this post was submitted on 02 Aug 2026
3 points (53.2% liked)

Showerthoughts

44010 readers
1084 users here now

A "Showerthought" is a simple term used to describe the thoughts that pop into your head while you're doing everyday things like taking a shower, driving, or just daydreaming. The most popular seem to be lighthearted clever little truths, hidden in daily life.

Here are some examples to inspire your own showerthoughts:

Rules

  1. All posts must be showerthoughts
  2. The entire showerthought must be in the title
  3. No politics
    • If your topic is in a grey area, please phrase it to emphasize the fascinating aspects, not the dramatic aspects. You can do this by avoiding overly politicized terms such as "capitalism" and "communism". If you must make comparisons, you can say something is different without saying something is better/worse.
    • A good place for politics is c/politicaldiscussion
  4. Posts must be original/unique
  5. Adhere to Lemmy's Code of Conduct and the TOS

If you made it this far, showerthoughts is accepting new mods. This community is generally tame so its not a lot of work, but having a few more mods would help reports get addressed a little sooner.

Whats it like to be a mod? Reports just show up as messages in your Lemmy inbox, and if a different mod has already addressed the report, the message goes away and you never worry about it.

founded 3 years ago
MODERATORS
 

The whole promise is that reversible computation is theoretically free (in quantum information theory) , quantum computer can exploit it by using quantum superposition to brute force 256bit key (and larger) in a single computation cycle.

There's a massive fundamental flaw in the reasoning behind this.

It's the second law of thermodynamics - entropy always increases. While computation is free, reversal of entropy isn't. What we're being promised is a 21st century version of perpetual motion machine.

Additional explanation:

Think about private key as low entropy, and public key as high entropy. Owner of the private key has cheat code in the form of missing information which allows reversing the entropy of public key.

However in order to break the cryptography you have to reverse public key back into private key without having access to it. The regualr way is to search for flaws in the cryptography scheme that allow reasoning about missing information and consecutively - private key recovery.

But if you do a brute force attack you are 100% forced to pay full thermodynamical price of reversing the entropy. And 2^256 is way, way more than you could ever afford. Even Planck scale values multiplied by that number grow into universe size and beyond.

In summary, quantum computing can skip time component of brute forcing a key, but it can't skip the energy costs. So it will never happen.

all 43 comments
sorted by: hot top controversial new old
[–] surewhynotlem@lemmy.world 35 points 2 months ago (2 children)

Your analogy is wrong.

Here's a silly example to highlight why.

Let's both stand together on the equator. You walk forward all the way around the earth and stop five feet behind me. You claim that it'll take me just as much energy to meet you there. But it doesn't, I just turn around and walk five feet.

Quantum computers, when when brute forcing, do it differently. They take a different path. That's why they're so much better at it.

[–] Strider@lemmy.world 1 points 2 months ago

I am also a sceptic if everything will turn out as currently expected but since I have absolutely no clue regarding quantum things (OK not none, but not nearly enough) I am really excited how everything will turn out.

[–] kbal@fedia.io 14 points 2 months ago (1 children)

For most of us, thinking random thoughts about it while in the shower is probably not the most effective way to gain an understanding of the mathematical details of quantum mechanics.

[–] BlackLaZoR@lemmy.world -3 points 2 months ago (1 children)

I'm not interested in detail. The question is: Is my claim about thermodynamics valid. If it is, the inner workings of quantum computing are irrelevant.

[–] Pelicanen@fedia.io 6 points 2 months ago

Is your reasoning really "I'm not interested in understanding how it works, I'm just interested in being told I'm right"?

There are tons of videos explaining how quantum computing can breach traditional encryption, and there are a bunch of videos explaining how to make encryption that can't easily be breached by quantum computing.

[–] minty@aussie.zone 12 points 2 months ago* (last edited 2 months ago) (3 children)

With regards to extracting the private key from the public key, to my knowledge there is shors algorithm that runs in polynomial time on a quantum computer that solves integer factorisation.

Solve integer factorisation in P and you break RSA in P. I believe there are similar P algorithms that run on quantum computers for the discrete logarithm problem and elliptic curve discrete logarithm problem.

In this sense, if you scale quantum computers resources enough you break modern asymmetric cryptography.

With regards to breaking AES: Quantum computers halve the security. So 256 bit security goes to 128 bits. Still secure.

AES 128 goes to 64 bits of security. Hmmm maybe not secure anymore. Have a read of post quantum cryptography and shors algorithm to see what im on about

EDIT: added important details

Edit 2: so so many typos

[–] BlackLaZoR@lemmy.world 2 points 2 months ago (1 children)

there is shors algorithm that runs in polynomial time on a quantum computer

I'm not claiming you can't do it faster. I'm claiming it's impossible to skip the related fundamental energy requirements.

[–] minty@aussie.zone 7 points 2 months ago (1 children)

Energy requirements scale exponentially on a polynomial time algorithm? That doesnt make sense. I admit however I have only studied quantum computers in relation to what they can do, not how. But I hope what I am saying makes sense.

[–] BlackLaZoR@lemmy.world -4 points 2 months ago (1 children)

I admit however I have only studied quantum computers in relation to what they can do, not how

I'm not an expert in quantum computing. The whole point of this thought experiment is to skip all all the mechanics and make an argument based on general fundamental thermodynamic limitations.

[–] Natanael@infosec.pub 4 points 2 months ago

Thermodynamics is derived from quantum physics. Quantum computing is derived from quantum physics. They are not bypassing the thermodynamic limitations. Instead the problems the researchers keep running into are related to noise.

[–] minty@aussie.zone 1 points 2 months ago

Not a physisct, so I dont known how much scaling of quantum computers can actually be done

[–] Natanael@infosec.pub 1 points 2 months ago

https://thequantuminsider.com/2026/04/21/cryptologist-finds-aes-128-likely-safe-from-quantum-attack/

That's different reasons why we should switch (larger blocks means better randomized modes), but quantum computers still needs to much energy and too much time to attack AES128 with Grover's algorithm

[–] maxwellfire@lemmy.world 4 points 2 months ago* (last edited 2 months ago) (1 children)

I think you're almost right about the high level principles, you've just forgotten that entropy scales as the log of the combinations not linearly.

So the entropy of a 128 bit key is not 2^128, it's just 128 and therefore the fundamental limit on the cost required to recover it that you're talking about is very small.

See landauer limit (which isn't quite the same thing since it's about irreversible computers which some quantum computers might not be, but gets at the idea of there being an energy cost to have information)

I believe the specifics of your thoughts about entropy of public vs private keys is also incorrect but not necessary to the core of what you're saying.

[–] Natanael@infosec.pub 1 points 2 months ago (1 children)

Keep in mind that the Landauer limit applies to the number of operations (specifically number of overwrites), not key size, and if you have no attack which is more efficient than bruteforce then bruteforce itself is directly limited by key size.

That is, for AES128 it actually is 2^128 that sets the energy limit. For algorithms like RSA the limit is below their key size, for RSA2048 it is somewhere above 2^128 at the last estimate because of attack algorithms like sieves. Assuming classical attack algorithms.

[–] maxwellfire@lemmy.world 1 points 2 months ago

I agree, I was trying to respond without getting too much in the weeds. The argument being made was that the entropy (information content) of the key itself is the problem. I was saying that isn't true because entropy is defined differently.

But there is a lower bound for any algorithm who's output produces something with a certain amount of information, and that's the information->energy cost of that output. The specifics of the algorithm being irrelevant. I believe even with something like thermodynamically reversible computing you still pay the cost at the end for storing your result? (Which gets into one of the most mind blowing things I remember from stat mech about Szilard engines. Essentially that if I know the microstate of a system [or even a macrostate I believe?] I can slowly burn that information to extract energy from the system equal to the information I had)

You're right that in the classical case with irreversible computation you can argue that there's a thermodynamic impossibility to the brute forcing based on the Landauer limit.

[–] BCsven@lemmy.ca 4 points 2 months ago (1 children)

The quantum vs current computing thermal needs are not linked directly to entropy. For current cryptography, solving faster is more energy by its linear relation nature, quantum is in parallel. It is possible quantum computing could be less wasteful in the future, but currently quantum computing is highly inefficient thermally.

And current computing can solve for the private key, just take a few days of heavy computing

[–] Natanael@infosec.pub 1 points 2 months ago (1 children)

a few days

A few trillion days lmao

[–] BCsven@lemmy.ca 1 points 2 months ago* (last edited 2 months ago) (1 children)

Nope. Current encryption. I'm not saying it computes the key backwards, but it somehow finds flaws or patterns that let's it make an accurate guesee.

Feed the public key samples into the llm, let it crunch, it will figure out the private keyi.

The more public samples you have the faster it finds the pattern between them.

HAWK 256 that was supposed to be post quantum has already been broken by CLAUDE https://www.anthropic.com/research/discovering-cryptographic-weaknesses

[–] Natanael@infosec.pub 1 points 2 months ago* (last edited 2 months ago)

That's a few weak asymmetric algorithms. Symmetric algorithms are absolutely out of reach. And I don't see advances against McEliece which had stood since the 80's.

[–] Onomatopoeia@lemmy.cafe 4 points 2 months ago

It's relatively easy for modern consumer desktop hardware to crack old encryption in reasonable timeframes.

Time - that's the limiter. How long you're willing to wait for a solution.

If quantum computing can apply orders of magnitude greater performance than current systems, the same increase in cracking applies.

Not all encryption is equally complex - it's all about how long it takes. The end.

[–] Assassassin@lemmy.dbzer0.com 3 points 2 months ago (1 children)

If your assertion were true, why would there be thousands of mathematicians focusing on building quantum safe encryption algorithms? You understand this situation better than scores of PhDs?

[–] BlackLaZoR@lemmy.world 0 points 2 months ago (1 children)

Good question. I have no answer to that. Maybe someone points a flaw in my reasoning...

[–] Assassassin@lemmy.dbzer0.com 3 points 2 months ago (1 children)

The flaw in your reasoning is that you're running under the assumption that quantum cracking uses the same amount of energy as conventional and that you have a higher level of understanding than people that are working on this professionally.

You're acting like you have some gotcha argument against billions of dollars of investment and a huge amount of institutional knowledge. If the problem was as simple as you're trying to make it, what would be the point of pouring so much time, money, and energy into developing quantum cryptography?

[–] cockmushroom@reddthat.com -3 points 2 months ago (1 children)

So, youhave nothing? Honestly disappointed.

[–] Assassassin@lemmy.dbzer0.com 1 points 2 months ago

Hey man, don't just jump in and try to capitalize off that guys hard earned trolling. That's fucked up

[–] theneverfox@pawb.social 1 points 2 months ago

I think there's a misunderstanding of the math going on here. A key is lower entropy than random noise, but it's not what crypto works on - it's about computation

You're not pulling order out of the ether, you're calculating a solution to a math problem. Normally, it's an n-p complete problem, meaning it's just difficult to calculate conventionally. It'll take n amount of computation cycles, meaning with a large amount of computing power you can break a key in x time, and there's no known short cuts

Unless there is a short cut - some key methods have been defeated through math, making them trivial to solve. Others have been defeated through increase in computing power, meaning longer key lengths are necessary

In the same way, some key methods are theoretically trivial for quantum computing to solve, while others are quantum resistant

It's all math at the end of the day

[–] Return_of_Chippy@lemmy.world 1 points 2 months ago (1 children)

Have you considered control, alt and delete?

[–] _deleted_@aussie.zone 1 points 2 months ago (1 children)

How often has that successfully broken cryptography for you?

[–] Return_of_Chippy@lemmy.world 1 points 2 months ago

Literally every time

[–] PiraHxCx@lemmy.dbzer0.com 1 points 2 months ago (2 children)

Probably a really dumb question, but... it's been decades since plenty of sites and programs started blocking you for x amount of time if you enter the wrong password x amount of times... isn't there any security like that against brute-forcing passwords on servers or whatever the brute force runs against?

[–] jacksilver@lemmy.world 3 points 2 months ago

In most cases the real risk is someone getting access or intercepting the encrypted data. If they have the raw data, there aren't any other protections in place to prevent brute force attacks.

Similarly, that's why groups like the FBI will clone devices (like phones) to bypass brute force protections.

[–] BlackLaZoR@lemmy.world 2 points 2 months ago

When your data is secured by password, the security is only as good as that password. And people are notoriously bad at making strong passwords

[–] Sauvandu60@lemmy.ml 1 points 2 months ago

We don't have quantum computer that can do amazing things yet.

[–] waldfee@feddit.org 1 points 2 months ago (1 children)

Since quantum computers are using superconductiv materials, do their computations actually consume energy? Obviously their refrigeration uses a bunch of power, but not the chips themselves I think

[–] Natanael@infosec.pub 2 points 2 months ago

The setup and readout and reset process necessarily takes energy. And the cooling takes energy. And the post processing of the measured states takes energy. And because it's probabilistic you need to perform validation and re-run until you get a useful answer.