Remix.run Logo
plopilop a day ago

There has been a lot of new stuff over the last few years.

For instance, breaking RSA or ECDSA is requiring much fewer logical qubits than previously thought, and thus fewer physical qubits as well. Progress in error codes, quantum processing etc. made it that in 2019, it was estimated we needed ~20 million noisy qubits to factor RSA 2048. In 2025, we know we need fewer than 1 million. [0]. Some other papers even claim the need of 1000 physical qubits but they rely on a very exotic architecture so I would not consider them feasible.

Progress on the hardware is also continuing, see [1]. Researchers managed to have functional-ish error correction for the first time last year, and experts in the topic are confident that a cryptographically relevant computer will appear in around 15 years.

I personally am less optimistic than the experts (admittedly I am not an expert either), but there is enough activity to get worried for critical infrastructure.

Regarding the factoring issue, as you point out factoring 15 and factoring 21 are two very different tasks. The first one can be used to show that your quantum computer is indeed doing quantum computation; the second will prove that you have a functional error correcting code. If you can factor 21, it is probably only a matter of months/maybe a few years until you factor RSA 2048. As Scott Aaronson said [3], "Once you understand quantum fault-tolerance, asking “so when are you going to factor 35 with Shor’s algorithm?” becomes sort of like asking the Manhattan Project physicists in 1943, “so when are you going to produce at least a small nuclear explosion?”"

[0] https://arxiv.org/abs/2505.15917

[1] https://sam-jaques.appspot.com/quantum_landscape

[2] https://globalriskinstitute.org/publication/quantum-threat-t...

[3] https://scottaaronson.blog/?p=9665#comment-2029013