to. When I go to sketch my ideas for the book, however, it just sounds like QCSC! Or a cross between it and ‘Thirty Years that Shook Physics’. I’ll keep thinking about it.

  62. Ex-Italian Lurker Says:

    Congratulations! And Very well deserved

  63. Ajit R. Jadhav Says:

    Dear Scott,

    Congratulations for the election. Of course, it must’ve been for your work in TCS in general — work spanning all those years.

    Still, simply because you also bundled in this position paper on QC and Blockchain in the same blog post, I’ve no option but to add a bit about the QC:

    I have tried to think a bit about what the position paper says, now with my better understanding of QM (iqWaves and the revisions to it and all that). I’ve also gone through Gil Kalai’s post (cf. #42 above), and a couple of his earlier posts to which he links from it. … Blockchain isn’t a topic of any interest whatsoever to me, but inasmuch as QC does involve QM, QC is.

    Thus, I guess I might’ve a bit to say about the QC part — i.e., provided that all the various points over which I’m mulling do get crystallized to something definitive to share. (Or at least, they *gel* together well enough!). That might take a while — may be a week, may be two weeks, may be two months, or even more.

    But for the time being, yes, I do note that the above position paper says that Quantum Simulation is now the primary driver. Then, its your own separate addition, as your personal opinion, this anticipation you keep about 2029 and all. … As to me, my own focus (for my thinking about the QC) happens to be about certain issues pertaining to the QC and the integer factoring problem (the same broad concern as Gil Kalai et al. have).

    OK. I can’t simply arouse your curiosity and just leave you hanging. So, let me add just “a word”: As you might perhaps recall, it’s been for years that I’ve been a soft skeptic of the QC, not a hard skeptic. With my much, much better understanding of QM of today’s, I guess my position is shifting a bit — just a slight bit — towards a little harder a skeptical position.

    But of course, as I said, I’m still thinking through these things. It would’ve been better if I could have a QC-knowledgeable person to interact with, right in person (say a PhD student, a post-doc, a prof, or similar). Online interactions are no match to working at a black-board or so. … I could’ve then got to my conclusions not only faster, but I guess the conclusions themselves (even if only tentative or probabilistic) would also have been much better … Anyway, I will still see what best can be done in the circumstances.

    But all that apart, congrats, once again.

    Best,
    –Ajit

  64. Illusory Factoid Says:

    Scott wrote in #36

    “namely that, as Sam Harris put it, the war to overthrow the murderous regime in Tehran is “the right war being waged by the wrong people”—people whose motivations are craven and self-interested rather than moral, and whose strategic abilities barely extend beyond the next five minutes, like a toddler’s”

    The problem is what everyone had warned: you can’t achieve regime change through bombing a country that’s much more powerful and prepared than Venezuela or Gaza (where regime change wasn’t even that successful).

    By all accounts the US/Israel bombing campaign against Iran went well in terms of the bombs reaching their intended targets (like killing scores of officials and military assets).

    The overall poor strategic results are constrained by what bombs can achieve.
    The main strategic blunder was to start a war in the first place.

    So I’m not clear what Scott and Sam are now expecting to be different strategy wise… like, send 150,000 US troops on the ground, the use of nukes?! Harder push for diplomacy with a country that has now been radicalized even further and no longer trusts our words after we sucker punched them twice? Escalate and expend into WW3, because this is a “right war”, no matter the cost?

  65. Georg Says:

    „ So, given that reality, isn’t it better that it be done first by mostly US-based companies in the open, than by (let’s say) Chinese or Russian intelligence in secret?“

    From a European point of view, these days I‘m not sure if there is a difference for us if Russia, China or the US gets there first.

  66. William Gasarch Says:

    Paul Crowley and anyone else who wants to chime in: You say that if we double the key size the amount of TIME for quantum computer won’t go up much. That I can believe. But what about all the other stuff you need: reliable error-corrected qubits, other hardware. Might that be hard to scale up?

  67. OhMyGoodness Says:

    Georg #65

    From a European view your statement may be true but from an objective point of view there is a considerable difference. I believe your statement may say more about the European point of view than about the relative effects on Europe of a country gaining a large strategic advantage with AI. Actually I believe China has a large following amongst EU technocrats so presumably they prefer China receive the spoils of Super-AI.

    Dr Aaronson

    I saw you are prominent in a YouTube video about Ewin Tang. Good work.

  68. Zalman Stern Says:

    Given the context and the proposed timeframe for fault tolerant quantum computing, one would have to assign a fair likelihood to *someone* already having the power to decrypt a lot of things people think are secure. It is well known that exploiting such an advantage well requires carefully choosing the opportunities to ensure the knowledge obtained does not result in actions that let adversaries know their encryption is broken. It is interesting to think about how a secret quantum computer would be used and perhaps to think how outsiders might detect the existence of such a technology.

    The US would be the most likely world power to have developed such a thing in secret. Given current geopolitics, that’s a strong incentive for pretty much everyone to fix their cryptography.

    Per Craig Gidney’s comment in #13, practice in security and cryptography stresses being very conservative in choosing algorithms, implementations etc. So it’s a tradeoff in that the stuff that’s been out there for a long time and is proven robust against current threats is a known quantity and folks are heavily encouraged to use it. Moving to something new is risky and generally happens slowly unless there’s a practical compromise in existence right now. Some of the early attempts to fix things did have problems and that did not help with momentum. Implementations, even if they have a formal proof which practically nothing does, have to be vetted in actual use. Smart folks don’t trust anything that hasn’t stood up to attack in the real world for some period of time.

    Given that crypto currency was an entirely new field, I do feel that realm should have been a leader in deploying post-quantum techniques, but the area is so rife with outright fraud, both technological and non-technological, I’m not convinced it matters much. More reason to mostly just avoid using the thing at all.

  69. E Says:

    Do you think the possibility of breaking cryptography by 2029 hinges on progress in neutral atom technology specifically, or do you see other technologies getting there by or around that time?

  70. Georg Says:

    OhMyGoodness #67:

    Can you kindly explain the „considerable difference“? The current US administration today is attacking Europe (and other not submissive countries) much more openly and directly than China, and it is fully supported by US big tech – or did I miss serious criticism from the likes of Google, OpenAi etc.?
    I don’t know whom you mean with „EU technocrats“, but for sure we did not see China uncritically. In fact, in the past we were cautious mostly about Chinese influence, but nowadays turn towards getting more independent from the US too.

  71. cananon Says:

    @ Georg #70

    At the risk of stating the obvious: 1) your concern is shared by almost every democratic country on Earth 2)
    if Europe’s elites were truly in love with China’s dictatorship, they wouldn’t keep equipping their armies with American weapons rather than Chinese ones.

    A few small tips to help read this non sense: when they say “objective point of view”, think the median Trumpist sense of reality. When they say “truth”, think social media. And relax. Midterms are coming! Six months and one great recession later, and you might never need them again. 🙂

  72. OhMyGoodness Says:

    Georg #70

    If you question the difference between the US and China with respect to governance then I don’t believe there is anything I can add to make the contrasts visible to you. An Uyghur would be better equipped to do so than myself. When I see photos of the Foxconn suicide nets I think how kind to provide these in the economic pursuit of high labor productivity.

    The World Economic Forum (WEF) based in Switzerland often writes about China. In my view the WEF is representative of a large portion of EU “technocrats”. The following is a passage from a WEF associated document-

    “ Therefore, we understand that China’s role in the World Economic Forum in Davos has been pivotal in shaping global economic dynamics, as Beijing seeks to offer solutions to global challenges while emphasizing the importance of cooperation and dialogue among developing countries of the Global South and all nations, based on the principle of a shared future for humanity, to counter American hegemonic and unilateral policies around the world.”

    I included the next one just because I liked the phrasing-

    “ China is still a place where the idea of a machine improving the world has not yet curdled into cynicism”

    The US aid to Ukraine is nearly $200 billion and $400 million of it this year so yeah the US is clearly the EU bad guy.

    The UN votes by the EU member nations have not been supportive of Israel in the wake of October 7th nor have the members been supportive of US and Israel operations in Iran.

  73. OhMyGoodness Says:

    cananon #71

    Your implied characterization of me is laughable and results, I guess, from common simplistic dichotomous thought.

    I made an additional post that didn’t appear noting that Trump’s comment about Iranian pipelines blowing up from internal overpressure due to the blockade of Kharg Island was complete nonsense. I lamented that these nonsensical ideas are able to travel freely from his brain to his mouth.

    There is an objective reality that is not contingent on Democratic or Republican talking points but is seemingly less real for many people than those talking points.

  74. SB Says:

    William Gasarch #66:

    The graph on https://sam-jaques.appspot.com/quantum_landscape shows multiple RSA key sizes and if you scroll from its 2021 version to its 2026 version, you can see how quantum computing hardware is improving in the two most important metrics.

    Another good resource is https://francoismarieleregent.xyz/awesome-quantum-computing-experiments/#qubit-count-evolution

  75. OhMyGoodness Says:

    My personal position is that if forced to choose between support for the EU or support for Israel without doubt I choose Israel. I expect this is contrary to the choice the US Left would make and so on that point more MAGA than not. On the other hand I support abortion so more US Left than MAGA. Nuance is such a terrible thing for ideologues. It is just too messy and too darn complicated.

  76. Illusory Factoid Says:

    OhMyGoodness

    what if you were “forced to choose” between supporting Brazil or Thailand?

    or between any pair of countries for that matter – maybe create an Excel spreadsheet with each possible combination so everyone reading this blog knows exactly where you stand 😀

  77. Tom Says:

    OhMyGoodness #72

    “The World Economic Forum (WEF) based in Switzerland often writes about China.”

    I’m not sure if you are trolling here, but just to state the obvious: Switzerland is not part of the EU. I would guess one reason why WEF is _not_ based in the EU is that it wants to avoid oversight by EU technocrats.

  78. Michel Says:

    Scott #9:

    I expect that around the time quantum computers factorize 2048 bit integers, we also have an algorithm – probably by one of your old students – that puts factorization in P, by means of unquantisizing Shor. No, I am not really joking.

  79. OhMyGoodness Says:

    IF #76

    Thanks for the suggestion but Israel and EU were the only pair I wanted to force rank.

    Tom #77

    The founder of WEF was Swiss, perhaps that’s the reason.

    I doubt von der Leyen and Virkunnen were actually working oversight undercover last year. In fact von der Leyen was formerly on the Board of Trustees for WEF

    https://europeannewsroom.com/agenda/world-economic-forums-inaugural-meeting-of-leaders-for-european-growth-and-competitiveness/

  80. Jeff Says:

    Imho you guys should not help save bitcoin from future QCs, because it’s better for everyone if bitcoin acts like a honey pot for future quantum computers.

    Instead, the kinda shitty e2ee messengers that appeal to bitcoiners by using secp256k1 should enable whatever deniability or similar features, specifically so that they can provide cover for a future NSA employee who claims some cipertext requires decryption, but really extracts a major bitcoin key from the decryption.

    We’ve good reasons to believe bitcoin should die before quantum computers arise anyways, but that’s a good thing, so let’s not help motivate them into doing changes. lol

    https://economics.princeton.edu/working-papers/on-the-instability-of-bitcoin-without-the-block-reward/

    There are interesting & fun post-quantum cryptography problems for the more interesting decentralized protocols, including some non-proof-of-work crypto-currencies, like post-quantum VRFs and post-quantum blind signatures, so folks should focus upon those problem instead of bitcoin.

  81. Jacob Oertel Says:

    I think several distinct questions are getting collapsed.

    The US, China, and Russia are not equivalent governance systems. Speech, courts, elections, dissent, leaks, journalism, civil society, and public contestation matter. But “not equivalent” does not imply “therefore Europe should accept unlimited dependence on US political moods, US security guarantees, or US-based frontier tech firms.” Comparative trust is not total dependency.

    The free-speech point cuts both ways. America’s unusually strong speech protections are a civilizational asset and also an attack surface: foreign influence operations can exploit open discourse through false personas, narrative laundering, selective amplification, and obscured attribution. The cure cannot be viewpoint policing; it has to be provenance, attribution, transparency, public literacy, and actor-focused counterintelligence.

    The same distinction matters for the Iran framing some commenters have raised and for Scott’s QC warning. A real threat does not make every response structurally equivalent. Targeted counterproliferation, regime-change war, defensive migration, verification, and resilience-building are different operations. Threat legitimacy does not erase operation-type distinctions.

    So, for post-quantum crypto: assume adversaries will harvest now and decrypt later; harden accordingly; and don’t let “we have to race” silently discharge the harder questions about coordination, migration, verification, and downstream control.

  82. Georg Says:

    OhMyGoodness #72:

    Oh yes, here come the EU antisemitism accusations. Without any connection to the discussion thread at hand, and without any differentiated basis.

  83. Georg Says:

    „But “not equivalent” does not imply “therefore Europe should accept unlimited dependence on US political moods, US security guarantees, or US-based frontier tech firms.” „

    Exactly, thanks!

  84. OhMyGoodness Says:

    Georg #82

    Sorry but my post #72 included no accusations but simply reference to facts and in particular the voting record of the EU members in the UN since the October 7th event.

    Georg #83

    The EU is certainly free to pursue whatever course it wishes and so should be no problem for an observer to acknowledge the direction of choice.

  85. arch1 Says:

    Jacob #81: Thanks for your observations which I think make a lot of sense.

  86. Shtetl-Optimized » Blog Archive » Held Prize call for nominations (+ call for postdocs) Says:

    […] Here at the National Academy of Sciences, it seems that my first job is to serve on the selection committee for the prestigious Michael and Sheila Held Prize in combinatorial and discrete optimization and related areas. The committee chair, my former MIT colleague Madhu Sudan (now at Harvard), invited me to share the following message here on Shtetl-Optimized. (I’d add: put in the effort to nominate someone, and you can actually influence how things go!) […]

Leave a Reply

You can use rich HTML in comments! You can also use basic TeX, by enclosing it within $$ $$ for displayed equations or \( \) for inline equations.

Comment Policies:

After two decades of mostly-open comments, in July 2024 Shtetl-Optimized transitioned to the following policy:

All comments are treated, by default, as personal missives to me, Scott Aaronson---with no expectation either that they'll appear on the blog or that I'll reply to them.

At my leisure and discretion, and in consultation with the Shtetl-Optimized Committee of Guardians, I'll put on the blog a curated selection of comments that I judge to be particularly interesting or to move the topic forward, and I'll do my best to answer those. But it will be more like Letters to the Editor. Anyone who feels unjustly censored is welcome to the rest of the Internet.

To the many who've asked me for this over the years, you're welcome!