TENTANG EPISODE INI
One of the most prolific and influential cryptographers in the world, it’s difficult to fully quantify the impact that Dan Boneh has had on Bitcoin and digital assets more broadly.
Through both his own research and his mentorship of some of the space’s most important contributors — e.g. Andrew Poelstra, Benedikt Bunz and Robin Linus — few people have done more to shape the cryptographic foundations underlying modern blockchains and digital finance.
More recently, Dan co-authored Google’s widely discussed paper, “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities,” which reduced prior estimates of the resources required to run Shor’s algorithm against the elliptic-curve cryptography used by Bitcoin.
The paper reignited debate around quantum computing timelines and the long-term security assumptions behind modern cryptocurrencies.
In this episode of Bitcoin Rails, Dan and I discuss the current state of quantum computing, its potential implications for Bitcoin, and how he believes the Bitcoin community should think about preparing for a post-quantum future over the coming decade and beyond.
And yes, Dan shares his take on the “when quantum” question in the interview, among other key perspectives.
This episode of Bitcoin Rails is brought to you by my NEW sponsors:
LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on Sui Network — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity
BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TAMPILKAN CATATAN 🔗
TRANSKRIP 🔗
00:00:00,000 --> 00:00:07,620
If you try to aggressively move to a post-quantum architecture, like for example by 2029, I think that would be a mistake for the blockchain.
2
00:00:07,840 --> 00:00:08,940
I think we need to take our time.
3
00:00:09,100 --> 00:00:19,320
And the reason is that a hasty transition to post-quantum, in my mind, is more likely to cause a catastrophic bug than will be attacked by a quantum computer.
4
00:00:20,040 --> 00:00:21,280
Dan, welcome.
5
00:00:21,820 --> 00:00:22,260
Thank you.
6
00:00:22,400 --> 00:00:23,920
Thank you so much for being here.
7
00:00:24,000 --> 00:00:26,140
This is such a treat to have you here.
8
00:00:26,200 --> 00:00:27,720
You don't do interviews very often.
9
00:00:27,720 --> 00:00:30,460
Likewise. I'm looking forward to the next hour.
10
00:00:30,460 --> 00:00:44,640
It's going to be very exciting. You are, of course, one of the most prolific and influential cryptographers in the world, not just in kind of the blockchain space, which we'll be focusing on today, but just industry sector wide.
11
00:00:44,640 --> 00:00:47,180
So I'm very honored to have you here.
12
00:00:48,120 --> 00:00:50,680
And you are also co-author of the Google paper,
13
00:00:51,520 --> 00:00:56,220
Re-Securing Elliptic Curve Cryptography from Advancements in Quantum Computers,
14
00:00:56,240 --> 00:01:00,680
which I think we'll probably spend a good portion of this interview drilling down into.
15
00:01:00,840 --> 00:01:02,700
So I'm very excited to get your thoughts.
16
00:01:02,780 --> 00:01:08,420
And I think it's been well over a year since you did an interview on that topic in particular.
17
00:01:08,580 --> 00:01:13,700
And my understanding is that your thoughts have changed and evolved since then.
18
00:01:13,700 --> 00:01:15,000
Indeed, lots to say about that.
19
00:01:15,220 --> 00:01:36,540
Lots to say about that. So we will get into it. I'd love to just start because I ask everyone this question. This is one of my common early interview questions. If you would share a little bit just to kind of, again, kind of contextualize you in this space, share a little bit about your history and specifically kind of the Bitcoin blockchain world. How did you get into Bitcoin? How did this sort of come up for you?
20
00:01:36,540 --> 00:02:01,420
Sure. Let's see. Maybe I'll just take one second to say how I got into cryptography in general. So, you know, I guess when I was growing up, I fell in love with computers at a pretty young age. I also love math, math competitions and all that. And when I took a cryptography course in college, I realized, oh, my God, I can have my love of computers and love of number theory and algebra kind of combined into cryptography.
21
00:02:01,420 --> 00:02:03,880
and that was very clear after I took that course.
22
00:02:03,940 --> 00:02:06,880
It was clear this is what I want to do for the rest of my life
23
00:02:06,880 --> 00:02:09,460
and that's what I studied in my PhD
24
00:02:09,460 --> 00:02:12,300
and that's what I did after graduating
25
00:02:12,300 --> 00:02:14,800
and becoming a professor at Stanford.
26
00:02:15,820 --> 00:02:17,520
So cryptography is kind of my passion.
27
00:02:17,720 --> 00:02:21,760
That's kind of all I work on and it's such an amazing field.
28
00:02:22,180 --> 00:02:25,600
There's like constantly, constantly new problems to think about,
29
00:02:25,600 --> 00:02:27,000
new application areas.
30
00:02:27,000 --> 00:02:34,400
it's just an incredible field that combines both deep mathematics and practice. So what can you ask
31
00:02:34,400 --> 00:02:40,000
more from a research area? And then the way I got into blockchains and Bitcoin in particular,
32
00:02:40,500 --> 00:02:46,000
I have to say, like everything else, I got into it through my students. So what happened is my
33
00:02:46,000 --> 00:02:51,880
students started asking me, this Bitcoin thing came out. What is that? Can you explain that to us?
34
00:02:52,660 --> 00:02:55,660
So, you know, I went and looked at what Bitcoin is.
35
00:02:55,840 --> 00:02:59,700
And then I said, ah, you know, this is just another digital payment system.
36
00:03:00,120 --> 00:03:02,120
We've seen digital payment systems before.
37
00:03:02,280 --> 00:03:03,940
They kind of never took off.
38
00:03:04,380 --> 00:03:06,220
You know, they've been around for quite a while.
39
00:03:07,400 --> 00:03:08,720
So let's wait and see.
40
00:03:09,380 --> 00:03:12,180
And so initially, to be honest, I kind of ignored it.
41
00:03:13,160 --> 00:03:15,420
But then, of course, it started growing.
42
00:03:15,420 --> 00:03:18,340
And then more and more students started asking me, what is this Bitcoin?
43
00:03:18,540 --> 00:03:19,900
Is this going to change the world?
44
00:03:19,900 --> 00:03:22,900
And this was actually, by the way, fairly early on.
45
00:03:23,240 --> 00:03:24,560
Yeah, when was this about?
46
00:03:24,760 --> 00:03:26,040
Like, what's like the timeline here?
47
00:03:26,580 --> 00:03:31,480
I don't remember exactly, but it seems like maybe 2012, 13.
48
00:03:31,680 --> 00:03:32,800
Okay, so pretty early.
49
00:03:33,120 --> 00:03:34,240
Around that era.
50
00:03:35,240 --> 00:03:35,420
Yeah.
51
00:03:36,060 --> 00:03:44,240
And so, yeah, so then I have to say, I kind of started looking more deeply into what it's about.
52
00:03:45,140 --> 00:03:47,520
You know, it turned out to be pretty interesting, actually.
53
00:03:47,520 --> 00:03:52,140
Once you start to dig into it, there's a lot going on and really interesting technical questions.
54
00:03:53,340 --> 00:03:59,520
And the thing that really hooked me is we wrote some papers about cryptography for Bitcoin.
55
00:04:00,020 --> 00:04:10,040
And one of the things that really kind of drew me into the space is the fact that we wrote a paper and within six months, a blockchain actually deployed it.
56
00:04:10,340 --> 00:04:14,120
And that is something that simply does not happen on the Internet.
57
00:04:14,120 --> 00:04:27,720
You know, it is so difficult to get new crypto systems adopted on the Internet, whereas in the blockchain space, people are hungry for new ideas and they're very, very excited to actually go and experiment and deploy new ideas.
58
00:04:27,860 --> 00:04:29,540
And the minute that happened, I was hooked.
59
00:04:29,900 --> 00:04:32,200
Like that, that to me was like a transition.
60
00:04:32,320 --> 00:04:33,920
I said, my God, this is such a cool space.
61
00:04:34,100 --> 00:04:41,200
And I kind of switched all my research to basically doing what I call cryptography for blockchains.
62
00:04:41,200 --> 00:04:51,020
And I'll say over the years, it has turned out remarkable that the blockchain just keeps on generating new beautiful questions in cryptography.
63
00:04:51,560 --> 00:04:55,540
Yeah. So we're always kind of as cryptographers, we're always looking for new research challenges.
64
00:04:56,320 --> 00:05:00,320
And the blockchain just provides it's like, you know, a kid in a toy store.
65
00:05:00,320 --> 00:05:14,100
There's like so many interesting cryptography, basic cryptography questions that the blockchain brings out that it'll just keep us busy as researchers for many, many years to come. And that's why I love the space so much.
66
00:05:14,100 --> 00:05:33,780
Would you say that it's fair? I mean, is it a fair assumption to say that you really became kind of like seriously hooked by this when there started to become all of these new blockchains developed post Bitcoin, right? Because Bitcoin's cryptography is sort of relatively, I don't want to use the word straightforward, but it certainly doesn't change much.
67
00:05:33,780 --> 00:05:45,260
Would you say that that's, I mean, is that a fair assumption that like kind of once these other blockchains, once sort of Ethereum and all of these other chains came about, you kind of had more to grip into on the crypto side?
68
00:05:45,260 --> 00:05:47,600
Well, first of all, I want to push back on your premise.
69
00:05:47,840 --> 00:05:51,280
Bitcoin itself is super interesting from a cryptography point of view.
70
00:05:51,440 --> 00:05:57,520
I think, in fact, one of my earlier papers, this was with Joe Bonneau and Benedict Bunz, was on proof of solvency.
71
00:05:57,880 --> 00:06:01,000
How do you prove in zero knowledge that an exchange is solvent?
72
00:06:01,180 --> 00:06:02,660
That's a purely Bitcoin question.
73
00:06:02,900 --> 00:06:03,240
Interesting.
74
00:06:03,240 --> 00:06:07,780
And it turns out, you know, you have to develop new zero knowledge mechanisms to do all that.
75
00:06:08,220 --> 00:06:10,740
That's a Bitcoin motivated question.
76
00:06:11,300 --> 00:06:21,560
Even within Bitcoin, how to do, you know, what's now called as MPCs, protecting secret keys by splitting them up, either for ECDCA or for Schnorr.
77
00:06:21,660 --> 00:06:25,080
Those are fantastic, interesting questions to think about.
78
00:06:25,240 --> 00:06:30,360
And so even within Bitcoin, there's still lots and lots of interesting cryptography questions to think about.
79
00:06:30,360 --> 00:06:47,660
Now, it is true that one of the strengths of Bitcoin is that it doesn't change, right? And other blockchains are kind of more amenable to change. And in fact, yes, other blockchains like Ethereum, Solana, and so on, have actually raised more interesting problems for cryptographers to work on.
80
00:06:47,660 --> 00:07:08,180
So I, you know, I view myself as I just love technical challenges. I'm neutral about the blockchains. I love technical challenges. And so any blockchain that has an interesting cryptography problem, please come talk to me because that's what I love to work on. And my group, we're kind of here for you.
81
00:07:08,180 --> 00:07:26,360
You originally, I mean, I think many people view you like kind of your influence starting with the co-creation of pairing-based cryptography specifically, which has just, you know, enormous implications for, again, various blockchain-related applications, including just the development of zero-knowledge proofs.
82
00:07:26,360 --> 00:07:30,440
Generally, most snarks use pairing-based cryptography.
83
00:07:31,400 --> 00:07:40,060
I'm wondering, what were the primary applications for pairing-based cryptography before blockchains and Bitcoin and zero-knowledge proofs came to be?
84
00:07:40,200 --> 00:07:42,900
What were you working on pre-Bitcoin and blockchains?
85
00:07:43,740 --> 00:07:45,100
Oh, I see. Yes, yes, of course.
86
00:07:45,460 --> 00:07:50,140
So pairing-based cryptography, that was developed long before the blockchain came about.
87
00:07:50,140 --> 00:08:08,760
But the reason I loved it so much is because all of a sudden there's this new algebraic tool called a pairing that was developed for some very deep questions in algebraic geometry that has nothing to do with cryptography or, to be honest, nothing to do with the real world.
88
00:08:08,760 --> 00:08:11,760
It's like very beautiful mathematical questions.
89
00:08:12,180 --> 00:08:15,180
And as a result, these pairings had to be developed.
90
00:08:15,500 --> 00:08:19,760
And then it turned out that all of a sudden pairings are useful for building cryptosystems.
91
00:08:20,140 --> 00:08:42,300
Yeah. But were they not super useful before that? I mean, it's like they were super useful. Oh, yeah, they were. They had like true applications before. Yeah, yeah, yeah. In fact, one of the very first papers we wrote on pairings was to solve this longstanding open problem called identity based encryption, which is a particular form of encryption. And then things kind of took off from there.
92
00:08:42,300 --> 00:08:49,320
Then we came up with the BLS signature and the fact that it's aggregatable, which is something that we haven't seen from a signature scheme before.
93
00:08:49,840 --> 00:08:57,880
So all of a sudden, pairings enabled like a whole new generation of crypto systems that had properties that we never had before.
94
00:08:58,560 --> 00:09:06,160
So in some sense, when we were forced to just use RSA and discrete log systems, there's only so much we can do.
95
00:09:06,160 --> 00:09:11,720
all of a sudden this tool fell on us from the sky that enabled us to do so many new things that we
96
00:09:11,720 --> 00:09:16,880
simply couldn't do before. And that, I would say, that kind of ushered in a golden age in the,
97
00:09:17,100 --> 00:09:21,840
this was like in the early 2000s, kind of the first and second decade of the 2000s,
98
00:09:22,160 --> 00:09:26,680
that basically all of a sudden let us build crypto systems that we couldn't even dream
99
00:09:26,680 --> 00:09:33,440
of building before, that had properties that were both efficient and kind of, they sounded like they
100
00:09:33,440 --> 00:09:38,280
couldn't be done any other way. And so that was kind of the remarkable thing about pairings.
101
00:09:39,100 --> 00:09:43,440
I should say that this is why, again, the field of cryptography is so exciting. Every time a new
102
00:09:43,440 --> 00:09:49,560
tool comes along, we use it to build new things. So another tool that came along, I guess, also
103
00:09:49,560 --> 00:09:55,000
kind of mid-2000s is this tool called lattices in cryptography. And lattices all of a sudden
104
00:09:55,000 --> 00:09:59,700
enable us to do a bunch of other stuff. So in particular, the most exciting thing we can do
105
00:09:59,700 --> 00:10:04,480
from lattices is something that was developed by one of my former students, Craig Gentry,
106
00:10:04,840 --> 00:10:09,880
called fully homomorphic encryption, which was an age-old problem in cryptography that we couldn't
107
00:10:09,880 --> 00:10:13,940
solve. And all of a sudden, using this new tool, we could build fully homomorphic encryption.
108
00:10:14,620 --> 00:10:20,340
And I think this is never going to end. Every time a new tool comes from algebra or mathematics,
109
00:10:20,620 --> 00:10:25,420
we're able to use it to build new cryptosystems that we couldn't build before. Maybe I'll just
110
00:10:25,420 --> 00:10:31,100
say here, since I can't skip over this, in that one of the big open problems that we're facing
111
00:10:31,100 --> 00:10:35,480
today that actually Bitcoiners need as well is what's called cryptographic obfuscation.
112
00:10:36,060 --> 00:10:41,260
Yeah. So there's sometimes related problems to that are called witness encryption or
113
00:10:41,260 --> 00:10:45,040
functional encryption. These are kind of all problems that are related to one another in
114
00:10:45,040 --> 00:10:51,320
one way or another. The best constructions we have for that today are not, let's say,
115
00:10:51,320 --> 00:10:56,200
practical. Yeah. They're inefficient. And so we're kind of waiting. We're in a waiting pattern.
116
00:10:56,460 --> 00:11:01,420
Clearly, the tools we have today are not powerful enough to build efficient obfuscation,
117
00:11:01,900 --> 00:11:06,060
efficient witness encryption, efficient functional encryption for general functionalities. We're
118
00:11:06,060 --> 00:11:10,060
kind of waiting for a new tool to appear that would let us solve these things much more
119
00:11:10,060 --> 00:11:13,840
efficiently. And this is why the space is so efficient. So exciting, right? I mean,
120
00:11:14,240 --> 00:11:20,000
you know, all it takes is some new tool that falls on us from algebraic geometry and poof,
121
00:11:20,000 --> 00:11:23,160
all of a sudden we'd be able to do things that we haven't been able to do before.
122
00:11:24,080 --> 00:11:26,960
Well, it's certainly interesting that you bring up lattice-based cryptography
123
00:11:26,960 --> 00:11:31,480
because I think we're going to be getting a lot deeper into lattice in a few moments,
124
00:11:31,640 --> 00:11:34,640
very relevant for the quantum conversation in particular.
125
00:11:36,360 --> 00:11:41,720
Lattices are, of course, generally considered quantum-resistant broadly, or it just depends.
126
00:11:42,060 --> 00:11:42,980
Believed to be quantum-resistant.
127
00:11:43,240 --> 00:11:44,260
Believed to be quantum-resistant.
128
00:11:44,860 --> 00:11:48,400
Before we kind of dive deeper into the quantum question, and speaking of history,
129
00:11:48,400 --> 00:11:53,500
You also mentioned, I mean, you've been in this space long enough to remember when Shores was developed.
130
00:11:54,860 --> 00:12:00,940
Shores, of course, being the algorithm that could potentially break elliptic curve cryptography, the signatures that protect Bitcoin private keys.
131
00:12:01,520 --> 00:12:04,180
Can you share a little bit about that and what that moment was like?
132
00:12:04,280 --> 00:12:06,160
Oh, yeah. Oh, my God. That was an exciting time.
133
00:12:06,700 --> 00:12:10,980
So, yeah, Peter Shores' paper came out back in 1994.
134
00:12:12,280 --> 00:12:14,400
It was a beautiful work.
135
00:12:14,400 --> 00:12:18,860
So at the time, actually, maybe I could go back one step further.
136
00:12:19,100 --> 00:12:24,580
So you probably know the original idea for quantum computers is attributed to Richard Feynman.
137
00:12:24,920 --> 00:12:31,680
So Feynman, what he realized is that when you try to simulate a quantum experiment on a classical computer, it's really slow.
138
00:12:31,800 --> 00:12:32,460
It's really hard.
139
00:12:32,940 --> 00:12:33,040
Yeah.
140
00:12:33,200 --> 00:12:43,880
And so he had this observation or this insight that maybe a quantum experiment can perform a computation that's really hard for a classical computer.
141
00:12:43,880 --> 00:12:48,160
That's why we're having so much trouble simulating these things on a classical computer.
142
00:12:48,820 --> 00:12:50,120
And so, boy, was he right.
143
00:12:50,440 --> 00:12:50,540
Yeah.
144
00:12:50,900 --> 00:12:52,680
So it took some time.
145
00:12:53,100 --> 00:12:59,860
But people, first of all, defined what does it mean to what is a quantum computation look like?
146
00:12:59,960 --> 00:13:01,840
And so this that model has been defined.
147
00:13:01,960 --> 00:13:09,880
It's now called, you know, BQB, basically effectively, you know, quantum polynomial time.
148
00:13:12,040 --> 00:13:12,480
Yeah.
149
00:13:12,480 --> 00:13:19,460
Yeah. And so we have an understanding of what is a quantum algorithm actually look like.
150
00:13:19,920 --> 00:13:23,400
And then the next question is, well, what can we use it for?
151
00:13:23,820 --> 00:13:27,980
And so there was some initial ideas for what can we use a quantum algorithm for.
152
00:13:27,980 --> 00:13:31,280
And I have to say that there have been a couple of insights there.
153
00:13:31,480 --> 00:13:36,900
But to keep the story short, I can say that kind of Shor's algorithm came as a bombshell to say,
154
00:13:36,900 --> 00:13:42,360
wait a minute, this new model that you guys just defined enables us to do something that we don't
155
00:13:42,360 --> 00:13:48,140
think is possible on a classical computer, namely factor large integers and compute discrete log in
156
00:13:48,140 --> 00:13:55,120
an arbitrary group. Any group, we can break discrete log. The paper itself was really quite
157
00:13:55,120 --> 00:13:58,880
pretty. I think I'd like to talk a little bit about the mechanics of Shor's algorithm
158
00:13:58,880 --> 00:14:05,700
in just a second. So the paper itself is quite pretty. It came out, I guess I was really excited
159
00:14:05,700 --> 00:14:10,460
about that. I actually wrote some papers myself right after trying to generalize the algorithm
160
00:14:10,460 --> 00:14:15,800
right after it came out. And so maybe I can tell you a little bit of my personal
161
00:14:15,800 --> 00:14:21,680
view of quantum computing. So initially, I was very excited. It seems like the reality is,
162
00:14:21,680 --> 00:14:25,200
if you believe the axioms of the postulates of quantum mechanics,
163
00:14:25,580 --> 00:14:31,400
then quantum computation is possible. It's just an engineering problem, just an engineering problem
164
00:14:31,400 --> 00:14:33,140
of building a quantum computer.
165
00:14:34,040 --> 00:14:35,140
So I was quite excited.
166
00:14:35,280 --> 00:14:37,960
Actually, like I said, I even wrote some papers shortly after.
167
00:14:38,140 --> 00:14:40,360
This was when, just again, to contextualize the time,
168
00:14:40,420 --> 00:14:42,380
because there's been this sort of evolution of thought here.
169
00:14:42,560 --> 00:14:43,080
So like when...
170
00:14:43,080 --> 00:14:45,220
Yeah, this was like mid-1990s.
171
00:14:45,300 --> 00:14:45,680
Oh, okay.
172
00:14:45,940 --> 00:14:47,480
Yeah, so fairly early on then.
173
00:14:47,560 --> 00:14:47,820
Okay.
174
00:14:48,280 --> 00:14:51,100
And these were the early rumblings of quantum computers
175
00:14:51,100 --> 00:14:53,980
even potentially being something we could build.
176
00:14:54,260 --> 00:14:55,620
Exactly, exactly, exactly.
177
00:14:56,420 --> 00:14:59,340
Yeah, and then I have to say,
178
00:14:59,340 --> 00:15:01,520
there was like an explosion in quantum algorithms
179
00:15:01,520 --> 00:15:04,240
of various things we can do with a quantum computer.
180
00:15:04,340 --> 00:15:05,860
In fact, there's a beautiful site.
181
00:15:06,280 --> 00:15:07,620
It's called the Quantum Algorithm Zoo.
182
00:15:08,220 --> 00:15:09,460
You guys can Google it.
183
00:15:09,900 --> 00:15:12,340
And there's like a list of all the beautiful quantum algorithms
184
00:15:12,340 --> 00:15:13,140
that have been developed.
185
00:15:13,740 --> 00:15:15,300
It's really quite an active area.
186
00:15:15,440 --> 00:15:18,120
There's whole conferences devoted to quantum algorithms.
187
00:15:18,240 --> 00:15:21,260
So there's a lot we can do beyond factoring and discrete log,
188
00:15:21,700 --> 00:15:23,120
mostly algebraic questions.
189
00:15:23,660 --> 00:15:25,560
But yes, there are quite a few problems
190
00:15:25,560 --> 00:15:27,860
that we can solve using a quantum computer.
191
00:15:28,380 --> 00:15:29,800
But then the question is, can we build it?
192
00:15:30,480 --> 00:15:32,840
And so initially, the physicists,
193
00:15:33,060 --> 00:15:34,520
so now the problem is on the physicists,
194
00:15:34,740 --> 00:15:35,740
not the computer scientists.
195
00:15:36,360 --> 00:15:38,140
So initially, kind of the attempts
196
00:15:38,140 --> 00:15:39,080
to build a quantum computer
197
00:15:39,080 --> 00:15:40,640
were these NMR techniques.
198
00:15:40,880 --> 00:15:43,660
And these NMR techniques were pretty clear
199
00:15:43,660 --> 00:15:44,680
they're not going to scale.
200
00:15:45,060 --> 00:15:46,680
But that was kind of the methods
201
00:15:46,680 --> 00:15:49,500
that people were quoting for quite a while.
202
00:15:49,720 --> 00:15:50,940
And that was a little disappointing
203
00:15:50,940 --> 00:15:53,320
because that's clearly not going to get us
204
00:15:53,320 --> 00:15:54,160
to where we need to go.
205
00:15:54,700 --> 00:15:56,160
So in some sense,
206
00:15:56,160 --> 00:16:03,940
But I kind of got a little bit, you know, just an engineering problem is maybe a harder problem than we thought.
207
00:16:04,040 --> 00:16:11,200
I kind of used to say to myself, oh, my God, I wish I would flip on the TV and the Star Trek episode would come on screen.
208
00:16:11,860 --> 00:16:17,520
And, you know, Spock would say, we intercepted an encrypted message from the 20th century, but that's OK.
209
00:16:17,660 --> 00:16:19,400
We have a quantum computer. We can break it.
210
00:16:19,400 --> 00:16:24,380
Yeah. So that in a sense, quantum computers would only be built in Star Trek times.
211
00:16:24,380 --> 00:16:29,260
Yeah. Because of just engineering problems seems to be really hard.
212
00:16:29,420 --> 00:16:34,040
So that was kind of the feeling that the field is not making progress.
213
00:16:34,200 --> 00:16:35,400
But then a couple of things changed.
214
00:16:36,280 --> 00:16:52,900
OK. I was just going to ask you, how bullish are you that these kind of theoretical advancements will actually translate into real practical hardware able running of shores?
215
00:16:52,900 --> 00:17:11,000
Yeah, yeah, yeah. No, of course, that's a great question. So like I said, there's kind of two big ideas that came about, physical ideas, that kind of changed the development of space. So one is what are called superconducting qubits. And so, you know, the groups at IBM, at Google, at Rigetti, and some other companies are kind of…
216
00:17:11,000 --> 00:17:13,840
These are kind of like, this is like the most promising…
217
00:17:13,840 --> 00:17:14,200
Directions.
218
00:17:14,480 --> 00:17:15,460
Style, right. Okay.
219
00:17:15,460 --> 00:17:18,360
Yeah, there's a couple of directions maybe that I won't...
220
00:17:18,360 --> 00:17:20,620
There's a couple of avenues that people are exploring.
221
00:17:21,100 --> 00:17:23,920
The ones that seem the most advanced
222
00:17:23,920 --> 00:17:26,580
are basically the superconducting qubits methods.
223
00:17:26,780 --> 00:17:28,860
This is basically using VLSI techniques.
224
00:17:29,420 --> 00:17:32,900
I'll say that those experiments are not that easy to build,
225
00:17:33,020 --> 00:17:36,540
which is why it takes IBM and Google and well-funded startups
226
00:17:36,540 --> 00:17:40,660
because you have to cool everything down to almost absolute zero.
227
00:17:40,660 --> 00:17:42,660
So these experiments, you probably see no...
228
00:17:42,660 --> 00:17:44,280
Remember these pictures of a quantum computer?
229
00:17:44,280 --> 00:17:46,340
They're all running inside of these big fridges.
230
00:17:46,820 --> 00:17:48,160
Everything has to be cooled down.
231
00:17:48,240 --> 00:17:50,600
So they're kind of expensive experiments to do.
232
00:17:50,620 --> 00:17:52,500
How long do you think it takes to build?
233
00:17:52,680 --> 00:18:00,020
Like, let's just say that, like, in theory, we figured out, you know, just like on paper, we know how to get to breaking a 256-bit elliptic curve.
234
00:18:00,200 --> 00:18:04,880
How long would it take to then build something that could potentially run shores?
235
00:18:05,660 --> 00:18:06,280
Yeah, OK.
236
00:18:06,360 --> 00:18:08,060
Actually, you know, that's a great question.
237
00:18:08,340 --> 00:18:12,300
But let me finish the story and then we can talk about timelines.
238
00:18:12,300 --> 00:18:12,540
OK.
239
00:18:12,900 --> 00:18:13,780
Fair, fair.
240
00:18:13,780 --> 00:18:14,840
Those are very relevant.
241
00:18:15,440 --> 00:18:19,020
So one approach that seems very promising is the superconducting qubits.
242
00:18:19,620 --> 00:18:24,600
But these are experiments that are kind of, there's a lot of hardware involved in doing the experiments.
243
00:18:25,300 --> 00:18:34,600
Meaning, and the implication of that is that, you know, there's kind of advancements theoretically that just then can't be proven physically because it's so difficult to build these things in practice.
244
00:18:34,680 --> 00:18:36,340
You can't test things in the physical real world.
245
00:18:36,340 --> 00:18:36,860
No, you can.
246
00:18:36,940 --> 00:18:37,160
You can.
247
00:18:37,280 --> 00:18:38,980
And there have been many tests, actually.
248
00:18:39,040 --> 00:18:39,740
But it's difficult.
249
00:18:39,940 --> 00:18:41,640
It's, like, challenging to do this.
250
00:18:41,640 --> 00:18:45,420
Yeah, the apparatus is, it takes some work to build the apparatus.
251
00:18:46,060 --> 00:18:49,060
The other direction, by the way, these are all physical experiments that have been done.
252
00:18:49,240 --> 00:18:53,840
The other direction that's very promising is what are called neutral atoms.
253
00:18:54,980 --> 00:19:00,140
So there, that technique is much easier for people to experiment with.
254
00:19:00,140 --> 00:19:05,560
And in fact, there's an explosion of startups actually building quantum computers using neutral atoms.
255
00:19:06,800 --> 00:19:07,580
And they're easier to build?
256
00:19:07,760 --> 00:19:10,260
Like it's easier to build computers using neutral atoms?
257
00:19:10,260 --> 00:19:13,860
I'll talk about the distinction between the two and just more distinctions between the two in a second.
258
00:19:13,940 --> 00:19:20,800
But I can tell you, maybe as a mental model, actually, let me explain how a neutral atom computer works.
259
00:19:21,500 --> 00:19:23,780
I'll definitely be imprecise.
260
00:19:24,180 --> 00:19:26,460
And what I'll say is not quite correct.
261
00:19:26,860 --> 00:19:31,580
But I think it's a good mental model for how to think about a neutral atom computer.
262
00:19:32,620 --> 00:19:39,680
And so the way it works is basically you have this one laser that basically creates these traps.
263
00:19:39,680 --> 00:19:47,460
So you take one laser, you split it up into 10,000, 50,000 beams, which is technology that exists today.
264
00:19:47,580 --> 00:19:52,120
For example, LiDAR in cars, they have one laser that gets split up into a lot of beams.
265
00:19:52,200 --> 00:19:59,880
So that's basically mostly dealing with optical hardware, which you can just buy the optical hardware that does all that.
266
00:19:59,980 --> 00:20:01,960
So you have a laser, you have some optical hardware.
267
00:20:01,980 --> 00:20:03,840
So those are cheaper than the…
268
00:20:03,840 --> 00:20:05,480
Yeah, there are companies that will just sell it to you.
269
00:20:05,480 --> 00:20:11,800
And then using those isolated beams, you can build what are called traps.
270
00:20:11,980 --> 00:20:15,460
So you can kind of trap the atom where it is.
271
00:20:15,500 --> 00:20:18,000
So you can build using one laser beam, splitting it up.
272
00:20:18,340 --> 00:20:21,080
You can build 3,000, 10,000.
273
00:20:21,540 --> 00:20:22,700
There was even some discussion.
274
00:20:22,900 --> 00:20:26,700
I saw one paper, one experiment that actually hasn't been done yet
275
00:20:26,700 --> 00:20:30,120
that claims to go even above 100,000 traps.
276
00:20:30,120 --> 00:20:36,720
and so potentially you can have a large number of atoms trapped in under this uh under this laser
277
00:20:36,720 --> 00:20:42,680
beam uh and then uh so they're just sitting there yeah they're they're they're the the beam traps
278
00:20:42,680 --> 00:20:55,798
them cools them down so they just sitting them sitting there um so that kind of what we call the memory zone of the computer and then when you want to act on these atoms so this is part of the step of a quantum computer you have to kind of implement what called a quantum gate
279
00:20:55,858 --> 00:21:01,138
So you can take two neutral atoms, bring them into the entanglement zone.
280
00:21:01,138 --> 00:21:08,878
So just like you have the trap that's holding them fixed, you can also move those atoms to bring them together into the entanglement zone.
281
00:21:09,238 --> 00:21:14,698
Have them, there's another laser that shines on them that causes them to get entangled.
282
00:21:14,998 --> 00:21:17,018
And then you take them back and bring them back to memory.
283
00:21:17,118 --> 00:21:21,178
And you pick the next two, you bring them to the entanglement zone, entangle them, and you move them back.
284
00:21:21,258 --> 00:21:25,338
And in fact, you can even do this on groups of atoms as an optimization.
285
00:21:26,058 --> 00:21:29,418
So again, this is not precisely how this works, but it's a good way to think about this.
286
00:21:29,418 --> 00:21:35,358
So you have memory, you have effectively a CPU that's kind of operating the way to operate on these bits.
287
00:21:35,398 --> 00:21:43,038
And then once you're ready to measure, you can actually bring these atoms into a measurement zone and look at them and sort of measure and get the result out.
288
00:21:43,038 --> 00:21:47,198
So this is sometimes called a three-zone architecture for a neutral atom computer.
289
00:21:47,578 --> 00:21:51,638
Turns out there's a fourth zone because all this is happening in a vacuum chamber.
290
00:21:52,138 --> 00:21:53,518
So you have to build a good vacuum chamber.
291
00:21:53,598 --> 00:21:55,678
That's kind of one expensive piece you have to do.
292
00:21:55,738 --> 00:21:57,418
But a vacuum chamber is not completely empty.
293
00:21:57,858 --> 00:22:05,238
So sometimes you have an atom that's roaming around that hits your trap and knocks the atom that's in the trap out of the trap.
294
00:22:05,658 --> 00:22:11,098
So you kind of, these traps, you lose atoms in the trap once in a while.
295
00:22:11,098 --> 00:22:14,438
So there's another zone that's used to replenish atoms into the trap.
296
00:22:14,618 --> 00:22:14,718
Yeah.
297
00:22:14,938 --> 00:22:20,098
And these styles of quantum computers, the sort of builds of quantum computers,
298
00:22:20,258 --> 00:22:22,798
these have been in development for many, many years.
299
00:22:23,378 --> 00:22:24,338
Not that many years, actually.
300
00:22:24,898 --> 00:22:30,698
So, you know, neutral atoms, I guess they're about a decade old.
301
00:22:30,978 --> 00:22:31,218
Okay.
302
00:22:31,278 --> 00:22:35,758
But the actual experiments, you know, if you look at the exciting experiments,
303
00:22:36,198 --> 00:22:37,798
they're just in the last two, three years.
304
00:22:38,038 --> 00:22:38,318
Okay.
305
00:22:38,318 --> 00:22:41,178
So this is like a relatively new development.
306
00:22:41,658 --> 00:22:48,598
Okay. So you would say in the last two or three years, that's when your maybe previous skepticism started to be turned?
307
00:22:48,758 --> 00:22:49,518
I mean, is that fair?
308
00:22:49,638 --> 00:22:55,038
Yeah, yeah, yeah. So maybe it's worthwhile also saying, maybe we're going too much into the physics here, but maybe I'll just say one more thing.
309
00:22:55,478 --> 00:22:59,598
So we have these two approaches, superconducting qubits, neutral atom approaches.
310
00:22:59,598 --> 00:23:03,758
There are other approaches like ion traps and photonics that I won't talk about here.
311
00:23:03,758 --> 00:23:08,678
but there's kind of core differences between them.
312
00:23:09,238 --> 00:23:11,098
In superconducting qubits, the bits don't move.
313
00:23:11,598 --> 00:23:14,198
Because of that, they can only talk to their direct neighbors.
314
00:23:14,758 --> 00:23:17,378
So the connectivity graph is not very big.
315
00:23:17,478 --> 00:23:19,278
Basically, you can only talk to your neighbors
316
00:23:19,278 --> 00:23:23,478
and that limits the type of computations you can do.
317
00:23:23,858 --> 00:23:25,898
However, superconducting qubits, because of this,
318
00:23:26,038 --> 00:23:26,938
they're quite fast.
319
00:23:27,378 --> 00:23:31,578
You can implement a gate in about 10 microseconds.
320
00:23:32,278 --> 00:23:33,598
Yeah, 10 microseconds, yeah.
321
00:23:33,758 --> 00:23:39,158
With the neutral atoms, because you have to move things back and forth, things actually are slower.
322
00:23:39,158 --> 00:23:41,898
So there you can implement a gate in about 10 milliseconds.
323
00:23:42,358 --> 00:23:45,238
So it's about 100 to 1,000 times slower.
324
00:23:45,978 --> 00:23:47,798
Yeah, so superconducting, remember, is fast.
325
00:23:48,178 --> 00:23:49,278
Neutral atoms is slow.
326
00:23:50,138 --> 00:23:51,598
Superconducting, limited connectivity.
327
00:23:52,178 --> 00:23:54,038
Neutral atoms, arbitrary connectivity.
328
00:23:54,258 --> 00:23:55,998
So you can implement computation more efficiently.
329
00:23:56,438 --> 00:23:58,258
Those are kind of the tradeoffs.
330
00:23:58,378 --> 00:24:03,318
I think everything I say here, by the way, is greatly simplified and not entirely accurate.
331
00:24:03,318 --> 00:24:07,258
But I think as a mental model, this is the good mental models.
332
00:24:07,378 --> 00:24:10,138
This is a good way to think about these architectures.
333
00:24:10,298 --> 00:24:15,718
Is one or the other just simply just, you know, like from a net perspective, more promising?
334
00:24:15,938 --> 00:24:16,118
Yes.
335
00:24:16,418 --> 00:24:16,678
Okay.
336
00:24:16,958 --> 00:24:23,418
So now it's looking like the neutral atom approach actually might be the one to scale first.
337
00:24:23,538 --> 00:24:24,218
Which is new.
338
00:24:24,638 --> 00:24:25,158
Which is new.
339
00:24:25,378 --> 00:24:26,498
Which was not previously believed.
340
00:24:26,498 --> 00:24:26,858
Yeah.
341
00:24:27,538 --> 00:24:33,158
And I can say we can even see that just about, what is it, three or four weeks ago, Google made an announcement.
342
00:24:33,158 --> 00:24:37,258
And Google is very heavily invested in the superconducting approach.
343
00:24:37,738 --> 00:24:45,558
And just three or four weeks ago, they said that they're now going to continue with the superconducting effort, but they're going to start a new effort on neutral atoms.
344
00:24:46,318 --> 00:24:51,398
So you take that as sort of like a low-key endorsement of the neutral atoms perspective.
345
00:24:51,398 --> 00:24:54,738
Yeah, so they hired a bunch of people to now work on neutral atoms.
346
00:24:54,918 --> 00:24:57,178
And so they're going to pursue both approaches in parallel.
347
00:24:57,178 --> 00:25:03,638
well. But also, yeah, so the neutral atoms approach, A, because it's simpler, simpler to build.
348
00:25:04,398 --> 00:25:08,358
There are more companies, more groups actually doing it. In fact, there's a new lab at Stanford
349
00:25:08,358 --> 00:25:13,458
that's actually building a neutral atom computer, which I'm pretty excited about. So it's just to
350
00:25:13,458 --> 00:25:19,998
show you that academics is simple enough to actually labs and universities can get involved
351
00:25:19,998 --> 00:25:24,658
and build these experiments. And is it these sort of like physics related advancements that you
352
00:25:24,658 --> 00:25:29,818
are kind of, that kind of, again, kind of tipped you more into the conservative, we should get
353
00:25:29,818 --> 00:25:39,398
prepped for this mode? Yeah, you know, it's interesting. So when should we worry about
354
00:25:39,398 --> 00:25:45,218
quantum? I'm a little surprised. It's a very divisive topic, very divisive in the community.
355
00:25:45,218 --> 00:25:50,738
Well, the implications are pretty significant. It's true. Yeah. So I'll say there's, I would
356
00:25:50,738 --> 00:25:56,078
say kind of things fall into two groups, right? So there's one group of people that says, you know,
357
00:25:56,178 --> 00:26:03,038
it's plausible that we'll have a working computer before 2035, let's say. Yeah. To be to be generous.
358
00:26:04,258 --> 00:26:08,538
Which you previously I have heard you on record saying that you thought it was like probably
359
00:26:08,538 --> 00:26:12,678
pretty a year ago. I think you said on a podcast you thought it was unrealistic that we would have
360
00:26:12,678 --> 00:26:17,938
a working a cryptographically relevant quantum computer for before 2035. Do you still feel that
361
00:26:17,938 --> 00:26:22,558
way? Honestly, when you look at the number of challenges that remain to be solved to scale
362
00:26:22,558 --> 00:26:27,358
these computers, I still think it's going to take a fair number of years. Well beyond 2035.
363
00:26:27,558 --> 00:26:32,878
I don't know if well beyond, but... But you think you would put the over-under on 2035 at like...
364
00:26:32,878 --> 00:26:39,458
So let's just say there is one group that's really... Their point is, some people say even
365
00:26:39,458 --> 00:26:45,058
it's potentially possible, maybe unlikely, but potentially possible that one will be built even
366
00:26:45,058 --> 00:26:45,898
by the end of the decade.
367
00:26:46,038 --> 00:26:48,398
That seems to be very aggressive to me.
368
00:26:49,498 --> 00:26:51,298
I think it's one of these things
369
00:26:51,298 --> 00:26:52,378
that might be possible
370
00:26:52,378 --> 00:26:55,758
if this became like a Manhattan-sized project, right?
371
00:26:56,558 --> 00:26:58,898
You know, when the Apollo program was running,
372
00:26:59,298 --> 00:27:01,458
you know, the moonshot was happening,
373
00:27:01,598 --> 00:27:03,658
that was like 2% to 3% of the U.S. GDP.
374
00:27:03,958 --> 00:27:05,938
Right. I think you described it in a previous interview
375
00:27:05,938 --> 00:27:08,918
as a national priority versus a business interest.
376
00:27:09,178 --> 00:27:09,658
Yes, exactly. Exactly, exactly.
377
00:27:09,658 --> 00:27:11,758
If it becomes a national priority,
378
00:27:11,998 --> 00:27:14,518
then we're all activated to solve this.
379
00:27:14,518 --> 00:27:19,798
If humanity is devoted to building a quantum computer, then maybe we can get it done.
380
00:27:19,938 --> 00:27:21,478
Just lots of hurdles to solve.
381
00:27:22,118 --> 00:27:26,118
You know, maybe we can get it done sooner than what one might expect.
382
00:27:26,678 --> 00:27:27,618
But that's not happening.
383
00:27:28,138 --> 00:27:28,238
Yeah.
384
00:27:28,358 --> 00:27:32,738
Right now, it is basically VC-funded efforts.
385
00:27:33,198 --> 00:27:37,418
Startups that are running towards this, I guess Google and IBM are running towards this.
386
00:27:37,498 --> 00:27:40,198
The Google and IBM groups are not huge.
387
00:27:40,358 --> 00:27:43,298
It's not a huge investment that Google and IBM are making.
388
00:27:43,298 --> 00:27:46,658
It's still like billions of dollars, though. I mean, it's significant.
389
00:27:47,238 --> 00:27:55,358
There are definitely investing, but it's not like, let's say, Google is investing in AI and Google investing in quantum.
390
00:27:55,738 --> 00:27:56,278
Totally different.
391
00:27:56,578 --> 00:27:57,318
Totally different scales.
392
00:27:57,398 --> 00:27:57,658
Right, right.
393
00:27:57,678 --> 00:27:58,418
Completely different scales.
394
00:27:58,478 --> 00:27:58,678
Fair.
395
00:27:58,918 --> 00:28:00,038
Not even in the same ballpark.
396
00:28:00,158 --> 00:28:00,598
Right, right, right.
397
00:28:00,898 --> 00:28:06,458
You know, if Google put the efforts that they're putting into AI into building quantum, we would be having a very different conversation.
398
00:28:06,478 --> 00:28:07,258
We'd be more scared.
399
00:28:07,518 --> 00:28:08,758
Yeah, we'd be having a different conversation.
400
00:28:09,198 --> 00:28:14,378
So the question is, at the current level of funding, how long do we think it's going to take?
401
00:28:14,878 --> 00:28:15,758
Again, nobody knows.
402
00:28:15,758 --> 00:28:29,058
I can tell you that from speaking to the physicists and kind of reading the physics papers on this stuff, there are a lot of technical challenges that have to be solved to scale superconducting qubits and neutral atoms.
403
00:28:29,178 --> 00:28:29,718
We're not there.
404
00:28:30,178 --> 00:28:30,278
Yeah.
405
00:28:30,458 --> 00:28:31,758
There are a lot of technical challenges.
406
00:28:32,218 --> 00:28:34,698
The main one or one, well, there's many.
407
00:28:35,218 --> 00:28:37,538
One of the issues that you always have to harp on,
408
00:28:37,578 --> 00:28:39,558
it's always about the quantum error correcting code.
409
00:28:39,958 --> 00:28:41,378
How complicated is it to run,
410
00:28:41,478 --> 00:28:43,218
to implement the quantum error correcting code?
411
00:28:44,098 --> 00:28:46,978
And we'll talk more about that in just a second.
412
00:28:47,738 --> 00:28:50,458
But given that, it seems like,
413
00:28:50,578 --> 00:28:53,578
so yeah, so it seems like anything between 2035,
414
00:28:53,718 --> 00:28:54,818
and again, this is my opinion,
415
00:28:55,398 --> 00:28:56,718
given the current level of funding,
416
00:28:58,158 --> 00:29:01,618
seems, I think, it's reasonable to assume
417
00:29:01,618 --> 00:29:03,238
that it's going to happen after 2035.
418
00:29:03,238 --> 00:29:07,698
So you would put it in the category of possible but unlikely before 2035?
419
00:29:07,858 --> 00:29:09,118
Depending on the level of investments.
420
00:29:09,118 --> 00:29:11,638
Like we should be prepared because of possibility but unlikely.
421
00:29:12,158 --> 00:29:12,838
Exactly, exactly.
422
00:29:13,358 --> 00:29:13,918
Yeah, exactly.
423
00:29:14,058 --> 00:29:21,818
So, I mean, the message I would like to get across is you don't need to panic about the effect of quantum computing.
424
00:29:22,038 --> 00:29:24,058
But at the same time, we shouldn't be ignoring it.
425
00:29:24,218 --> 00:29:28,838
And the reason we shouldn't be ignoring it is because the transition is going to be very painful.
426
00:29:28,978 --> 00:29:31,198
And we'll talk about the transition in just a little bit.
427
00:29:31,198 --> 00:29:33,218
And that transition is going to take a long time.
428
00:29:33,638 --> 00:29:37,378
And we need to start early enough to give us enough time to do it.
429
00:29:37,738 --> 00:29:42,398
We are definitely going to get into this very lengthy and probably painful transition.
430
00:29:42,558 --> 00:29:44,018
I have many, many questions about that.
431
00:29:44,198 --> 00:29:44,658
But really quickly.
432
00:29:44,858 --> 00:29:45,338
Actually, sorry.
433
00:29:45,418 --> 00:29:46,638
There's one more thing I want to say.
434
00:29:46,738 --> 00:29:47,838
There's another group.
435
00:29:48,178 --> 00:29:52,538
So there's one group that says, you know, we should be worried right now before 2035.
436
00:29:52,878 --> 00:29:53,818
And so on and so forth.
437
00:29:54,198 --> 00:29:58,178
There's another group of people that basically says, oh, this is not going to happen in our lifetime.
438
00:29:58,778 --> 00:30:00,078
This is Star Trek technology.
439
00:30:00,078 --> 00:30:19,058
We don't need to worry about this at all. You know, that seems to be also not quite the right thing to say, to be honest. And I like to kind of draw this analogy. So the analogy I would bring up is the development of human flight.
440
00:30:19,638 --> 00:30:19,778
Yeah.
441
00:30:19,978 --> 00:30:27,038
I think it's useful to remember that throughout the 1800s, people kind of knew how lift works.
442
00:30:27,478 --> 00:30:33,598
People knew that if a wing moves fast enough, you can generate enough lift to lift a human.
443
00:30:34,218 --> 00:30:38,318
So the theory of flight was kind of understood for many, many years, for many decades.
444
00:30:38,698 --> 00:30:42,018
But no, it was just an engineering problem, kind of like what we're facing now.
445
00:30:42,358 --> 00:30:46,718
In fact, there were many failed attempts at building a plane that just didn't fly.
446
00:30:46,718 --> 00:31:02,518
To the point where it's really interesting to remember, in 1903, the New York Times ran an article saying human flight, heavier than air human flight is not possible and it will not be possible for a million years.
447
00:31:02,518 --> 00:31:04,998
Yeah, there was literally an article in the New York Times.
448
00:31:05,698 --> 00:31:10,318
Ten weeks later, Kitty Hawk, the Wright brothers happened just ten weeks later.
449
00:31:10,818 --> 00:31:19,198
So I think this is and by the way, once Kitty Hawk happened and, you know, Kitty Hawk 1903, the Wright brothers, they only flew for like, what, 300 feet or so.
450
00:31:19,318 --> 00:31:20,538
There was a small flight.
451
00:31:21,058 --> 00:31:21,158
Yeah.
452
00:31:21,698 --> 00:31:24,238
Once they did that, things really took off quickly.
453
00:31:24,238 --> 00:31:24,578
Yeah.
454
00:31:24,698 --> 00:31:29,318
Like within a year or two, just a small number of years, they were already flying all over the place.
455
00:31:29,318 --> 00:31:32,578
by 1919, there was already transatlantic flights.
456
00:31:33,638 --> 00:31:36,358
So the reason I'm bringing this analogy up
457
00:31:36,358 --> 00:31:39,078
is people who say this is Star Trek technology
458
00:31:39,078 --> 00:31:41,098
just need to think a little bit
459
00:31:41,098 --> 00:31:42,678
about what happened with human flights.
460
00:31:43,158 --> 00:31:44,958
All it took is like one step,
461
00:31:45,138 --> 00:31:47,658
one physical experiment, and everything happened.
462
00:31:47,918 --> 00:31:49,018
Everything kind of took off from there.
463
00:31:49,518 --> 00:31:50,378
Personally, to me,
464
00:31:50,978 --> 00:31:53,738
I think we've already had the Kitty Hawk moment
465
00:31:53,738 --> 00:31:54,718
of quantum computing.
466
00:31:55,138 --> 00:31:57,418
And that is what's called the Willow experiment
467
00:31:57,418 --> 00:31:58,498
back in 2024.
468
00:31:59,238 --> 00:32:01,238
So Google was able to actually show
469
00:32:01,238 --> 00:32:04,078
that they can implement quantum error correcting codes
470
00:32:04,078 --> 00:32:06,078
using 105 physical qubits.
471
00:32:06,258 --> 00:32:08,378
Yeah, so they did a superconducting experiment.
472
00:32:08,738 --> 00:32:11,078
They showed that we can actually build a logical qubit
473
00:32:11,078 --> 00:32:12,998
using physical qubits,
474
00:32:13,058 --> 00:32:16,238
and they can actually run the logical qubit corrector,
475
00:32:16,378 --> 00:32:17,598
and it actually corrects the errors.
476
00:32:18,338 --> 00:32:20,138
Since then, so this was 2024.
477
00:32:20,698 --> 00:32:23,438
In June 2025, there was a paper that appeared.
478
00:32:23,438 --> 00:32:26,098
This is a paper by Dolev, who's currently at Caltech.
479
00:32:26,818 --> 00:32:31,958
They did an experiment using neutral atoms on 448 atoms, 448 atoms.
480
00:32:32,458 --> 00:32:37,398
They demonstrated that quantum error correction works, that it actually corrects errors across,
481
00:32:37,498 --> 00:32:39,658
I think they did 27 gates.
482
00:32:39,858 --> 00:32:42,238
So they were able to run a circuit of depth 27.
483
00:32:42,838 --> 00:32:44,718
Already that generates a lot of errors.
484
00:32:44,718 --> 00:32:49,018
You remember, you have to bring these atoms together, bring them back, bring more atoms
485
00:32:49,018 --> 00:32:49,658
together, bring them back.
486
00:32:49,698 --> 00:32:50,618
So you're moving them back and forth.
487
00:32:51,098 --> 00:32:52,838
So that generates a lot of errors.
488
00:32:52,838 --> 00:32:59,118
And that experiment demonstrated that error correction actually is able to correct errors in that experiment.
489
00:32:59,998 --> 00:33:02,198
So 27 gates, quantum error correction.
490
00:33:03,198 --> 00:33:05,038
That's literally June 2025.
491
00:33:05,318 --> 00:33:08,898
It's like less than a year ago that that was done.
492
00:33:09,498 --> 00:33:12,978
And so I think we're kind of at a moment now where things are going to start scaling.
493
00:33:13,378 --> 00:33:16,718
You know, human flight took off really quickly.
494
00:33:17,458 --> 00:33:19,238
Things are going to start scaling now.
495
00:33:19,238 --> 00:33:22,378
Now, that's not to say that this is happening tomorrow.
496
00:33:22,838 --> 00:33:24,398
No, this is not at all what's happening.
497
00:33:24,558 --> 00:33:26,498
There are still a lot, you have to understand,
498
00:33:26,618 --> 00:33:29,238
there's a lot of technical challenges that have to be solved
499
00:33:29,238 --> 00:33:33,598
before we can scale a quantum computer to what's needed to run shores.
500
00:33:34,798 --> 00:33:36,458
But kind of the components are there.
501
00:33:36,618 --> 00:33:37,458
The components are there.
502
00:33:37,558 --> 00:33:38,958
They're like in different papers now.
503
00:33:39,378 --> 00:33:40,238
The components are there.
504
00:33:40,338 --> 00:33:43,698
Somebody needs to bring it together and build a large enough experiment.
505
00:33:43,698 --> 00:33:47,078
And there are many startups and companies that are trying to do just that.
506
00:33:47,458 --> 00:33:51,778
Can you give some examples of the unsolved problems that you're referencing
507
00:33:51,778 --> 00:33:56,158
when you say there are many problems that need to be solved. Like, what are those specifically?
508
00:33:56,598 --> 00:34:01,318
And is there a reason to believe that those are problems that could be solved suddenly
509
00:34:01,318 --> 00:34:06,898
rather than, you know, incrementally over time? No, I'm pretty sure they will be solved
510
00:34:06,898 --> 00:34:13,398
incrementally over time. There's no sub. OK. So I would say that because that's the concern,
511
00:34:13,578 --> 00:34:18,498
right? Like, I think that there's broadly, you know, this concern that, you know, all of the
512
00:34:18,498 --> 00:34:22,598
sudden these things that are currently not possible will just like magically become possible
513
00:34:22,598 --> 00:34:26,998
and the timeline will compress, right? That's sort of like the fear narrative. And then I think like
514
00:34:26,998 --> 00:34:32,358
the opposing kind of more skeptical narrative is that, no, no, no, we're going to have tons of
515
00:34:32,358 --> 00:34:38,998
runway on this because actually it's exponentially more difficult to scale as you put more qubits
516
00:34:38,998 --> 00:34:44,598
together. And, you know, so I kind of want to drill down into that and sort of where you lie
517
00:34:44,598 --> 00:34:45,918
in that argument specifically?
518
00:34:47,058 --> 00:34:49,358
Look, the reality is we don't know.
519
00:34:49,458 --> 00:34:49,578
Yeah.
520
00:34:49,658 --> 00:34:50,458
To be realistic,
521
00:34:51,018 --> 00:34:53,498
it's possible that quantum computers
522
00:34:53,498 --> 00:34:54,998
will never be built.
523
00:34:55,458 --> 00:34:56,098
Yeah, it's possible.
524
00:34:56,178 --> 00:34:58,858
Is that possibly provable?
525
00:34:59,018 --> 00:35:00,078
Like, could something come up
526
00:35:00,078 --> 00:35:00,938
that could prove
527
00:35:00,938 --> 00:35:02,798
that this is just not physically possible?
528
00:35:02,998 --> 00:35:03,778
Or is it just...
529
00:35:03,778 --> 00:35:04,738
Yeah, of course.
530
00:35:04,918 --> 00:35:05,038
Okay.
531
00:35:05,318 --> 00:35:06,258
So, you know,
532
00:35:06,338 --> 00:35:08,278
quantum mechanics has never been tested
533
00:35:08,278 --> 00:35:09,578
at the scales that are needed
534
00:35:09,578 --> 00:35:10,418
for Shor's algorithm.
535
00:35:11,458 --> 00:35:12,038
And so, you know,
536
00:35:12,078 --> 00:35:12,818
there's a paper that,
537
00:35:12,918 --> 00:35:14,578
a physics paper that appeared last year
538
00:35:14,578 --> 00:35:18,898
I don't subscribe to that paper, but that paper says quantum mechanics is wrong.
539
00:35:19,518 --> 00:35:21,658
Is there an incentive for that?
540
00:35:21,898 --> 00:35:26,298
Is there an incentive for somebody to prove that Shores cannot be run by a quantum computer?
541
00:35:26,878 --> 00:35:28,418
Well, it could be.
542
00:35:28,558 --> 00:35:29,578
I don't think that's going to happen.
543
00:35:29,778 --> 00:35:37,978
But it could be that we try to scale up these experiments, and all of a sudden it turns out we're getting wrong results because our understanding of quantum mechanics is incorrect.
544
00:35:38,518 --> 00:35:41,178
I don't think that's going to happen because quantum mechanics, all we know is correct.
545
00:35:41,178 --> 00:35:47,538
People are spending billions of dollars trying to make sure that to make that to prove the opposite, basically.
546
00:35:47,838 --> 00:35:49,538
By the way, that's very true.
547
00:35:49,698 --> 00:35:58,878
But I would say that even, come on, even if we learn that our understanding of quantum mechanics is incorrect and there's a different physical theory of the universe, that's like a once in a century event.
548
00:35:59,138 --> 00:36:00,278
That is like Nobel Prize.
549
00:36:01,118 --> 00:36:02,558
Forget Nobel. Of course, Nobel Prize.
550
00:36:02,558 --> 00:36:08,978
But I mean, just the implication for what we can do if we have a different understanding of our universe, that would be incredible.
551
00:36:08,978 --> 00:36:11,818
Yeah. And so I think it's kind of a win-win situation.
552
00:36:11,998 --> 00:36:21,858
OK. So you don't think there's like a situation where we have like misaligned incentives where it's like, you know, there's so much money and running and potentially running shores one day, which even that I'd like to drill down into.
553
00:36:22,038 --> 00:36:25,238
Like, why are we spending all this money just to break all of our cryptography?
554
00:36:25,438 --> 00:36:27,098
Are there other reasons why we want to?
555
00:36:27,578 --> 00:36:28,718
Yeah, yeah. Maybe we should talk about that.
556
00:36:28,798 --> 00:36:36,738
Yeah. So so, yeah, I also want to go through the Google paper because there's a lot of very cool ideas in the Google paper that I want to get through.
557
00:36:37,298 --> 00:36:37,698
Yeah.
558
00:36:37,798 --> 00:36:41,618
So your question is, why build a quantum computer in the first place?
559
00:36:41,938 --> 00:36:42,078
Yeah.
560
00:36:42,718 --> 00:36:47,778
So it's kind of, I don't know, it's kind of maybe funny is not the right word, but it
561
00:36:47,778 --> 00:36:50,078
is funny that the universe is in some sense messing with us.
562
00:36:50,318 --> 00:36:50,418
Yeah.
563
00:36:50,678 --> 00:36:56,118
The universe gave us this magical ability to compute things that we can't compute classically
564
00:36:56,118 --> 00:36:57,078
using a quantum computer.
565
00:36:57,498 --> 00:36:58,738
And what is it good for?
566
00:36:59,358 --> 00:37:00,158
Causing harm.
567
00:37:00,298 --> 00:37:00,518
Right.
568
00:37:00,858 --> 00:37:01,738
Breaking cryptography.
569
00:37:02,578 --> 00:37:02,818
Right.
570
00:37:02,818 --> 00:37:04,958
So is it good for anything else?
571
00:37:04,958 --> 00:37:19,978
So first of all, I did mention the quantum zoo. There's a whole bunch of algorithms that can be run on a quantum computer. The other application people always talk about is what's called quantum simulation. And that has to do with solving problems in chemistry, computational chemistry.
572
00:37:19,978 --> 00:37:25,598
I give you a complicated molecule and I ask you, what is the shape of the molecule in the real world?
573
00:37:26,178 --> 00:37:28,338
Potentially, a quantum computer can actually compute this.
574
00:37:28,578 --> 00:37:37,958
And so, you know, we would potentially have the ability to build, to calculate what materials look like without having to do expensive experiments, physical experiments.
575
00:37:38,118 --> 00:37:45,658
Yeah, that is that's an area that, you know, we'll see whether that actually works out.
576
00:37:46,218 --> 00:37:50,038
But that's a potential other application area for quantum computers.
577
00:37:50,698 --> 00:37:55,838
Right now, the most compelling application, sadly, is breaking cryptography.
578
00:37:56,078 --> 00:37:59,238
But you're asking why are people investing so much money in building it?
579
00:37:59,778 --> 00:38:04,498
I think it's this grander vision that we'll demonstrate that it works by breaking cryptography,
580
00:38:04,718 --> 00:38:09,078
but then there'll be other applications that people come up with.
581
00:38:09,078 --> 00:38:13,398
It's also one of these things that, you know, once the technology—
582
00:38:13,398 --> 00:38:19,698
Today, nobody really is looking or the number of people looking for applications is not that high because the computers don't exist.
583
00:38:19,918 --> 00:38:25,178
Once the computers exist, you can imagine, oh, everybody will try to look for new applications for them.
584
00:38:25,458 --> 00:38:27,598
And, you know, human ingenuity is amazing.
585
00:38:27,878 --> 00:38:31,198
So we'll find new applications that would drive this industry.
586
00:38:31,638 --> 00:38:40,098
So the argument here is that Shores is basically like the low hanging fruit of proving that we can even use quantum computers for any like practical real world use case.
587
00:38:40,098 --> 00:38:47,638
But that ultimately, like the incentive for building these things is that potentially once we're able to do that, you know, other kind of more profitable.
588
00:38:48,118 --> 00:38:53,098
Well, I don't know, maybe breaking shores might be may be very profitable for the right or wrong person.
589
00:38:53,258 --> 00:38:53,378
Yeah.
590
00:38:54,038 --> 00:39:01,938
So shores, by the way, is a way to prove that there's a new computing ability here, that it does something that we can't do on a classical computer.
591
00:39:01,998 --> 00:39:03,498
At least we believe we can't do on a classical computer.
592
00:39:03,498 --> 00:39:06,038
Do you want to give a little TLDR on how shores works?
593
00:39:06,998 --> 00:39:07,698
Yeah, yeah, actually.
594
00:39:07,858 --> 00:39:08,878
Yeah, that would be great, actually.
595
00:39:09,378 --> 00:39:10,498
In fact, let's do this.
596
00:39:10,578 --> 00:39:12,978
Let's kind of quickly walk through the Google paper.
597
00:39:13,118 --> 00:39:14,558
I think it's a pretty interesting paper.
598
00:39:14,878 --> 00:39:18,078
It's kind of a long paper, so I'm not sure how many people have actually read it.
599
00:39:18,678 --> 00:39:21,938
So let's kind of walk through quickly what's there.
600
00:39:21,938 --> 00:39:28,458
So first of all, what is fundamentally the result in the paper is an optimization of Shor's algorithm.
601
00:39:28,998 --> 00:39:31,978
So to do that, I have to kind of briefly explain how Shor's algorithm works.
602
00:39:32,658 --> 00:39:34,178
Shor's is not a complicated algorithm.
603
00:39:34,278 --> 00:39:35,558
It's actually quite a simple algorithm.
604
00:39:35,558 --> 00:39:38,918
Let me describe it the way Shor described it.
605
00:39:38,998 --> 00:39:41,518
These days we think of it a little bit differently,
606
00:39:41,938 --> 00:39:44,278
but let me try to explain it the way Shor described it.
607
00:39:44,838 --> 00:39:47,318
So really there are four steps to Shor's algorithm.
608
00:39:47,958 --> 00:39:50,938
I'm going to say some words here that hopefully will be clear,
609
00:39:51,058 --> 00:39:56,018
but if not, please Google it or chat to PT it because it's really interesting.
610
00:39:56,798 --> 00:40:02,138
So the first step in Shor's algorithm is you take a classical state
611
00:40:02,838 --> 00:40:07,918
And what you do is you create a superposition of exponentially many states.
612
00:40:08,318 --> 00:40:14,238
The way to think about that is you literally write down a pair of numbers, x comma y,
613
00:40:14,838 --> 00:40:18,818
for all x, y, let's say between 0 and 2 to the 256.
614
00:40:19,618 --> 00:40:19,698
Yeah.
615
00:40:20,098 --> 00:40:27,118
So classically, we can not write down such a large list because it's got 2 to the 512 values in it.
616
00:40:27,218 --> 00:40:28,538
Yeah, it's two numbers.
617
00:40:28,938 --> 00:40:30,378
Each one is 256 bits.
618
00:40:30,378 --> 00:40:40,638
But the magic of quantum computing or quantum mechanics is we can create a superposition using, let's say, a thousand atoms, a thousand cubits, a thousand logical cubits.
619
00:40:40,798 --> 00:40:50,518
We can create a superposition, I'll say, using 512 logical cubits, we can create a superposition of 2 to the 512 different states.
620
00:40:51,078 --> 00:40:57,018
OK, so now we have this huge vector of pairs X comma Y for all XY.
621
00:40:57,538 --> 00:40:58,398
OK, that's the first step.
622
00:40:58,398 --> 00:41:00,278
Turns out that's a really easy step to do.
623
00:41:00,378 --> 00:41:02,698
Yeah, that uses just what are called Hadamard gates.
624
00:41:03,118 --> 00:41:04,838
That's for a computer that's easy to do.
625
00:41:05,398 --> 00:41:07,278
The next step is actually the hardest part
626
00:41:07,278 --> 00:41:07,898
of Schor's algorithm.
627
00:41:08,618 --> 00:41:11,758
Now we have to take every pair X, Y,
628
00:41:11,878 --> 00:41:14,338
and we have to apply a classical computation to it.
629
00:41:14,518 --> 00:41:16,778
Okay, so we're operating on the superposition.
630
00:41:16,958 --> 00:41:18,398
So on all pairs X, Y,
631
00:41:18,578 --> 00:41:21,498
on each pair, we apply a classical computation.
632
00:41:21,618 --> 00:41:22,238
What's the computation?
633
00:41:22,758 --> 00:41:23,918
Well, if we're trying to compute
634
00:41:23,918 --> 00:41:26,118
the discrete log of H base G,
635
00:41:26,658 --> 00:41:29,998
what we're computing is the function X times G
636
00:41:29,998 --> 00:41:46,896
plus y times h So remember we have a table of all x y we have our elliptic curve group elements g and h and then for every x we compute X times G plus Y times H Remember that formula X times G plus Y times H
637
00:41:47,216 --> 00:41:48,436
Okay, so we compute that formula.
638
00:41:49,296 --> 00:41:53,516
And that classical computation turns out to be the hardest part of Shor's algorithm.
639
00:41:54,036 --> 00:41:56,836
It's kind of funny that all the quantum things are easy.
640
00:41:57,376 --> 00:42:00,096
The classical computation is the one that's hard to do on a quantum computer.
641
00:42:00,896 --> 00:42:03,396
So now once we have done this calculation,
642
00:42:03,396 --> 00:42:09,496
Now we have a table that looks like X comma Y comma X times G plus Y times H.
643
00:42:09,896 --> 00:42:11,256
OK, we have a table of triples.
644
00:42:12,096 --> 00:42:15,476
Then now we get into something that maybe I'll just say the words.
645
00:42:15,596 --> 00:42:17,276
We do what's called a quantum Fourier transform.
646
00:42:17,976 --> 00:42:19,636
Yeah, that is not so important.
647
00:42:19,736 --> 00:42:22,936
I'll just tell you again for a quantum computer, that step is not hard.
648
00:42:23,476 --> 00:42:25,816
Yeah, so we do that and then we measure.
649
00:42:26,356 --> 00:42:30,556
We measure the result and it turns out what comes out is something called a period.
650
00:42:30,556 --> 00:42:33,216
The function I just described is a periodic function.
651
00:42:33,396 --> 00:42:36,596
What comes out is an approximate period of that function.
652
00:42:37,336 --> 00:42:39,256
And I have to say, then there's the part,
653
00:42:39,336 --> 00:42:40,476
when I saw this in Schwarz's paper,
654
00:42:40,556 --> 00:42:41,216
I got really excited
655
00:42:41,216 --> 00:42:43,456
because that's the most beautiful part of Schwarz's paper
656
00:42:43,456 --> 00:42:45,296
to show that that approximation
657
00:42:45,296 --> 00:42:47,456
is enough to compute the discrete log
658
00:42:47,456 --> 00:42:48,976
using a classical computation.
659
00:42:49,416 --> 00:42:50,256
So let's go over it again.
660
00:42:50,716 --> 00:42:52,976
So first step, you create this massive superposition.
661
00:42:53,536 --> 00:42:55,296
Then you do a classical computation,
662
00:42:55,636 --> 00:42:57,316
x times g plus y times h.
663
00:42:57,636 --> 00:42:58,956
Then you do a quantum free transform.
664
00:42:59,576 --> 00:43:00,436
Then you do a measurement.
665
00:43:00,936 --> 00:43:02,336
And then you do a classical computation
666
00:43:02,336 --> 00:43:03,516
to recover the discrete log.
667
00:43:03,976 --> 00:43:05,736
Yeah, those are the steps of Shor's algorithm.
668
00:43:05,936 --> 00:43:06,096
Okay.
669
00:43:06,456 --> 00:43:10,076
The hardest step is X times G plus Y times H,
670
00:43:10,256 --> 00:43:11,376
the classical computation.
671
00:43:11,816 --> 00:43:13,896
So you do that using a quantum circuit
672
00:43:13,896 --> 00:43:16,256
that implements that classical step.
673
00:43:17,156 --> 00:43:19,296
The innovation in Google's paper
674
00:43:19,296 --> 00:43:22,116
is basically an optimization for that step.
675
00:43:22,616 --> 00:43:25,596
Okay, so we can do the hardest part of Shor's algorithm
676
00:43:25,596 --> 00:43:28,216
faster than we thought we could do it before.
677
00:43:28,216 --> 00:43:30,176
Okay, so this is the cute optimization
678
00:43:30,176 --> 00:43:32,136
that you were referencing earlier.
679
00:43:32,336 --> 00:43:36,356
And this is, I mean, really the key breakthrough of the Google paper.
680
00:43:36,476 --> 00:43:38,916
Like this is the new thing that really happened.
681
00:43:39,256 --> 00:43:41,436
Although there are a couple of other very cute ideas in the paper.
682
00:43:41,916 --> 00:43:51,916
So one thing that happened is, so Google decided to actually not reveal the actual algorithm for computing X times G plus Y times H.
683
00:43:52,056 --> 00:43:54,276
It literally is just a quantum circuit.
684
00:43:54,616 --> 00:43:57,016
So I'll tell you, they have a quantum circuit simulator.
685
00:43:57,196 --> 00:43:57,956
It's called Kikmix.
686
00:43:57,956 --> 00:44:04,196
KickMix, you literally write down a program as a quantum circuit and KickMix will simulate it for
687
00:44:04,196 --> 00:44:08,836
you. Remember, this is a classical computation that's written using quantum gates. Yeah. So
688
00:44:08,836 --> 00:44:15,656
KickMix can just run the classic algorithm and show that it works correctly. They could have just
689
00:44:15,656 --> 00:44:21,956
showed the world what their circuit is. Yeah. But they decided to not do that. Yeah. For good reason.
690
00:44:22,976 --> 00:44:26,156
I mean, would that be not be a security vulnerability? I mean, isn't that the reason
691
00:44:26,156 --> 00:44:28,676
why they decided to use a zero-knowledge proof is they didn't?
692
00:44:28,976 --> 00:44:31,976
Personally, I wish they would have revealed the algorithm.
693
00:44:32,056 --> 00:44:33,256
I believe in open research.
694
00:44:33,396 --> 00:44:33,856
I'm an academic.
695
00:44:34,316 --> 00:44:36,536
I believe that we should share our knowledge with the world.
696
00:44:37,136 --> 00:44:40,676
Personally, I would have liked to have that released in the open.
697
00:44:41,036 --> 00:44:44,316
But let me just say that they were operating under certain constraints.
698
00:44:45,056 --> 00:44:48,276
Their only option was not to tell the world anything
699
00:44:48,276 --> 00:44:50,556
or to do a zero-knowledge proof.
700
00:44:50,556 --> 00:44:52,876
Who was enforcing these constraints?
701
00:44:52,996 --> 00:44:53,916
What constraints exactly?
702
00:44:54,176 --> 00:44:56,136
Okay, that is, I'm going to, that's actually the point.
703
00:44:56,156 --> 00:44:58,536
No, that's up to the Google people to say.
704
00:44:58,816 --> 00:44:59,056
Okay.
705
00:44:59,336 --> 00:45:05,056
But let me just say that I thought it was a pretty cool application of a zero-knowledge proof.
706
00:45:05,296 --> 00:45:11,056
What they did is they took the KickMix simulator, quantum simulator, they converted it to Rust,
707
00:45:11,336 --> 00:45:18,896
and then they ran a zero-knowledge prover to prove that their circuit actually computes point condition correctly.
708
00:45:19,276 --> 00:45:22,456
So this was a fun new application of zero-knowledge proofs on top of everything else.
709
00:45:22,456 --> 00:45:22,696
Yeah, yeah.
710
00:45:22,696 --> 00:45:23,716
That's basically what you were saying.
711
00:45:23,716 --> 00:45:25,696
It's a pretty exciting application of zero-knowledge proofs.
712
00:45:25,696 --> 00:45:29,936
You know, you prove that you have an attack without actually revealing what the attack is.
713
00:45:29,936 --> 00:45:34,736
Now, I want to walk through actually what actually is being proved in this EK proof.
714
00:45:35,376 --> 00:45:44,016
So one thing that I want to drill down a bit more is when you look at the function that needs to be computed, x times g plus y times h.
715
00:45:44,556 --> 00:45:48,096
Yeah, that you compute using what's called a repeated doubling algorithm.
716
00:45:48,736 --> 00:45:52,656
Of course, now I'm going to say a few words that hopefully your audience is familiar with.
717
00:45:52,656 --> 00:45:57,736
When you implement repeated doubling, of course, you implement this using what's called a windowing method.
718
00:45:59,076 --> 00:46:03,776
And it turns out what you would do is they chose to implement it using a 16-bit window.
719
00:46:04,536 --> 00:46:08,236
And then there's a different windowing table at every step of the algorithm.
720
00:46:08,836 --> 00:46:13,876
When you do the math, there's 512 X times G plus Y times H.
721
00:46:13,956 --> 00:46:15,236
X and Y are 256 bits.
722
00:46:15,616 --> 00:46:18,676
So there are 512 elliptic curve additions that are done naively.
723
00:46:18,676 --> 00:46:25,556
using this windowing method, it turns out you only need to do 31 additions, 31 additions. It
724
00:46:25,556 --> 00:46:32,536
turns out you can save three additions by some other tricks. And so overall, Shor's algorithm,
725
00:46:32,656 --> 00:46:36,956
it's kind of important to understand, Shor's algorithm at the end of the day just boils down
726
00:46:36,956 --> 00:46:43,676
to 28 elliptic curve additions. Yeah. The only thing the circuit needs to do is 28 elliptic curve
727
00:46:43,676 --> 00:46:50,536
additions plus some lookup tables. Yeah, that's it. 28. So what they proved is that they have
728
00:46:50,536 --> 00:46:57,216
an addition circuit that computes an elliptic curve addition using a circuit of a certain size.
729
00:46:57,516 --> 00:47:04,176
In particular, I can tell you the size that they showed is 2.7 million non-Clifford gates,
730
00:47:04,336 --> 00:47:09,236
which is what we care about. 2.7 million Toffoli gates. Yeah. So yes, so they can compute
731
00:47:09,236 --> 00:47:14,416
one elliptic curve addition using 2.7 million Toffoli gate, and they have to do that 28 times,
732
00:47:14,556 --> 00:47:20,176
which is roughly where the 90 million Toffoli gate count comes from. Okay, so the whole algorithm
733
00:47:20,176 --> 00:47:24,916
takes 90 million Toffoli gates. They proved in zero knowledge that they have a circuit that does
734
00:47:24,916 --> 00:47:31,156
it in 2.7 million Toffoli gates. I thought that once the paper is published, people are going to
735
00:47:31,156 --> 00:47:35,856
think of this as an amazing puzzle. So we know there's a circuit that implements,
736
00:47:35,856 --> 00:47:41,476
you know, there's a kick mix circuit that does curve addition using 2.7 million Toffoli gates
737
00:47:41,476 --> 00:47:46,616
because the proof is correct. We can talk about that too, too, but the proof is correct.
738
00:47:48,496 --> 00:47:54,196
And so now there's an amazing puzzle out there. Can you guys figure out what the circuit is?
739
00:47:54,696 --> 00:47:59,136
It's a pretty cool puzzle. I thought it was just a challenge that you're. Yeah. Yeah. It's a
740
00:47:59,136 --> 00:48:04,996
challenge for the research community. I thought actually it would. But by now, people have already
741
00:48:04,996 --> 00:48:11,216
figured it out. I can tell you one of my former students, Ilya, told me that he just went to
742
00:48:11,216 --> 00:48:15,236
Cloud Code and said, hey, Cloud, why don't you learn how to use KickMix? And can you come up
743
00:48:15,236 --> 00:48:20,216
with an addition circuit yourself? I think he said Cloud came up with like a circuit that was 10
744
00:48:20,216 --> 00:48:24,596
million Toffoli gates and like 5,000 physical qubits, which is much worse than the Google paper.
745
00:48:24,996 --> 00:48:29,336
But at least it gives you a scaffold. And now you can try to optimize the scaffold manually.
746
00:48:29,336 --> 00:48:33,236
Yeah. Or maybe by interacting with Cloud, you can try to optimize the scaffold.
747
00:48:34,076 --> 00:48:37,016
So, yeah, so this is a pretty cool challenge out there.
748
00:48:37,056 --> 00:48:40,776
Maybe somebody can even find a better gate, a better circuit than the Google one.
749
00:48:41,176 --> 00:48:45,456
So in the Google paper, we have this sort of optimization of shores as sort of like the key breakthrough.
750
00:48:45,636 --> 00:48:54,316
We have the zero knowledge proof application of proving the attack without revealing information about the attack, which is pretty cool and kind of potentially lends itself to this challenge.
751
00:48:54,556 --> 00:48:55,676
Hey, go figure this out.
752
00:48:56,576 --> 00:49:01,896
Anything else that's cute in the Google paper that you want to make sure we cover before we go into mitigation?
753
00:49:01,896 --> 00:49:05,976
Oh, good, good, good. Yes, yes, of course. Yes, there's a couple other very cool ideas on the paper.
754
00:49:07,056 --> 00:49:13,416
So, right. It turns out, remember when we compute a function x times g plus y times h?
755
00:49:14,916 --> 00:49:21,096
Amazingly, g in the world of ECDSA and Schnorr, g is fixed forever.
756
00:49:21,276 --> 00:49:22,976
Everybody uses the same group generator.
757
00:49:23,876 --> 00:49:26,156
H kind of depends on the user's public key.
758
00:49:26,756 --> 00:49:26,876
Yeah.
759
00:49:27,236 --> 00:49:33,256
So really half of the computation in the X times G plus Y times H can be done before
760
00:49:33,256 --> 00:49:34,936
we even know the user's public key.
761
00:49:35,736 --> 00:49:35,876
Yeah.
762
00:49:36,076 --> 00:49:37,396
So we call this priming.
763
00:49:37,596 --> 00:49:42,316
You can prime the quantum computer with X times G so that when the public key becomes
764
00:49:42,316 --> 00:49:45,856
known, all you have to do is Y times H.
765
00:49:45,856 --> 00:49:52,196
So it's a factor of two speed up in breaking a public key if you don't know the public
766
00:49:52,196 --> 00:49:53,016
key ahead of time.
767
00:49:53,016 --> 00:49:56,836
So when is there a situation where you don't know the public key out of time?
768
00:49:57,396 --> 00:50:00,116
Well, that's exactly the Bitcoin mempool, right?
769
00:50:00,336 --> 00:50:08,216
So in the Bitcoin mempool, what happens is Satoshi had this incredible idea that Bitcoin addresses are hashes of public keys.
770
00:50:08,816 --> 00:50:17,316
So when somebody wants to spend, you know, a pay to public key hash UTXO, they publish the public key as part of this transaction.
771
00:50:18,076 --> 00:50:21,396
And now the attacker has basically 10 minutes to try to do the attack.
772
00:50:21,396 --> 00:50:33,016
Okay, so that, just like if we were going to TLDR that for folks, it basically means like we now have evidence that the amount of time that it would take to execute an attack is reduced, essentially.
773
00:50:33,376 --> 00:50:34,596
Or theoretically reduced.
774
00:50:34,716 --> 00:50:39,716
Because you can prime the computer so that when the public key becomes known, you can break it twice as fast.
775
00:50:39,756 --> 00:50:48,436
Which is not relevant to the when quantum question, but is more relevant to the types of attacks that we need to be able to mitigate against in the future.
776
00:50:48,636 --> 00:50:50,076
Short exposure versus long exposure.
777
00:50:50,076 --> 00:50:50,536
Is that fair?
778
00:50:50,536 --> 00:51:12,616
Yeah, that's very fair. Yeah, I thought that was a very, very cute observation in the paper that is worth highlighting. So the reason that's important is because the superconducting qubits, remember, they are fast. Yeah, when you do the math of how long will a superconducting qubit actually take to run this optimized Shores algorithm, it turns out it's about 20 minutes. Yeah.
779
00:51:12,616 --> 00:51:17,856
But because of this factor of two optimization, you can prime the algorithm and then attack on the fly.
780
00:51:18,396 --> 00:51:19,936
The 20 minutes drops to 10 minutes.
781
00:51:20,516 --> 00:51:20,636
Yeah.
782
00:51:20,936 --> 00:51:21,596
Which is kind of interesting.
783
00:51:21,776 --> 00:51:25,076
Which is an interesting number when you're talking about mempool attacks.
784
00:51:25,236 --> 00:51:28,096
It's kind of weird that the numbers literally just line up with the Bitcoin numbers.
785
00:51:28,316 --> 00:51:30,696
That is, again, a bizarre coincidence of the universe.
786
00:51:30,916 --> 00:51:32,556
Bizarre coincidence of the universe.
787
00:51:32,716 --> 00:51:33,456
Okay, fair enough.
788
00:51:33,496 --> 00:51:36,176
On a neutral atom computer, remember things that are much slower.
789
00:51:36,676 --> 00:51:42,276
The Caltech paper estimates that on a neutral atom computer, they will need about, their estimates,
790
00:51:42,276 --> 00:51:48,556
a lot of debates on whether those estimates are aggressive or not. Their estimates are you'll need
791
00:51:48,556 --> 00:51:56,016
26,000 atoms, which is within reason, and you will need about 10 days of compute.
792
00:51:56,596 --> 00:52:00,516
Was there anything in the paper? I thought I had read something, and there were a couple people
793
00:52:00,516 --> 00:52:05,796
who suggested that the paper kind of implied that there may be sort of like a specific tipping point
794
00:52:05,796 --> 00:52:11,456
where scaling could become easier rather than exponentially more difficult, right? Like,
795
00:52:11,456 --> 00:52:20,116
I think I mentioned earlier when we were prepping that, you know, the 32-bit number isn't that much easier than breaking a 256-bit number.
796
00:52:20,116 --> 00:52:23,256
I mean, is there any reason to believe that that's true?
797
00:52:23,336 --> 00:52:33,956
Because that could be potentially an argument for, you know, the bears, the quantum bears who are saying, no, no, no, no, it's going to, you know, we're going to have tons of runway on the incremental time.
798
00:52:33,956 --> 00:52:44,796
But if it is true that it's not necessarily exponentially harder to go from breaking a 32-bit key to a 256-bit key, why is that?
799
00:52:44,896 --> 00:52:47,016
Is there evidence to support that idea?
800
00:52:47,136 --> 00:52:48,436
Or is it just who knows?
801
00:52:49,256 --> 00:52:49,416
Yeah.
802
00:52:49,516 --> 00:52:53,896
So the quantum Star Trek folks that will only be possible in Star Trek times, the quantum bears, I like the name.
803
00:52:55,016 --> 00:52:58,296
One of the arguments is, well, you have an year factor of 21, right?
804
00:52:59,036 --> 00:52:59,976
So why is that?
805
00:52:59,976 --> 00:53:13,996
So, again, I'm not sure exactly what the timelines are, but I can say factoring 21 using Shor's algorithm is a circuit that takes between 100 and 200 gates, non-Toffley gates, non-Clifford gates.
806
00:53:14,516 --> 00:53:18,256
And as a result, you already need all the quantum error correction.
807
00:53:18,416 --> 00:53:25,916
Like even just to factor 21, all the machinery that is preventing quantum computing from happening tomorrow is already needed.
808
00:53:26,396 --> 00:53:26,496
Yeah.
809
00:53:26,656 --> 00:53:26,996
I see.
810
00:53:26,996 --> 00:53:31,976
And so today, it's not clear that we can factor 21 if we want to.
811
00:53:32,536 --> 00:53:34,776
But the tools are coming together.
812
00:53:34,916 --> 00:53:41,916
As I said, quantum error correction has just been demonstrated for 448 physical qubits, 27 gates.
813
00:53:42,696 --> 00:53:48,976
So that needs to be scaled up to a couple hundred gates, and then maybe they'll be able to factor 21.
814
00:53:48,976 --> 00:53:56,736
And so my point is that it's just now that these tools are coming together.
815
00:53:57,356 --> 00:54:02,196
And so I think now actually we will start to see things moving a little bit faster than we saw before.
816
00:54:02,196 --> 00:54:19,276
So, I mean, is the kind of core argument there that there's so much that has to go into building a quantum computer that just factors 21 that once you get there, it's actually really not that much of a jump in terms of like overarching work to get to breaking 256?
817
00:54:19,856 --> 00:54:22,996
Okay, so that is an oversimplification.
818
00:54:23,336 --> 00:54:28,536
So the quantum error correcting code is going to be much harder to do for a large scale computation.
819
00:54:29,056 --> 00:54:29,916
It's very interesting, by the way.
820
00:54:30,056 --> 00:54:32,116
Exponentially harder as you increase.
821
00:54:32,196 --> 00:54:34,996
Not exponential is a mathematical term, not exponentially.
822
00:54:35,136 --> 00:54:35,656
Okay, no.
823
00:54:36,136 --> 00:54:37,456
Harder, not exponentially harder.
824
00:54:37,616 --> 00:54:38,536
Not exponentially harder.
825
00:54:38,656 --> 00:54:39,056
Yeah, yeah.
826
00:54:39,076 --> 00:54:41,956
Some people do say that, but maybe they're just, that's what I want to clarify.
827
00:54:42,176 --> 00:54:42,776
Yeah, yeah, yeah.
828
00:54:42,816 --> 00:54:43,396
It is harder.
829
00:54:43,576 --> 00:54:49,836
But I wish we had more time because there's so much I want to say in that one of the bottlenecks,
830
00:54:49,876 --> 00:54:54,016
it's interesting, one of the bottlenecks of a quantum computation is the classical work
831
00:54:54,016 --> 00:54:56,736
that needs to be done to run the error correcting code.
832
00:54:57,296 --> 00:54:57,496
Yeah.
833
00:54:57,596 --> 00:55:01,776
And why that's true is super interesting to the point where NVIDIA got into this game,
834
00:55:01,776 --> 00:55:02,836
which I thought was kind of cool.
835
00:55:03,216 --> 00:55:05,476
So NVIDIA realized, oh my God, to run a quantum computer,
836
00:55:05,856 --> 00:55:07,816
you need a massive classical computer.
837
00:55:08,336 --> 00:55:11,636
And so they said, oh, we have a massive classical computer
838
00:55:11,636 --> 00:55:13,016
with these GPUs.
839
00:55:13,156 --> 00:55:14,916
So they put up this, what is it called?
840
00:55:15,316 --> 00:55:16,896
A CUDAQ library.
841
00:55:17,336 --> 00:55:21,256
So a lot of the physics experiments are hoping that NVIDIA
842
00:55:21,256 --> 00:55:22,936
will solve the software version of it,
843
00:55:23,196 --> 00:55:24,676
the software aspect of it,
844
00:55:24,996 --> 00:55:27,156
and that will help scale things up.
845
00:55:27,496 --> 00:55:29,776
So yeah, so things are coming together.
846
00:55:29,776 --> 00:55:32,396
It takes time, but things are coming together.
847
00:55:32,896 --> 00:55:36,456
Again, I think we have still many years to come.
848
00:55:37,116 --> 00:55:41,436
Just the number of things that have to be done is quite large.
849
00:55:41,516 --> 00:55:44,096
So we still have quite a long runway.
850
00:55:45,276 --> 00:55:53,096
In my, again, I could be wrong, reading between the lines, to me, it sounds like it's 2035 and above.
851
00:55:54,656 --> 00:55:58,476
I probably would guess even further out.
852
00:55:59,236 --> 00:56:05,416
But not everybody is as, some people are much more bullish than I am in thinking that it will come sooner.
853
00:56:05,796 --> 00:56:09,416
And of course, there's the argument that we should be prepared in the unlikely event.
854
00:56:10,176 --> 00:56:10,436
Exactly.
855
00:56:10,976 --> 00:56:17,656
Just again, to drive the point home, you know, the Google security team, not the quantum team, the Google security team made their own assessments.
856
00:56:18,076 --> 00:56:22,056
And they decided that they want to move the timelines up to 2029.
857
00:56:22,516 --> 00:56:22,996
Yeah.
858
00:56:23,156 --> 00:56:26,696
So not because they think there's a computer that's going to appear in 2029.
859
00:56:26,696 --> 00:56:28,996
is because they want to be ready.
860
00:56:29,676 --> 00:56:30,536
Just in case.
861
00:56:31,156 --> 00:56:32,876
Yeah, you don't want to bet the whole world
862
00:56:32,876 --> 00:56:36,876
just on something that's on a hunch.
863
00:56:36,996 --> 00:56:37,676
Yeah, you want to be ready.
864
00:56:38,136 --> 00:56:40,396
So they want to finish the transition by 2029.
865
00:56:40,516 --> 00:56:41,876
Another interesting thing about that is
866
00:56:41,876 --> 00:56:43,436
the transition is quite difficult.
867
00:56:43,616 --> 00:56:45,796
Moving the world to post-quantum is going to be,
868
00:56:46,376 --> 00:56:48,996
even for the web, it's going to be very difficult and slow.
869
00:56:49,616 --> 00:56:52,916
They might say 2029, but they could miss by three years easily.
870
00:56:52,916 --> 00:56:56,096
If they say 2035 and they miss by three years,
871
00:56:56,096 --> 00:56:58,176
now we're getting into kind of a danger zone.
872
00:56:58,836 --> 00:57:00,896
And so saying 2029 and missing by three years,
873
00:57:00,976 --> 00:57:02,136
we're still probably okay.
874
00:57:02,656 --> 00:57:04,616
All right, guys, taking a quick moment
875
00:57:04,616 --> 00:57:06,536
to thank my new sponsors of the show.
876
00:57:06,976 --> 00:57:09,356
First off, the one and only Layer 2 Labs,
877
00:57:09,496 --> 00:57:12,096
pushing forward research and development of drive chains.
878
00:57:12,716 --> 00:57:14,156
Drive chains were first introduced
879
00:57:14,156 --> 00:57:15,836
as a software proposal to Bitcoin,
880
00:57:16,036 --> 00:57:18,116
aka BIP300, BIP301.
881
00:57:18,836 --> 00:57:21,456
These BIPs essentially propose a bridging mechanism
882
00:57:21,456 --> 00:57:23,076
between Bitcoin and Layer 2s
883
00:57:23,076 --> 00:57:24,956
that are incentive aligned with miners,
884
00:57:24,956 --> 00:57:28,636
and they've gotten a ton of attention over the last couple of years.
885
00:57:29,236 --> 00:57:32,316
If you're curious about how drive chains could work in practice, though,
886
00:57:32,776 --> 00:57:37,056
check out Layer2Labs.com and download their alternative front end to Bitcoin Core.
887
00:57:37,536 --> 00:57:41,236
It lets you play with drive chains and see how they actually work in real life.
888
00:57:41,956 --> 00:57:46,876
I'd also like to introduce Hashi, an alternative primitive to traditional L2s
889
00:57:46,876 --> 00:57:50,776
that allows users to execute a wide range of Bitcoin DeFi activities
890
00:57:50,776 --> 00:57:53,576
without having to trust a federated bridge.
891
00:57:53,576 --> 00:58:06,196
With Hashi, Bitcoin is controlled by an MPC wallet that requires a quorum of proof-of-stake validators on the SUI network to execute Bitcoin transactions based on the validity of smart contracts.
892
00:58:06,876 --> 00:58:20,356
At least a third of the staking power of the SUI validators network is required to execute these MPC mint and redeem transactions, which is a substantive improvement in trust assumptions relative to other L2s or sidechain bridges.
893
00:58:21,316 --> 00:58:27,256
Hashi's commercial team is also stacked, including a crew of former builders from the crypto division of Meta.
894
00:58:27,836 --> 00:58:32,596
I think we're going to see a suite of super competitive Bitcoin DeFi products built with this protocol.
895
00:58:32,796 --> 00:58:36,736
So definitely check out the Hashi page on sui.io if you're curious.
896
00:58:37,956 --> 00:58:40,676
Last but not least, shout out to Bitbox.
897
00:58:41,216 --> 00:58:46,236
Bitbox is one of the easiest and most simple to use Bitcoin hardware wallets on the market right now.
898
00:58:46,236 --> 00:58:57,756
If you have friends or family members that you want to make sure stay safe and use cold storage, but maybe they're not the most Bitcoin native people in the world, I highly recommend checking out Bitbox.
899
00:58:57,936 --> 00:59:05,816
They're completely open source, no compromises on security, but they're also super easy to use, really intuitive UX.
900
00:59:06,396 --> 00:59:11,976
Plus, you can use them with concierge multi-sig services like Unchained, which I'm personally a big fan of.
901
00:59:11,976 --> 00:59:18,916
If you want to check out their hardware wallets, go to bitbox.swiss and use code Bitcoin Rails to get a discount.
902
00:59:19,436 --> 00:59:20,696
All right. Back to the show.
903
00:59:21,036 --> 00:59:22,436
So let's talk about mitigation.
904
00:59:22,796 --> 00:59:22,896
Yeah.
905
00:59:23,756 --> 00:59:28,856
For Bitcoin specifically, which is, you know, kind of most of my audience listening to this.
906
00:59:29,316 --> 00:59:34,356
Do you have a point of view about signature schemes and sort of how we should be?
907
00:59:34,436 --> 00:59:39,136
I mean, we could even just zoom out from there, you know, what we how we should be addressing this broadly.
908
00:59:39,136 --> 00:59:41,616
If you have like a big picture that you'd like to share for Bitcoin.
909
00:59:41,616 --> 00:59:47,316
But certainly I want to kind of ask you about your point of view about post-quantum signature schemes for Bitcoin, if you have a favorite.
910
00:59:47,756 --> 00:59:52,136
Yes. OK, good, good, good. So the question is what to do about the transition.
911
00:59:52,456 --> 00:59:55,376
Yeah. The answer is there's really no good answer.
912
00:59:55,756 --> 00:59:58,796
It's kind of sad, actually. There's really no good answer.
913
00:59:59,116 --> 01:00:02,356
So but we have to do something. Yeah. So we have to prepare. Right.
914
01:00:03,016 --> 01:00:06,176
So what do we do? Again, don't panic.
915
01:00:07,116 --> 01:00:11,576
But we can't ignore this problem either. And we need to start to start the transition.
916
01:00:11,616 --> 01:00:13,156
So what do we do?
917
01:00:13,836 --> 01:00:15,716
So let me actually zoom out just a little bit.
918
01:00:15,836 --> 01:00:18,376
I would say, first of all, for new blockchains,
919
01:00:18,636 --> 01:00:20,796
you know, there are new blockchains created once in a while.
920
01:00:21,376 --> 01:00:25,916
For new blockchains, it seems like a cautious thing to do
921
01:00:25,916 --> 01:00:28,916
is to have every user choose their seed phrase.
922
01:00:29,376 --> 01:00:33,856
But from the seed phrase, you can generate both ECDSA and ECDSA or Schnorr key
923
01:00:33,856 --> 01:00:38,336
and a post-quantum key and have both keys committed on chain.
924
01:00:38,336 --> 01:00:42,856
so that before Q-Day, everybody just uses the pre-quantum key and the world is happy.
925
01:00:43,316 --> 01:00:48,956
After Q-Day, at least users are protected because they already have a post-quantum key that's registered on chain.
926
01:00:49,016 --> 01:00:52,296
And this is happening at the wallet level or this would be like consensus?
927
01:00:52,516 --> 01:00:53,196
This is just wallet level.
928
01:00:53,196 --> 01:00:53,876
This is just wallets.
929
01:00:53,876 --> 01:00:58,076
For the non-Bitcoin chains, you can do this wallet level, which is maybe points for them.
930
01:00:58,636 --> 01:01:01,096
Yeah, well, this is also for new chains.
931
01:01:01,496 --> 01:01:06,036
For the existing chains, unfortunately, the reason this is so problematic
932
01:01:06,036 --> 01:01:08,716
is that everybody is going to have to transition.
933
01:01:09,376 --> 01:01:11,716
They have to revoke their old pre-quantum key
934
01:01:11,716 --> 01:01:13,856
and transition to post-quantum key.
935
01:01:13,896 --> 01:01:15,236
And some will inevitably not,
936
01:01:15,336 --> 01:01:17,136
which is a question that we'll get into.
937
01:01:17,456 --> 01:01:18,616
Which is the problem, the abandoned assets and so on.
938
01:01:18,616 --> 01:01:19,476
Abandoned assets, yep.
939
01:01:19,636 --> 01:01:20,656
Yeah, so what do we do?
940
01:01:20,656 --> 01:01:25,356
So, yeah, so look, we can go through the different schemes.
941
01:01:25,756 --> 01:01:28,116
Maybe to zoom out at a high level,
942
01:01:28,276 --> 01:01:30,456
I'll say there are kind of two contenders, right?
943
01:01:30,836 --> 01:01:32,176
And I think your audience knows this.
944
01:01:32,356 --> 01:01:35,156
There are hash-based schemes that people are considering.
945
01:01:35,596 --> 01:01:37,276
And then there are lattice-based schemes.
946
01:01:37,736 --> 01:01:39,896
Is isogeny in the mix at all or not really?
947
01:01:40,916 --> 01:01:42,016
So it's interesting you say this.
948
01:01:42,096 --> 01:01:43,256
So isogeny is in the mix.
949
01:01:43,476 --> 01:01:49,116
And in fact, NIST has a running additional signature scheme competition.
950
01:01:49,856 --> 01:01:54,876
And SQSign is actually one of the round two signature schemes in the NIST competition.
951
01:01:54,976 --> 01:01:56,456
So they've made it to round two.
952
01:01:57,056 --> 01:02:00,836
So isogenies are in the mix, but isogenies are a little problematic.
953
01:02:03,096 --> 01:02:04,616
Maybe do you want to talk about isogeny?
954
01:02:04,616 --> 01:02:06,376
So just really quickly, why are they problematic?
955
01:02:07,156 --> 01:02:11,516
So isogenies, as you probably know, they suffered a pretty significant attack recently.
956
01:02:11,676 --> 01:02:14,536
The key exchange mechanism turned out to be insecure.
957
01:02:15,456 --> 01:02:19,836
And it kind of shows, and the attack is basically not using kind of new math.
958
01:02:19,916 --> 01:02:22,496
It was like old math that just people didn't know about.
959
01:02:22,496 --> 01:02:23,016
Yeah.
960
01:02:23,176 --> 01:02:37,034
And it just shows this area uses such sophisticated tools that it a little hard for you know maybe there a theorem that we don know about that would impact
961
01:02:37,134 --> 01:02:39,774
It's not hard enough is sort of the argument, right?
962
01:02:39,774 --> 01:02:40,754
We need to wait.
963
01:02:40,894 --> 01:02:44,554
Isolians are great, fantastic, but we need to wait a bit more
964
01:02:44,554 --> 01:02:49,074
to make sure things are as secure as claimed before we start to use them.
965
01:02:49,074 --> 01:02:54,074
Is there an argument that lattice-based also could potentially experience
966
01:02:54,074 --> 01:02:58,094
those kinds of vulnerabilities that like maybe it's more like theoretical and like, you know,
967
01:02:58,314 --> 01:03:03,634
again, less hardened than hashes or Sphinx? Yeah, it is. So it is possible. So of course,
968
01:03:03,774 --> 01:03:08,114
I know it's possible that SHA-256 is not secure. It's possible that ECDSA is not secure. Anything
969
01:03:08,114 --> 01:03:12,154
is possible. Relatively speaking, though, I mean, like, how would you compare just the security
970
01:03:12,154 --> 01:03:18,094
properties of Lattice versus Hashes? Okay, I'll say it this way. You know, so the Bitcoin folks,
971
01:03:18,094 --> 01:03:23,294
they love SHA-256 and they love ECDSA. Yeah. Because we're used to them.
972
01:03:23,754 --> 01:03:23,994
Right.
973
01:03:24,214 --> 01:03:24,954
Yeah, we love.
974
01:03:25,054 --> 01:03:25,474
Yeah, I should say.
975
01:03:26,514 --> 01:03:27,454
Well, used to them.
976
01:03:27,534 --> 01:03:29,094
And also Satoshi kind of blessed them.
977
01:03:29,314 --> 01:03:29,774
Right, right.
978
01:03:29,894 --> 01:03:33,474
I guess it took forever for Peter Woolley to even convince folks to use Schnorr signatures.
979
01:03:33,754 --> 01:03:33,894
True.
980
01:03:34,434 --> 01:03:36,894
At least we adapted Schnorr signatures.
981
01:03:37,734 --> 01:03:42,074
Where, you know, SHA-256 and ECDAC and Schnorr, they didn't come from God.
982
01:03:42,174 --> 01:03:42,934
They came from NIST.
983
01:03:43,374 --> 01:03:43,774
Right?
984
01:03:43,894 --> 01:03:44,574
They came from NIST.
985
01:03:44,814 --> 01:03:45,734
NIST said this is OK.
986
01:03:45,734 --> 01:03:50,434
Well, now NIST is telling us lattices are OK to use for post-quandom crypto.
987
01:03:50,434 --> 01:03:54,154
Okay. You know, if Satoshi was alive today, well, if Satoshi was around.
988
01:03:54,174 --> 01:03:55,894
NIST has not approved isogenies. Is that?
989
01:03:56,174 --> 01:03:56,514
Not yet.
990
01:03:56,594 --> 01:03:59,214
Okay. So Lattice, okay. How's the NIST approval? Okay.
991
01:03:59,314 --> 01:04:03,694
They have approved Lattice schemes. They have approved Lattice signatures, Hashbase signatures.
992
01:04:04,274 --> 01:04:10,194
It's quite possible if Satoshi was designing Bitcoin today, he would have just used one of the post-quantum NIST standards.
993
01:04:10,494 --> 01:04:13,094
Yeah. So I think it's good to remember.
994
01:04:13,414 --> 01:04:15,454
Now, at the same time, I also understand the caution.
995
01:04:15,454 --> 01:04:17,414
I mean, of course, you need to be cautious.
996
01:04:18,414 --> 01:04:21,934
Lattice-based schemes are not as old as elliptic curve-based schemes.
997
01:04:22,074 --> 01:04:23,434
Or hash-based schemes.
998
01:04:23,754 --> 01:04:24,494
Or hash.
999
01:04:24,674 --> 01:04:25,194
Well, or hashes, period, yeah.
1000
01:04:25,594 --> 01:04:25,954
It's true.
1001
01:04:25,994 --> 01:04:27,534
But they have been around for quite a while.
1002
01:04:27,694 --> 01:04:29,894
Yeah, so lattice-based schemes now are over 20 years old.
1003
01:04:30,434 --> 01:04:31,994
They have been around for quite a while.
1004
01:04:32,334 --> 01:04:35,454
They have nice random stuff reduction properties to them.
1005
01:04:36,454 --> 01:04:41,514
You know, could there be a quantum algorithm that gives you polynomial approximations for
1006
01:04:41,514 --> 01:04:42,154
shortest vector?
1007
01:04:43,094 --> 01:04:43,454
Could be.
1008
01:04:43,454 --> 01:04:45,254
In fact, last, what was it, last year?
1009
01:04:45,374 --> 01:04:47,074
I mean, last year or two years ago.
1010
01:04:47,074 --> 01:04:50,894
I don't remember. There was actually a paper that claimed to have to have solved that.
1011
01:04:51,334 --> 01:04:57,954
Turned out to be wrong, but that that scared quite a few people for quite a while.
1012
01:04:58,194 --> 01:05:06,274
So I would say that when you move to a new signature scheme, there is not you can do what the web is doing.
1013
01:05:06,374 --> 01:05:11,414
So the web, if you look, the web has already transitioned to post-quantum encryption, post-quantum key exchange.
1014
01:05:11,414 --> 01:05:17,394
rather, if you connect to Amazon, if you connect to GitHub, if you connect to any of your favorite
1015
01:05:17,394 --> 01:05:22,674
sites on Chrome, you can look at the key exchange method that the browser is using. It's using
1016
01:05:22,674 --> 01:05:28,234
what's called a hybrid encryption scheme. Yeah, it's using effectively 25509, which is an elliptic
1017
01:05:28,234 --> 01:05:34,834
curve scheme, combined with MLChem768, which is a lattice-based scheme. Yeah. So we necessarily
1018
01:05:34,834 --> 01:05:40,614
don't make security worse. We still have elliptic curves to fall back to if something happens with
1019
01:05:40,614 --> 01:05:45,894
with lattices. But if somebody builds a quantum computer, at least we have lattices to protect
1020
01:05:45,894 --> 01:05:49,094
this. This is going to be one of my other key questions, because I've heard differing points
1021
01:05:49,094 --> 01:05:53,174
of view on this is, do you think that we should have redundancies of signature types in Bitcoin?
1022
01:05:53,514 --> 01:05:55,894
Absolutely. Absolutely. When you move to a new signature scheme,
1023
01:05:56,294 --> 01:05:57,934
you should always move to a hybrid signature scheme.
1024
01:05:57,934 --> 01:06:02,654
What do you think is the optimal number of signature scheme options to have in Bitcoin?
1025
01:06:02,654 --> 01:06:20,774
Okay, so to me, it's not options. So what I hope will happen, I'm not sure that will actually happen, but what I hope will happen is that the new post-quantum, so, okay, there are many solutions for Bitcoin, but let's suppose for a minute that Bitcoin adopts a post-quantum signature scheme.
1026
01:06:20,774 --> 01:06:27,854
What I hope will happen is that what will be adopted is actually one signature scheme that actually implements two.
1027
01:06:28,654 --> 01:06:34,854
In particular, it will do Schnorr plus, let's say, I'll say Hawk.
1028
01:06:35,194 --> 01:06:39,214
But specifically, it'll do something PQ and something elliptic curve based.
1029
01:06:39,574 --> 01:06:40,874
Is that the implication?
1030
01:06:41,294 --> 01:06:46,574
And it will be one signature, but the signature will be kind of two signatures smushed together.
1031
01:06:47,274 --> 01:06:47,354
Yeah.
1032
01:06:47,574 --> 01:06:47,734
Cool.
1033
01:06:47,734 --> 01:06:49,554
And the reason I say that that's actually...
1034
01:06:49,554 --> 01:06:50,654
Is there fun math to be able to do that?
1035
01:06:50,774 --> 01:06:52,314
No, no, no. It's actually quite –
1036
01:06:52,314 --> 01:06:52,814
It's simple?
1037
01:06:52,934 --> 01:06:55,214
Just an engineering problem.
1038
01:06:55,574 --> 01:06:58,054
You know, be careful when somebody tells you just engineering.
1039
01:06:58,754 --> 01:07:02,174
But from a mathematical point of view, we actually know how to do it.
1040
01:07:02,254 --> 01:07:04,054
Now it's just a matter of implementing it.
1041
01:07:04,414 --> 01:07:07,654
And I would say that is even true for the hash-based signature schemes.
1042
01:07:08,154 --> 01:07:11,774
The reason is ECDSA libraries are battle-tested.
1043
01:07:11,914 --> 01:07:12,794
They've been with us forever.
1044
01:07:12,954 --> 01:07:13,614
They've been optimized.
1045
01:07:14,434 --> 01:07:15,254
We trust them.
1046
01:07:15,834 --> 01:07:19,374
These hash-based signatures, you know, maybe there are bugs in the implementation, right?
1047
01:07:19,374 --> 01:07:23,114
if you combine a pre-quantum signature with a hash-based signature,
1048
01:07:23,714 --> 01:07:27,234
you are not harming, you are by, provably, you are not harming security.
1049
01:07:27,354 --> 01:07:31,354
So you get the separate benefits of each signature type,
1050
01:07:31,414 --> 01:07:33,754
even if you smush them together into one signature.
1051
01:07:33,894 --> 01:07:35,614
Well, provably, you're not harming security.
1052
01:07:35,754 --> 01:07:37,134
You can only make things better.
1053
01:07:37,534 --> 01:07:40,234
Now, the interesting thing is the post-quantum signatures
1054
01:07:40,234 --> 01:07:43,734
are much longer than the pre-quantum signatures, sadly,
1055
01:07:44,034 --> 01:07:46,494
which means that actually moving to a hybrid model
1056
01:07:46,494 --> 01:07:49,954
is actually from a signature size point of view,
1057
01:07:50,314 --> 01:07:52,054
is not that expensive, right?
1058
01:07:52,234 --> 01:07:54,414
When you take a big number and you add a small number to it,
1059
01:07:54,554 --> 01:07:56,434
it doesn't change the big number by too much.
1060
01:07:57,154 --> 01:08:00,594
And so it's not an unreasonable engineering requirement to do that.
1061
01:08:00,854 --> 01:08:03,354
But I see the world not going in that direction,
1062
01:08:03,814 --> 01:08:07,234
which I think deserves more discussion.
1063
01:08:07,514 --> 01:08:09,774
You see instead people just being like,
1064
01:08:09,834 --> 01:08:11,934
okay, we're just going to switch out of ECC entirely
1065
01:08:11,934 --> 01:08:14,074
and just go straight into some hash-based scheme?
1066
01:08:14,294 --> 01:08:15,794
Or what they'll do is, for example,
1067
01:08:15,794 --> 01:08:21,854
they use taproot where one leaf is Schnorr or ECDSA,
1068
01:08:21,954 --> 01:08:23,854
and the other leaf is some post-quantum.
1069
01:08:23,854 --> 01:08:26,474
And that would be like the optionality version
1070
01:08:26,474 --> 01:08:27,714
versus what you're saying,
1071
01:08:27,774 --> 01:08:29,534
which is the smushing together option.
1072
01:08:29,774 --> 01:08:34,394
What we have learned for over many years of pain and suffering
1073
01:08:34,394 --> 01:08:37,994
is the minute you start giving users and developers options,
1074
01:08:38,554 --> 01:08:39,414
those are foot guns.
1075
01:08:39,754 --> 01:08:40,794
It's interesting you say that
1076
01:08:40,794 --> 01:08:43,314
because that is the primary argument that I've heard
1077
01:08:43,314 --> 01:08:45,074
for like reducing redundancies
1078
01:08:45,074 --> 01:08:46,634
is don't give people options.
1079
01:08:46,794 --> 01:08:48,834
Don't let people do different things on Bitcoin
1080
01:08:48,834 --> 01:08:51,534
that actually comes with its own risks, essentially.
1081
01:08:51,914 --> 01:08:53,934
You're taking on different security vulnerabilities
1082
01:08:53,934 --> 01:08:54,834
than your counterpart.
1083
01:08:54,974 --> 01:08:55,934
It's not a good idea.
1084
01:08:56,214 --> 01:08:58,214
So my point is even more than my point is
1085
01:08:58,214 --> 01:09:00,794
if we're going to implement post-quantum using Taproot,
1086
01:09:01,334 --> 01:09:05,814
rather than having a ECDSA leaf and a MLDSA leaf,
1087
01:09:05,914 --> 01:09:07,774
say, or a HAWC leaf or whatever,
1088
01:09:08,454 --> 01:09:11,074
let's make the, HAWC, by the way,
1089
01:09:11,154 --> 01:09:12,814
is a post-quantum lattice signature.
1090
01:09:13,034 --> 01:09:13,314
Yeah.
1091
01:09:13,454 --> 01:09:14,514
Which I would love to talk about.
1092
01:09:14,554 --> 01:09:15,574
Okay, we can talk about hog.
1093
01:09:15,674 --> 01:09:24,554
What I'm saying is, rather than just having a hog leaf, make the hog leaf be a concatenation of a hog signature and schnorr, for example.
1094
01:09:24,554 --> 01:09:25,834
I've never even heard of this idea.
1095
01:09:25,934 --> 01:09:27,934
Have you posited this on the mailing list?
1096
01:09:28,014 --> 01:09:29,554
Like you said, no one's talking about this.
1097
01:09:29,554 --> 01:09:29,994
I don't know.
1098
01:09:30,014 --> 01:09:30,514
It's kind of obvious.
1099
01:09:30,634 --> 01:09:31,374
What is there to say?
1100
01:09:31,514 --> 01:09:32,914
But you said no one is talking about this.
1101
01:09:32,914 --> 01:09:33,994
Well, that's what we're talking about.
1102
01:09:34,014 --> 01:09:36,774
I mean, we're talking about, okay, so now we're popularizing this idea.
1103
01:09:36,874 --> 01:09:38,654
Hey, you don't need to give people the option.
1104
01:09:38,734 --> 01:09:41,834
You can smush them together and just kind of, I guess, two plus two.
1105
01:09:41,834 --> 01:09:51,534
But it's even more than that. This is literally what the web decided to do. The web didn't just move to MLChem. The web moved to a hybrid scheme. Why would the blockchain do something different? Right?
1106
01:09:51,974 --> 01:09:54,094
Fair question. What do you think of...
1107
01:09:54,094 --> 01:10:05,834
Oh, sorry. One more point. In the web, we didn't give people the option, oh, you know, you can choose whichever pairs you want. No, no. The name of the cipher spec that is post-quantum is 25519MLChem.
1108
01:10:05,834 --> 01:10:11,714
MLChem. Like, that is one atom. It's not like the two are separate. That is one atom that does both
1109
01:10:11,714 --> 01:10:15,574
at the same time. This is an important distinction because I think a lot of people are not thinking
1110
01:10:15,574 --> 01:10:19,454
about it this way. I think most people are thinking of it in the Merkle-ized way, where you have
1111
01:10:19,454 --> 01:10:23,534
options of signatures, and that's problematic. And the minute you give options, people are going to
1112
01:10:23,534 --> 01:10:28,214
start misusing the options and maybe not implementing the option. And basically, we're
1113
01:10:28,214 --> 01:10:34,414
just giving people a foot gun. Okay. My opinion. My opinion. What do you think? I mean, so I have
1114
01:10:34,414 --> 01:10:38,554
lots of follow-up questions there. But I was going to ask you about some of the hash-based
1115
01:10:38,554 --> 01:10:43,294
signatures that folks are putting forth on Bitcoin. Right now, it seems like the popular
1116
01:10:43,294 --> 01:10:51,474
front-runner is Jonas Nix shrinks, shrimps, kind of hash-based optimization. Would it even be
1117
01:10:51,474 --> 01:10:56,954
possible to, I mean, could you do this kind of smushing technique with something like that,
1118
01:10:57,014 --> 01:11:00,494
with like shrinks and shrimps potentially? Of course, of course. You could. So that is
1119
01:11:00,494 --> 01:11:08,734
not a problem. That is not a problem. Okay. So, man, okay. Right. Lots to say here. I think what
1120
01:11:08,734 --> 01:11:14,954
you're asking me is, forget the hybrid method. Just let's talk about the core post-quantum
1121
01:11:14,954 --> 01:11:18,434
signature. Should we use a hash-based signature or should we use a lattice-based signature?
1122
01:11:19,434 --> 01:11:27,754
So I would like to say that the current blockchain thinking is we're going to move in the direction
1123
01:11:27,754 --> 01:11:29,474
of purely hash-based signatures.
1124
01:11:30,334 --> 01:11:32,614
Ethereum, by the way, is more general than that.
1125
01:11:32,654 --> 01:11:33,094
It's very interesting.
1126
01:11:33,234 --> 01:11:35,694
For Ethereum transactions, Ethereum is saying,
1127
01:11:35,954 --> 01:11:37,994
we're just going to move to smart contract wallets.
1128
01:11:38,114 --> 01:11:38,334
Right.
1129
01:11:38,594 --> 01:11:40,954
And then users can implement whatever signature scheme
1130
01:11:40,954 --> 01:11:42,554
they want in their wallet.
1131
01:11:42,634 --> 01:11:43,834
Do you think that's a good plan for them?
1132
01:11:44,134 --> 01:11:45,094
It's a very interesting plan.
1133
01:11:45,274 --> 01:11:46,554
Actually, I kind of like that.
1134
01:11:46,614 --> 01:11:47,174
That's a very interesting plan.
1135
01:11:47,174 --> 01:11:49,234
So optionality works for Ethereum in a way
1136
01:11:49,234 --> 01:11:50,114
that it doesn't for Bitcoin.
1137
01:11:50,114 --> 01:11:51,254
At the transaction level, yeah, yeah.
1138
01:11:51,574 --> 01:11:53,594
For consensus, they're thinking of doing something different.
1139
01:11:53,814 --> 01:11:54,674
But let's talk about Bitcoin.
1140
01:11:55,254 --> 01:11:57,094
So again, the question is hash-based signatures
1141
01:11:57,094 --> 01:11:58,534
or lattice-based signatures.
1142
01:11:59,494 --> 01:12:03,054
I would like to actually push for lattice-based signatures.
1143
01:12:03,234 --> 01:12:04,074
Let me explain why.
1144
01:12:06,534 --> 01:12:07,314
Hot take.
1145
01:12:07,674 --> 01:12:08,234
Well, okay.
1146
01:12:08,514 --> 01:12:08,774
Is it?
1147
01:12:08,934 --> 01:12:09,174
All right.
1148
01:12:09,574 --> 01:12:11,434
Well, I would like to push for lattice-based signatures.
1149
01:12:11,614 --> 01:12:12,894
So my reasoning is this.
1150
01:12:14,414 --> 01:12:16,854
Hash-based signatures are kind of combinatorial in nature,
1151
01:12:17,054 --> 01:12:22,434
and that limits a lot of the clever things we can do with them.
1152
01:12:22,994 --> 01:12:24,414
So what do we want to do with signatures?
1153
01:12:24,594 --> 01:12:26,814
So, for example, we'd like to implement threshold signatures.
1154
01:12:27,094 --> 01:12:31,474
So what's a threshold signature? You take your secret key, you break it up into multiple shares,
1155
01:12:31,914 --> 01:12:35,494
and so that even if a few shares are compromised, the key is not revealed.
1156
01:12:36,174 --> 01:12:41,114
It turns out with lattice-based signatures, it's actually not as easy as BLS,
1157
01:12:41,314 --> 01:12:45,014
but it's not that difficult to actually thresholdize lattice-based signatures.
1158
01:12:45,494 --> 01:12:49,614
When it comes to hash-based signatures, there are a couple of proposals for doing it,
1159
01:12:49,674 --> 01:12:55,814
but it's a lot harder. And here we can go into how hash-based signatures work. There's actually
1160
01:12:55,814 --> 01:13:01,674
a proposal called Haystack for threshold-based hash-based signatures. And just to give you
1161
01:13:01,674 --> 01:13:07,234
an idea for why already you can see why it's complicated, in Haystack, for example, the
1162
01:13:07,234 --> 01:13:13,974
threshold and the, so T and N, the threshold and the number of parties is somewhat, it's sort of
1163
01:13:13,974 --> 01:13:18,434
revealed by the public key. Yeah, by the public key and the signatures. Whereas when you use
1164
01:13:18,434 --> 01:13:22,994
threshold signatures, there's often a desire to not reveal what the threshold is. You know,
1165
01:13:22,994 --> 01:13:27,094
if I'm using threshold signatures to protect my secret key,
1166
01:13:27,474 --> 01:13:30,134
I don't want to tell the attacker how many people they have to compromise
1167
01:13:30,134 --> 01:13:31,774
in order to steal my key.
1168
01:13:31,814 --> 01:13:33,854
So I want the threshold to remain secret.
1169
01:13:34,974 --> 01:13:38,614
And for example, if you use a combinatorial threshold signature scheme,
1170
01:13:38,694 --> 01:13:40,814
it's much harder to keep the, not impossible,
1171
01:13:41,174 --> 01:13:43,334
but much harder to keep the threshold secret.
1172
01:13:43,754 --> 01:13:47,614
So one approach to threshold signatures from hash-based signatures
1173
01:13:47,614 --> 01:13:49,134
is actually using a snark.
1174
01:13:49,714 --> 01:13:52,794
So everybody will generate their own secret key, public key,
1175
01:13:52,994 --> 01:13:58,034
So T people will sign to indicate that T have signed.
1176
01:13:58,314 --> 01:14:02,834
And then we'll use a snark to compress those T signatures into a single proof.
1177
01:14:03,234 --> 01:14:06,794
So some combination of snarks plus lattice-based signatures.
1178
01:14:07,054 --> 01:14:07,434
Hash-based.
1179
01:14:07,534 --> 01:14:08,114
This will be hash-based.
1180
01:14:08,134 --> 01:14:09,174
Oh, this is for hash-based.
1181
01:14:09,174 --> 01:14:09,254
This is hash-based.
1182
01:14:09,274 --> 01:14:09,954
You have to use snarks.
1183
01:14:10,054 --> 01:14:11,754
But if you had lattices, you would not.
1184
01:14:12,434 --> 01:14:12,894
Okay.
1185
01:14:13,614 --> 01:14:14,434
Let's be precise here.
1186
01:14:14,474 --> 01:14:14,734
Okay.
1187
01:14:15,114 --> 01:14:19,694
In the hash-based world, there are combinatorial methods to do threshold signatures.
1188
01:14:19,694 --> 01:14:24,874
they are somewhat problematic for various reasons.
1189
01:14:25,074 --> 01:14:28,894
One of them is that the simple constructions reveal the threshold.
1190
01:14:29,474 --> 01:14:33,934
The other way to do threshold signatures from hash-based methods is using a snark.
1191
01:14:34,494 --> 01:14:36,954
But now you have to use a snark for every signature.
1192
01:14:37,034 --> 01:14:43,054
Every signature basically involves a snark proof with all the baggage that it goes without.
1193
01:14:43,354 --> 01:14:46,394
By the way, I'll say one thing when using a snark, you have to be a little careful.
1194
01:14:46,394 --> 01:14:49,634
The snark by default will reveal the threshold.
1195
01:14:50,294 --> 01:14:52,634
So when implementing a SNARK-based threshold signature,
1196
01:14:52,994 --> 01:14:56,694
it's kind of important that the threshold is committed and not available in the clear.
1197
01:14:57,054 --> 01:15:00,554
So the SNARK proof would have to be relative to commitment to the threshold,
1198
01:15:00,734 --> 01:15:01,974
not on the threshold itself.
1199
01:15:02,174 --> 01:15:04,634
Okay, so there's a bit of a nuance in implementing the SNARK,
1200
01:15:04,734 --> 01:15:06,134
but I want people to keep that in mind.
1201
01:15:06,554 --> 01:15:11,314
Yeah, hiding the threshold is very important in the threshold signature for some applications.
1202
01:15:11,474 --> 01:15:13,914
While we're on the topic of SNARKs, really quickly,
1203
01:15:13,994 --> 01:15:18,134
do you have a point of view about quantum-resistant SNARKs and what we should be doing there?
1204
01:15:18,154 --> 01:15:19,554
Yeah, yeah, yeah. That's actually not a problem.
1205
01:15:19,554 --> 01:15:22,594
In fact, most of the deployed snarks are quantum resistant.
1206
01:15:22,854 --> 01:15:23,174
Oh, okay.
1207
01:15:23,194 --> 01:15:24,794
So actually, that's not a problem.
1208
01:15:24,954 --> 01:15:25,854
Okay, okay.
1209
01:15:25,994 --> 01:15:27,114
How are they quantum resistant?
1210
01:15:27,134 --> 01:15:27,954
They're hash-based, basically.
1211
01:15:27,954 --> 01:15:28,314
Oh, they are?
1212
01:15:28,614 --> 01:15:30,674
You would say most snarks are hash-based?
1213
01:15:30,774 --> 01:15:36,694
Yeah, the deployed ones, not the ones that go on-chain, but the deployed ones, for other purposes, are hash-based.
1214
01:15:36,834 --> 01:15:37,114
Okay.
1215
01:15:37,374 --> 01:15:41,034
So for that, we have, I would say that is not a controversial.
1216
01:15:41,034 --> 01:15:41,754
That's not an issue.
1217
01:15:42,154 --> 01:15:42,314
Okay.
1218
01:15:42,314 --> 01:15:54,214
Sadly, of course, they're not as compact as the pre-quantum ones, but they are post-quantum because they're only based on hashes.
1219
01:15:54,654 --> 01:15:57,694
But let's go back to your question of hash-based signatures versus lattice-based signatures.
1220
01:15:58,274 --> 01:16:05,974
So my first point is with lattice-based signatures, a threshold mechanism is much easier than in a hash-based mechanism.
1221
01:16:06,434 --> 01:16:06,554
Okay?
1222
01:16:07,154 --> 01:16:07,714
Point number one.
1223
01:16:07,814 --> 01:16:08,014
Okay.
1224
01:16:08,014 --> 01:16:16,634
Point number two is lattice-based signatures have an algebraic structure, and we know that algebraic structures allow us to innovate.
1225
01:16:17,214 --> 01:16:23,574
And even with Schnorr signatures, we have adapter signatures and we have the taproot tweaking mechanism.
1226
01:16:23,894 --> 01:16:36,774
There's all these beautiful ideas, even in the Bitcoin world, all these beautiful ideas that are based on the algebraic structure of Schnorr signatures, and it translates to lattice-based signatures.
1227
01:16:37,194 --> 01:16:40,754
There's a new paper on HD wallets for lattice-based schemes.
1228
01:16:40,754 --> 01:16:47,954
Yeah, and so the algebraic structure lets us do things that are much harder or even impossible to do with hash-based signatures.
1229
01:16:48,254 --> 01:16:57,834
So I would say that if the community decides to go down the path of hash-based signatures, we are basically cutting off a lot of potential innovation.
1230
01:16:58,174 --> 01:17:00,634
Yeah, because we're stuck with combinatorics.
1231
01:17:00,634 --> 01:17:18,134
So my, again, my sort of take on that, if I was going to just summarize what you just said, is basically that lattice-based signatures will allow us to be able to continue to do all of these interesting technical things that we currently do with ECDSA that would not be possible if we moved to hash-based schemes.
1232
01:17:18,234 --> 01:17:24,734
So hash-based schemes might have like a minor edge is what I'm hearing on hardness, but you just give up all this functionality.
1233
01:17:25,014 --> 01:17:28,354
And that might be an argument to just move into lattice-based from the get.
1234
01:17:29,094 --> 01:17:30,914
Yeah, that's a fair summary.
1235
01:17:31,234 --> 01:17:31,354
Okay.
1236
01:17:32,254 --> 01:17:33,594
Yeah, I guess we could go with hash-based.
1237
01:17:33,754 --> 01:17:34,614
There's further nuance.
1238
01:17:34,714 --> 01:17:36,954
If you're going to do ZK proofs on hash-based schemes,
1239
01:17:37,654 --> 01:17:42,514
there is actually a push towards using hash-friendly,
1240
01:17:42,854 --> 01:17:46,014
hash functions, and that has its own can of worms.
1241
01:17:46,514 --> 01:17:48,954
I wonder if we're going to see any proposals,
1242
01:17:49,114 --> 01:17:50,774
lattice-based proposals anytime soon.
1243
01:17:50,774 --> 01:17:53,134
I think that one of the challenges with Bitcoin
1244
01:17:53,134 --> 01:17:55,794
is that it is the sort of like new beast.
1245
01:17:56,614 --> 01:17:57,334
Okay, good, good, good.
1246
01:17:57,394 --> 01:17:58,154
I like that you said that.
1247
01:17:58,154 --> 01:18:00,154
So let's talk about now the lattice-based signatures.
1248
01:18:00,814 --> 01:18:05,594
So one thing that happened, which is really unfortunate, is the NIST competition.
1249
01:18:05,694 --> 01:18:06,914
Well, they don't like calling it a competition.
1250
01:18:07,054 --> 01:18:10,134
The NIST process actually happened too early.
1251
01:18:10,594 --> 01:18:10,714
Yeah.
1252
01:18:10,854 --> 01:18:16,314
So they standardized lattice-based signatures before the research community had its say.
1253
01:18:16,734 --> 01:18:16,894
Yeah.
1254
01:18:17,354 --> 01:18:23,254
And so as a result, MLDSA at this point is not the best lattice algorithm, lattice scheme that we have.
1255
01:18:23,574 --> 01:18:23,634
Yeah.
1256
01:18:23,714 --> 01:18:24,214
Also a hot take.
1257
01:18:24,274 --> 01:18:24,454
Yeah.
1258
01:18:24,454 --> 01:18:26,534
And NIST actually recognizes this.
1259
01:18:26,534 --> 01:18:29,394
And because of this, they reopened the competition.
1260
01:18:29,594 --> 01:18:31,394
They have this thing called additional signature schemes.
1261
01:18:32,014 --> 01:18:37,154
And like the round two candidates, I can tell you there's a, well, there's one isogeny-based
1262
01:18:37,154 --> 01:18:38,614
scheme, a skew sign.
1263
01:18:39,494 --> 01:18:43,354
There's one lattice-based scheme called HAWC in that competition.
1264
01:18:43,894 --> 01:18:44,874
So HAWC, it's kind of interesting.
1265
01:18:44,994 --> 01:18:47,154
It's based on an interesting problem.
1266
01:18:47,274 --> 01:18:53,034
It's called the lattice isomorphism problem, which is really, it's quite an elegant problem.
1267
01:18:53,114 --> 01:18:55,094
I can tell you in one sentence what the problem is.
1268
01:18:55,094 --> 01:18:59,374
I give you two isomorphic bilinear forms
1269
01:18:59,374 --> 01:19:01,894
and I ask you find the isomorphism between them.
1270
01:19:02,194 --> 01:19:03,274
Yeah, that's the problem.
1271
01:19:03,654 --> 01:19:04,774
That's quite an elegant problem,
1272
01:19:04,874 --> 01:19:07,114
has a lot of interesting properties to it.
1273
01:19:07,414 --> 01:19:11,594
And it leads to signatures that are not even that big.
1274
01:19:11,694 --> 01:19:14,534
Here, I even wrote it down
1275
01:19:14,534 --> 01:19:16,854
just to make sure I get the right number.
1276
01:19:17,254 --> 01:19:18,154
Do I have it here somewhere?
1277
01:19:18,554 --> 01:19:19,154
Let's see.
1278
01:19:19,154 --> 01:19:20,714
Oh, yeah, yeah.
1279
01:19:20,854 --> 01:19:24,594
So yeah, so Hawk, the higher level of security
1280
01:19:24,594 --> 01:19:30,654
is about 1.2 kilobytes, whereas MLDSA is even longer. Yeah, so Hawk is a much shorter signature.
1281
01:19:31,434 --> 01:19:35,114
I love that all these lattice-based schemes are named after birds, by the way.
1282
01:19:36,514 --> 01:19:39,134
Hawk, Falcon. I mean, I love the bird.
1283
01:19:39,134 --> 01:19:45,214
Right, right. That's good. That's, I guess, one of the fun things about being in the field.
1284
01:19:46,134 --> 01:19:51,994
Yeah, okay. So, right. So, we have, by the way, 1.2 kilobytes is not 64 bytes,
1285
01:19:51,994 --> 01:19:54,134
which is what we have in the pre-quantum world.
1286
01:19:54,454 --> 01:19:55,354
Still quite expensive.
1287
01:19:55,694 --> 01:19:56,334
Still quite expensive.
1288
01:19:57,694 --> 01:19:58,274
So, yeah.
1289
01:19:58,354 --> 01:20:00,434
So, anyhow, I think that's what I'll say about...
1290
01:20:00,434 --> 01:20:00,934
Oh, sorry.
1291
01:20:00,974 --> 01:20:02,034
There's one more thing that I'd like to say.
1292
01:20:02,114 --> 01:20:07,654
There's even a recent result from Crypto 25 that shows that even if you look at MLDSA,
1293
01:20:07,874 --> 01:20:13,454
even MLDSA itself can be improved and the signature size can be reduced quite dramatically
1294
01:20:13,454 --> 01:20:14,774
to just over a kilobyte.
1295
01:20:15,114 --> 01:20:16,834
Whereas today, it's much, much more than that.
1296
01:20:16,834 --> 01:20:22,254
So just keep in mind, the NIST process in some sense was done too early.
1297
01:20:22,614 --> 01:20:27,714
I remember in the early version of BIP 360 that you are a co-author of, you guys suggested MLDSA.
1298
01:20:28,054 --> 01:20:29,574
That was not the right thing to do.
1299
01:20:30,054 --> 01:20:34,414
Yeah, we have better signature schemes now, lattice-based signature schemes.
1300
01:20:34,514 --> 01:20:35,554
There would be better alternatives.
1301
01:20:35,874 --> 01:20:38,394
And the ones that it sounds like the Hawk is your favorite.
1302
01:20:39,414 --> 01:20:43,694
Well, Hawk is on, like I said, it's one of the round two NIST candidates.
1303
01:20:43,694 --> 01:20:47,354
And, you know, the Bitcoin world seems to be in love with NIST standards.
1304
01:20:47,974 --> 01:20:51,154
And so that one could be on a track to become a NIST standard.
1305
01:20:51,354 --> 01:20:52,754
And so that's the one thing.
1306
01:20:52,774 --> 01:20:54,954
Is it mostly the Bitcoin world that loves NIST standards?
1307
01:20:55,234 --> 01:20:57,254
It's not everyone who loves NIST standards?
1308
01:20:58,134 --> 01:20:59,734
That's not a global point of view?
1309
01:21:00,034 --> 01:21:01,114
Okay, well, fair.
1310
01:21:01,414 --> 01:21:04,274
I would say the Ethereum world is much more open.
1311
01:21:04,574 --> 01:21:05,934
I mean, Ethereum uses BLS.
1312
01:21:06,134 --> 01:21:08,554
Ethereum uses pairings much more aggressively.
1313
01:21:08,554 --> 01:21:13,634
And so I would say other blockchains are much more open to more modern systems.
1314
01:21:13,694 --> 01:21:18,274
Would you consider like shrimp shrinks like a modern system, like a custom system?
1315
01:21:18,374 --> 01:21:18,954
Yeah, yeah.
1316
01:21:19,054 --> 01:21:19,434
You would.
1317
01:21:19,694 --> 01:21:20,374
Yeah, yeah, for sure.
1318
01:21:20,454 --> 01:21:21,574
That's not a NIST standard.
1319
01:21:21,614 --> 01:21:22,614
So actually, you know what?
1320
01:21:22,874 --> 01:21:23,514
Thank you very much.
1321
01:21:23,594 --> 01:21:25,834
I guess you just you just gave me a counter example.
1322
01:21:26,434 --> 01:21:29,254
Well, but shrimps has not been adopted by the Bitcoin community yet.
1323
01:21:29,274 --> 01:21:29,994
It's just a proposal.
1324
01:21:30,594 --> 01:21:31,254
That's true.
1325
01:21:31,454 --> 01:21:32,734
At the same time, I would say that.
1326
01:21:32,994 --> 01:21:35,574
But they seem to be leading in the court of public opinion.
1327
01:21:35,674 --> 01:21:35,954
For sure.
1328
01:21:36,074 --> 01:21:36,254
For sure.
1329
01:21:36,554 --> 01:21:36,774
Yeah.
1330
01:21:37,094 --> 01:21:39,714
What's your point of view as far as hash based schemes go?
1331
01:21:39,774 --> 01:21:41,234
What's your point of view on shrinks and shrimps?
1332
01:21:41,414 --> 01:21:41,874
Yeah, yeah, yeah.
1333
01:21:41,874 --> 01:21:52,274
So with hash-based schemes, I guess the, I mean, at the end of the day, you can prove that the scheme is as secure as the underlying hash function.
1334
01:21:52,894 --> 01:21:53,014
Yeah.
1335
01:21:53,114 --> 01:21:56,814
And so as long as you trust SHA-256, the scheme is secure.
1336
01:21:57,014 --> 01:21:58,014
There's nothing to debate.
1337
01:21:58,334 --> 01:21:58,534
Right.
1338
01:21:58,674 --> 01:22:02,854
That's sort of what I was thinking is like, well, it's based on hashes, which I think is like the key thing.
1339
01:22:03,254 --> 01:22:05,334
So that's why people are not terribly worried.
1340
01:22:05,374 --> 01:22:09,914
So in some sense, the fact that it deviates from the NIST standard is not that important.
1341
01:22:09,914 --> 01:22:10,634
Not that big a deal.
1342
01:22:10,634 --> 01:22:15,574
She can prove it's as secure as the new standard because it's still based on SHA-256.
1343
01:22:16,514 --> 01:22:19,774
So from a security point of view, there's not any problem.
1344
01:22:20,034 --> 01:22:20,214
Okay.
1345
01:22:20,214 --> 01:22:21,134
That's perfectly fine.
1346
01:22:21,294 --> 01:22:21,454
Okay.
1347
01:22:21,714 --> 01:22:28,814
My argument is, look, sure, if you want to use hash-based signatures, use hash-based signatures.
1348
01:22:28,814 --> 01:22:35,594
My argument is it's going to stifle a lot of upcoming innovation in that, you know,
1349
01:22:35,854 --> 01:22:39,534
threshold signatures, adapter signatures, how do we do distributed key generation?
1350
01:22:39,534 --> 01:22:46,734
I mean, there's like a lot of questions that are solvable when we have an algebraic structure and are much harder when we don't.
1351
01:22:46,994 --> 01:22:49,494
And those things actually do have security implications.
1352
01:22:49,934 --> 01:22:52,394
Like when you talk about key management, those kinds of things.
1353
01:22:52,514 --> 01:22:57,494
I mean, these are not, this is just like innovation in the like layer two sense or something like that.
1354
01:22:57,574 --> 01:23:00,494
It's like this is critical for like custody and issues of that nature.
1355
01:23:00,494 --> 01:23:04,814
So for example, if you're going to do threshold signatures from hash-based schemes using a
1356
01:23:04,814 --> 01:23:10,434
snark, well, now all of a sudden the Bitcoin network has to be able to verify snarks.
1357
01:23:10,434 --> 01:23:11,434
Yeah.
1358
01:23:11,434 --> 01:23:15,094
So now you've introduced this huge complexity into the Bitcoin network.
1359
01:23:15,094 --> 01:23:19,954
Speaking of snarks and kind of circling back into Xero knowledge proofs, where do you see
1360
01:23:19,992 --> 01:23:23,852
proofs. I mean, you gave one example of how zero knowledge proofs could be useful in this sort of
1361
01:23:23,852 --> 01:23:30,872
quantum hardening process. They've also obviously come up in the conversation about Satoshi's coins
1362
01:23:30,872 --> 01:23:35,072
and quantum vulnerable coins. I think that this is a proposal that people are thinking about is,
1363
01:23:35,212 --> 01:23:39,632
you know, again, first, like, burn, don't burn. But if we do burn, can we do retrieval with zero
1364
01:23:39,632 --> 01:23:45,032
knowledge proofs? I'm curious if you could touch on that a little bit. Of course, of course. As
1365
01:23:45,032 --> 01:23:50,792
usual. There's lots to say. Right. So I guess BIP 361 came out.
1366
01:23:50,972 --> 01:23:51,932
Yeah. Jameson Lopp.
1367
01:23:52,112 --> 01:24:00,012
Yes, exactly. So let's just review the proposal. The proposal is disallow transfers into non-post-quantum
1368
01:24:00,012 --> 01:24:08,132
scripts. Two years after the proposal is adopted, revoke all non-post-quantum UTXOs.
1369
01:24:08,352 --> 01:24:11,372
So deprecate all quantum vulnerable UTXOs.
1370
01:24:11,372 --> 01:24:23,612
And then the third phase is if somebody complains that they lost their funds as a result, then there's a backup process through a ZK proof of a BIP32 seed phrase.
1371
01:24:23,912 --> 01:24:25,352
And this would only be usable.
1372
01:24:25,492 --> 01:24:31,852
I think people often point this out, is that that would only be possible with addresses that have seed phrases, right?
1373
01:24:32,152 --> 01:24:32,292
Yeah.
1374
01:24:32,392 --> 01:24:33,272
I think it's good to remember.
1375
01:24:33,372 --> 01:24:35,212
BIP32 is 2012.
1376
01:24:35,552 --> 01:24:35,752
Right.
1377
01:24:35,752 --> 01:24:41,192
So any address before 2012, by definition, is not BIP32.
1378
01:24:41,372 --> 01:24:45,332
Even after 2012, you know, the Bitcoin world is the Wild West.
1379
01:24:45,692 --> 01:24:47,772
So wallets don't have to use BIP32.
1380
01:24:48,192 --> 01:24:53,292
Wallets can do seed phrase to secret key generation however they want.
1381
01:24:53,752 --> 01:24:56,772
And so people who didn't use BIP32, there's an issue.
1382
01:24:57,492 --> 01:24:59,392
There's other issues that I wanted to bring up.
1383
01:24:59,832 --> 01:25:07,132
So technically, the way seed phrases work is they use BIP39 to hash and then they use BIP32 to do key derivation.
1384
01:25:07,512 --> 01:25:07,672
Yes?
1385
01:25:08,272 --> 01:25:10,072
I hope everybody's familiar with this.
1386
01:25:11,052 --> 01:25:13,552
BIP39 is very ZK unfriendly.
1387
01:25:13,912 --> 01:25:17,152
Yeah, so BIP39 uses PBKDF2.
1388
01:25:17,432 --> 01:25:21,632
So if I remember correctly, it does 2,000 iterations of SHA-256.
1389
01:25:21,852 --> 01:25:23,772
So that is very ZK unfriendly.
1390
01:25:23,892 --> 01:25:24,272
Interesting.
1391
01:25:24,312 --> 01:25:30,012
Because now you have to prove 2,000 iterations of SHA-256, which is kind of hard for a prover to do.
1392
01:25:30,472 --> 01:25:34,132
But fortunately, the two are nicely segmented.
1393
01:25:34,132 --> 01:25:38,672
Yeah, so you do 2,000 iterations to get to somewhere.
1394
01:25:38,672 --> 01:25:43,792
And then from that point on, you just use HMAC to derive your secret keys.
1395
01:25:44,272 --> 01:25:49,932
So the ZK proofs really only need to apply to this second step, the one that's only using HMAC.
1396
01:25:50,132 --> 01:25:55,992
So that was actually quite lucky that we don't keep using PBKDF2 throughout key derivation.
1397
01:25:56,612 --> 01:26:03,272
And so in principle, when we talk about proving seed knowledge, it's not really proof knowledge of the seed phrase.
1398
01:26:03,432 --> 01:26:06,732
It's proof of knowledge of what comes out of PBKDF2.
1399
01:26:06,732 --> 01:26:07,992
So just to be precise.
1400
01:26:07,992 --> 01:26:08,512
Okay.
1401
01:26:08,972 --> 01:26:14,152
Yeah, and that actually seems like a good backup to go.
1402
01:26:14,472 --> 01:26:18,972
The one thing I would be a little worried about is the BIP 361 two-year proposal.
1403
01:26:19,472 --> 01:26:22,812
So effectively, we'll be giving people two years to transition.
1404
01:26:23,632 --> 01:26:25,452
That seems a little short.
1405
01:26:25,592 --> 01:26:26,872
That's too tight, in your opinion.
1406
01:26:27,352 --> 01:26:28,732
What would you like to see there?
1407
01:26:28,832 --> 01:26:29,992
How much time would you like to give people to transition?
1408
01:26:29,992 --> 01:26:30,532
Good, good, good.
1409
01:26:30,552 --> 01:26:35,912
So Optimism, for example, they announced 2035 as a deprecation date.
1410
01:26:35,912 --> 01:26:37,412
And to me, that seems—
1411
01:26:37,412 --> 01:26:37,932
Way more reasonable.
1412
01:26:37,992 --> 01:26:40,092
Yeah, that seems like it gives people a lot of time.
1413
01:26:40,232 --> 01:26:40,492
And so.
1414
01:26:40,772 --> 01:26:46,252
But that, you know, again, there's always this argument like, well, what if the quantum computer arises in 2029?
1415
01:26:46,652 --> 01:26:53,312
I mean, that seems to be I mean, you hear, you know, it depends on sort of like how prepared we want to be relative to the risk associated.
1416
01:26:53,452 --> 01:26:54,792
Do you think 2035 is.
1417
01:26:55,572 --> 01:26:56,912
It seems reasonable.
1418
01:26:57,132 --> 01:27:00,672
And the interesting thing is there are proposals.
1419
01:27:00,892 --> 01:27:03,532
There are some other proposals that I find really intriguing.
1420
01:27:04,092 --> 01:27:09,692
So the one that I, for example, really like is this proposal of, you know, commit, delay, reveal.
1421
01:27:10,112 --> 01:27:10,452
Taj.
1422
01:27:10,632 --> 01:27:11,412
Taj's proposal.
1423
01:27:11,652 --> 01:27:12,912
I really forget what that's called.
1424
01:27:13,492 --> 01:27:16,332
Well, he has a nickname for it called Lifeboat.
1425
01:27:16,492 --> 01:27:18,412
I actually had him on the show and he talked about it.
1426
01:27:18,532 --> 01:27:18,932
Oh, it's all right.
1427
01:27:18,992 --> 01:27:21,692
Yeah, I think that's a pretty interesting proposal.
1428
01:27:21,692 --> 01:27:29,952
So basically what happens there is we use the fact that the hash of your public key is on chain and the actual public key becomes the secrets.
1429
01:27:30,652 --> 01:27:30,732
Yeah.
1430
01:27:30,732 --> 01:27:36,692
It means you can't move coins quite as quickly, but it's like a nice little backup plan and it's relatively unobtrusive.
1431
01:27:37,232 --> 01:27:41,552
Exactly, exactly. So I thought that was pretty clever.
1432
01:27:42,092 --> 01:27:48,672
I guess there's now a new proposal for using Bitcoin scripts to even implement some post-quantum schemes.
1433
01:27:49,332 --> 01:27:50,652
But those are a bit more painful.
1434
01:27:52,072 --> 01:27:59,132
But even working out, I mean, I wish someone would actually literally work out all the details of commit, delay, reveal.
1435
01:27:59,132 --> 01:28:01,832
there's a lot of interesting questions there.
1436
01:28:01,952 --> 01:28:04,572
When you have to post a commitment to your transaction
1437
01:28:04,572 --> 01:28:06,732
on chain ahead of time,
1438
01:28:07,172 --> 01:28:07,932
well, who pays for that?
1439
01:28:07,932 --> 01:28:08,612
How do you pay for that?
1440
01:28:09,112 --> 01:28:09,932
Right, you don't have any,
1441
01:28:10,032 --> 01:28:11,412
all your UTXOs are locked.
1442
01:28:11,492 --> 01:28:13,292
So how do you pay for that?
1443
01:28:14,232 --> 01:28:16,432
And so one proposal is,
1444
01:28:16,792 --> 01:28:18,072
you know, maybe you go to Coinbase
1445
01:28:18,072 --> 01:28:20,772
and Coinbase creates like a $1 UTXO for you
1446
01:28:20,772 --> 01:28:23,412
that you can just pay for posting your commitments
1447
01:28:23,412 --> 01:28:25,272
is one option.
1448
01:28:25,272 --> 01:28:49,260
And so there a lot of mechanics to go into making that work And so I wish somebody would actually flesh that out completely Just to close the loop on the Satoshi conversation you said we have a solution to how people can retrieve their coins if coins are deprecated quantum vulnerable coins are deprecated as long as those addresses were created post and people obviously have access to their seed phrases
1449
01:28:49,260 --> 01:29:06,700
There are, I think, almost close to 2 million coins in total, but probably not that many actually active users or actual key holders in the category of, you know, the Satoshi's, proper Satoshi's coins category where we don't have seed phrases and that wouldn't be possible.
1450
01:29:07,200 --> 01:29:16,580
Do you have sort of an ethical or sort of a philosophical point of view about how we should handle, you know, potentially deprecating coins where retrieval might not be possible?
1451
01:29:17,140 --> 01:29:17,740
Yeah, yeah.
1452
01:29:17,780 --> 01:29:19,320
I think that's a great question.
1453
01:29:20,480 --> 01:29:22,560
So let's play this out.
1454
01:29:22,820 --> 01:29:25,040
I think it's pretty clear how things are going to go.
1455
01:29:25,040 --> 01:29:36,720
And so this question of what to do about abandoned assets is one that will probably will cause a lot of arguments and contention in the community.
1456
01:29:37,780 --> 01:29:39,960
And I don't think there's no right or wrong.
1457
01:29:40,480 --> 01:29:45,360
And so I think there's quite a good possibility that the community will not reach agreement.
1458
01:29:45,860 --> 01:29:48,580
What happens in Bitcoin when the community does not reach agreement?
1459
01:29:48,980 --> 01:29:50,100
We've been to this movie before.
1460
01:29:50,820 --> 01:29:51,020
Yes.
1461
01:29:51,420 --> 01:29:52,060
The F word.
1462
01:29:52,200 --> 01:29:53,580
The F word, which we don't want to say.
1463
01:29:54,220 --> 01:29:54,500
Right.
1464
01:29:54,980 --> 01:29:56,540
Now, OK, fine.
1465
01:29:56,600 --> 01:29:57,480
So let's play this out.
1466
01:29:57,740 --> 01:30:02,600
Suppose Bitcoin forks and in one fork they're deprecated and the other fork they're not deprecated.
1467
01:30:03,260 --> 01:30:05,780
The question is which fork will survive?
1468
01:30:06,480 --> 01:30:09,100
Well, that depends on the asset holders.
1469
01:30:09,100 --> 01:30:10,840
Which fork do they decide to use?
1470
01:30:11,380 --> 01:30:13,600
And which fork do you think the asset holders will end up using?
1471
01:30:14,200 --> 01:30:15,680
Obviously the one with burned coins.
1472
01:30:15,860 --> 01:30:18,680
Obviously the ones with burned coins because then their coins are worth more.
1473
01:30:19,420 --> 01:30:21,640
And so it's kind of-
1474
01:30:21,640 --> 01:30:22,180
Substantively more.
1475
01:30:22,360 --> 01:30:23,420
Yeah, exactly.
1476
01:30:23,500 --> 01:30:27,200
So it's kind of clear that the fork that does deprecate is the one that will survive.
1477
01:30:27,360 --> 01:30:29,800
The economic incentives are just going to be what they're going to be.
1478
01:30:29,880 --> 01:30:31,300
It's like, why are we even having this discussion?
1479
01:30:31,740 --> 01:30:36,420
And so my question to the community then is if we can kind of play this game in our heads
1480
01:30:36,420 --> 01:30:40,440
and it's pretty clear what the outcome is going to be, why do we have to play the game?
1481
01:30:40,440 --> 01:30:40,760
Right.
1482
01:30:40,760 --> 01:30:47,820
Like, why fork, which will be very painful if the outcome is, like, pretty much, you know, kind of written on the wall.
1483
01:30:48,120 --> 01:30:48,260
Yeah.
1484
01:30:48,400 --> 01:30:48,600
Right.
1485
01:30:48,960 --> 01:30:50,040
So I think we're kind of in agreement.
1486
01:30:50,160 --> 01:30:51,420
We're on the same page.
1487
01:30:51,840 --> 01:30:55,200
I'm like, let's do this the easier, softer way, guys.
1488
01:30:55,400 --> 01:30:55,640
Yeah.
1489
01:30:55,860 --> 01:30:57,000
Is sort of my point of view.
1490
01:30:57,080 --> 01:30:57,340
Okay.
1491
01:30:57,560 --> 01:30:57,920
Interesting.
1492
01:30:58,080 --> 01:30:58,200
Yeah.
1493
01:30:58,260 --> 01:30:59,220
So that's my argument.
1494
01:30:59,360 --> 01:31:06,980
Again, other people can have other arguments, but that seems to be, like, how things will play out.
1495
01:31:07,040 --> 01:31:09,820
And so if we know how they're going to play out, why do we need to play the game?
1496
01:31:10,380 --> 01:31:10,980
Fair enough.
1497
01:31:11,300 --> 01:31:12,120
I'm with you.
1498
01:31:13,360 --> 01:31:16,440
This has been a super interesting conversation.
1499
01:31:16,580 --> 01:31:17,280
I'm just checking the time.
1500
01:31:17,420 --> 01:31:18,200
No, I think I know.
1501
01:31:18,460 --> 01:31:20,540
Well, I had a feeling.
1502
01:31:20,540 --> 01:31:22,740
By the way, there's a million other things I would love to talk about.
1503
01:31:22,860 --> 01:31:24,680
So much we could talk about.
1504
01:31:25,320 --> 01:31:27,160
Maybe we'll do a part two on my next trip.
1505
01:31:27,740 --> 01:31:36,280
But is there anything like major that you feel like we didn't cover that you want to make sure that we cover while we have like a few extra minutes to spare?
1506
01:31:36,280 --> 01:31:46,720
Yeah, maybe just in one minute, I'll say, look, there are so many exciting cryptographic questions in the blockchain space, in Bitcoin and Ethereum and all these blockchains.
1507
01:31:47,180 --> 01:31:51,120
Maybe I'll just mention things that I'm really interested in now and stuff that we're working on.
1508
01:31:51,560 --> 01:31:56,840
So one question that I find really fascinating is this question of encrypted mempools.
1509
01:31:57,440 --> 01:32:00,960
And the reason we want to have an encrypted mempool, of course, is to prevent MEV, right?
1510
01:32:00,960 --> 01:32:03,840
So the point is, I submit my transaction encrypted.
1511
01:32:03,840 --> 01:32:08,920
it only gets decrypted after it's finalized on chain.
1512
01:32:09,300 --> 01:32:11,320
So basically it prevents front running, right?
1513
01:32:11,820 --> 01:32:14,020
Not prevents, but makes it harder to do front running.
1514
01:32:14,160 --> 01:32:16,080
It turns out with spamming, you can still front run,
1515
01:32:16,400 --> 01:32:16,900
but it's harder.
1516
01:32:17,060 --> 01:32:19,020
Which is just sort of in Ethereum land, again,
1517
01:32:19,080 --> 01:32:21,260
because most of my audience are Bitcoiners.
1518
01:32:21,320 --> 01:32:23,080
In Ethereum land, that's just the way things are.
1519
01:32:23,800 --> 01:32:26,800
Like MEV is just like a normal part of life
1520
01:32:26,800 --> 01:32:28,280
and there are just economics
1521
01:32:28,280 --> 01:32:31,260
that sort of just play out around MEV as an inevitable.
1522
01:32:31,840 --> 01:32:37,420
Bitcoiners are obviously terrified of MEV coming to Bitcoin with layer twos and meta protocols, etc.
1523
01:32:38,440 --> 01:32:43,120
By the way, quantum computers might cause MEV to happen because there's an incentive.
1524
01:32:44,280 --> 01:32:45,260
Maybe I'll just explain it.
1525
01:32:45,260 --> 01:32:46,140
Like a reorg incentive?
1526
01:32:46,220 --> 01:32:47,020
A reorg incentive.
1527
01:32:47,020 --> 01:32:51,000
Once your transaction is posted, now you've revealed your public key.
1528
01:32:51,520 --> 01:32:56,200
And now there's an incentive to reorg the chain so that someone could actually exploit your public key.
1529
01:32:56,720 --> 01:32:58,560
So it could be that, oddly enough,
1530
01:32:58,640 --> 01:33:01,480
quantum actually might cause MEV to happen.
1531
01:33:01,620 --> 01:33:02,700
This is another big topic
1532
01:33:02,700 --> 01:33:04,600
that I don't think people are talking about enough
1533
01:33:04,600 --> 01:33:07,880
and that I hope people are talking about more.
1534
01:33:07,920 --> 01:33:09,920
My hope is that by the time QDA happens,
1535
01:33:10,220 --> 01:33:11,800
Bitcoin will have already transitioned.
1536
01:33:12,540 --> 01:33:13,700
And so this will not be an issue.
1537
01:33:13,780 --> 01:33:15,220
But if it does come up,
1538
01:33:15,220 --> 01:33:19,100
then people do need to worry about the reorg issue.
1539
01:33:19,520 --> 01:33:22,040
Well, yeah, so in the question of encrypted mempools,
1540
01:33:22,540 --> 01:33:25,980
that raises so many beautiful cryptography questions.
1541
01:33:25,980 --> 01:33:28,320
Maybe I'll mention just a few very, very briefly.
1542
01:33:28,320 --> 01:33:32,320
So the idea is, again, we're going to split the decryption key
1543
01:33:32,320 --> 01:33:35,740
across the validators or miners, whatever you want to call them.
1544
01:33:35,740 --> 01:33:50,888
And so we kind of doing threshold decryption now Threshold decryption is an old topic that been studied I written many papers on it It been studied for 40 years now Turns out because of encrypted mempool all of a sudden all these new questions in this 40 area are coming up that nobody has
1545
01:33:50,888 --> 01:33:59,108
ever thought to ask before. For example, there's this question like, suppose I have a block of
1546
01:33:59,108 --> 01:34:04,648
transactions. So I have a bunch of transactions in a mempool. A subset of them go into the block.
1547
01:34:04,988 --> 01:34:06,908
I want to decrypt only that subset.
1548
01:34:07,328 --> 01:34:10,748
The naive thing to do is to go and decrypt them one by one.
1549
01:34:11,188 --> 01:34:16,028
But that means that I have to now post decryption shares for each one of those transactions.
1550
01:34:16,028 --> 01:34:18,228
And it's a lot of data that's going to go on chain.
1551
01:34:18,788 --> 01:34:18,908
Yeah.
1552
01:34:19,408 --> 01:34:22,428
A much better way to do things is to do what's called batch decryption.
1553
01:34:22,588 --> 01:34:25,708
I have a set of, I don't know, N transactions.
1554
01:34:26,148 --> 01:34:28,688
And I want to decrypt a subset of those transactions.
1555
01:34:29,068 --> 01:34:30,428
That's called a batch decryption.
1556
01:34:30,428 --> 01:34:43,848
What I will do is, or what the miners or validators will do, is they'll publish a secret key that will decrypt, a short secret key that will decrypt the transactions in the block and no other transactions.
1557
01:34:44,448 --> 01:34:44,508
Yeah.
1558
01:34:44,808 --> 01:34:53,148
So this is now called batch threshold decryption, super active area of research that's purely motivated by this question of encrypted mempools.
1559
01:34:53,148 --> 01:35:02,288
Would you, in that example, just so that I can wrap my brain around this because this is a totally new idea for me, would you theoretically be choosing what to decrypt based on fees?
1560
01:35:03,428 --> 01:35:05,968
No, no. It's based on what the block proposer proposes.
1561
01:35:06,628 --> 01:35:08,108
Yeah. So whoever builds the block.
1562
01:35:08,268 --> 01:35:13,328
But in Bitcoin, you're building blocks ostensibly based on fees, right?
1563
01:35:13,328 --> 01:35:18,888
Sure, sure, sure. In some sense, those things are orthogonal. You build your block however you want to.
1564
01:35:19,148 --> 01:35:19,308
Okay.
1565
01:35:19,468 --> 01:35:20,048
The thing is.
1566
01:35:20,328 --> 01:35:22,208
But that would be public information.
1567
01:35:22,428 --> 01:35:22,588
Exactly.
1568
01:35:22,588 --> 01:35:24,168
That's not something that would be encrypted.
1569
01:35:24,448 --> 01:35:24,588
Exactly.
1570
01:35:24,588 --> 01:35:29,188
The reason I'm asking this to get to the point is like, would you not be able to guess the
1571
01:35:29,188 --> 01:35:33,328
value of the underlying transaction based on the fees that are being paid to execute
1572
01:35:33,328 --> 01:35:33,588
them?
1573
01:35:34,248 --> 01:35:36,628
So the fees might actually be public.
1574
01:35:36,928 --> 01:35:40,388
What the transactions do is what's being hidden.
1575
01:35:40,868 --> 01:35:41,128
Right.
1576
01:35:41,288 --> 01:35:41,508
Yeah.
1577
01:35:41,628 --> 01:35:45,208
But like, couldn't you like potentially, like if somebody is paying a huge amount of fees
1578
01:35:45,208 --> 01:35:48,388
to get a transaction, you might think that's a really valuable transaction.
1579
01:35:48,568 --> 01:35:50,168
I bet that that's the one that I should.
1580
01:35:50,168 --> 01:35:50,728
That's a great question.
1581
01:35:50,948 --> 01:35:51,108
Okay.
1582
01:35:51,108 --> 01:35:56,308
What you're asking is, do encrypted mempools, do they solve the problem completely?
1583
01:35:56,728 --> 01:35:57,068
Right.
1584
01:35:57,268 --> 01:36:02,408
Like, you're still going to have, if you know what the fees are, you're kind of going to be able to guess which transactions are more valuable anyway.
1585
01:36:03,288 --> 01:36:03,628
Absolutely.
1586
01:36:03,808 --> 01:36:06,568
So encrypted mempools, they don't completely solve the MEV problem.
1587
01:36:06,688 --> 01:36:07,668
I'm the first to admit that.
1588
01:36:07,768 --> 01:36:08,128
Okay, okay.
1589
01:36:08,868 --> 01:36:10,408
But they are a step in the right direction.
1590
01:36:10,528 --> 01:36:14,188
This is one of these situations where you don't want perfect to be the enemy of the good.
1591
01:36:14,288 --> 01:36:14,668
Fair enough.
1592
01:36:14,908 --> 01:36:15,108
Yeah.
1593
01:36:15,228 --> 01:36:17,088
So they're a step in the right direction.
1594
01:36:17,088 --> 01:36:23,108
Once we have encrypted mempools, we can do lots of other things to solve other MEV questions.
1595
01:36:23,368 --> 01:36:23,708
Fair enough.
1596
01:36:23,868 --> 01:36:25,928
But then the question is, how do we implement these encrypted mempools?
1597
01:36:26,168 --> 01:36:26,888
And I could go on and on.
1598
01:36:26,948 --> 01:36:27,768
So batch decryption is one.
1599
01:36:27,808 --> 01:36:28,588
Maybe I'll just say the words.
1600
01:36:28,948 --> 01:36:31,828
Batch decryption is a new problem that we have to work on.
1601
01:36:31,908 --> 01:36:33,448
That's a pretty thriving area of research.
1602
01:36:34,348 --> 01:36:40,588
It turns out there's something called a decryption context that comes up in the context of encrypted mempools.
1603
01:36:40,868 --> 01:36:42,828
Something that's very natural once you say it.
1604
01:36:42,828 --> 01:36:47,488
But nobody thought of saying it until blockchain said, we want to do encrypted mempools.
1605
01:36:47,768 --> 01:37:02,728
And finally, the third one that's really fascinating is, well, once you have an encrypted mempool, the searchers, you know, the guys that are trying to front run people, they could go to the miners and say, hey, sell us your decryption key.
1606
01:37:02,788 --> 01:37:05,408
We'll pay you such and such if you sell us your decryption key.
1607
01:37:05,968 --> 01:37:08,728
And the miners could sell the decryption key.
1608
01:37:08,788 --> 01:37:10,528
Nobody would ever know that that actually happened.
1609
01:37:10,528 --> 01:37:11,048
Yeah.
1610
01:37:11,048 --> 01:37:20,888
So what we're working on is what's called traceable threshold decryption, where if you sell your secret key, I can actually figure out that it's you who did it.
1611
01:37:20,948 --> 01:37:22,708
And then you can be slashed in some way.
1612
01:37:22,708 --> 01:37:23,708
Who are you working on this, Wes?
1613
01:37:24,328 --> 01:37:30,588
So first of all, I should say, this now has become a pretty active area of research in the community.
1614
01:37:31,128 --> 01:37:33,188
Of course, I work with my students and my collaborators.
1615
01:37:33,568 --> 01:37:33,808
Okay.
1616
01:37:34,208 --> 01:37:35,908
So there's several people working on this.
1617
01:37:35,908 --> 01:37:36,268
Yeah, yeah, yeah.
1618
01:37:36,268 --> 01:37:37,308
This is a major topic.
1619
01:37:37,308 --> 01:37:41,788
I would say there's like by now there's probably a dozen papers on these three questions.
1620
01:37:42,008 --> 01:37:46,328
And most of the research, I presume, is happening more on the Ethereum front, but it would have implications for Bitcoin.
1621
01:37:46,768 --> 01:37:48,248
Yes. Yes, absolutely. Absolutely.
1622
01:37:48,568 --> 01:37:48,868
Interesting.
1623
01:37:49,028 --> 01:37:53,948
So that's one example in CryptoMimples. Super exciting, super fascinating for a cryptographer like me.
1624
01:37:54,068 --> 01:37:56,448
This is, again, why I love the space so much.
1625
01:37:56,488 --> 01:37:57,988
Always new problems to solve.
1626
01:37:58,208 --> 01:38:00,728
Always new areas of research to execute.
1627
01:38:00,728 --> 01:38:08,008
In the area of zero-knowledge proofs, there's a ton happening both in better proofs and new applications.
1628
01:38:08,288 --> 01:38:10,708
I could go on and on and on about applications of zero-knowledge proofs.
1629
01:38:10,828 --> 01:38:11,008
Okay.
1630
01:38:11,208 --> 01:38:16,948
And finally, I would say even in the area of threshold Schnorr signatures, there are a lot of interesting ideas.
1631
01:38:17,068 --> 01:38:25,988
I'll just throw out one concept, something called an exponent VRF, EVRF, which is something that we worked on that potentially can improve threshold Schnorr.
1632
01:38:26,228 --> 01:38:28,688
Hopefully, people can look it up and see what that's about.
1633
01:38:28,828 --> 01:38:29,168
Awesome.
1634
01:38:29,168 --> 01:38:31,428
Well, I have one final question.
1635
01:38:31,548 --> 01:38:38,668
This is our final foray question, which will be, you know, just kind of wrapping up in summary the quantum conversation.
1636
01:38:38,808 --> 01:38:45,288
I think, you know, there are some folks out there who are just bearish that you've mentioned several times that this is going to be a painful transition.
1637
01:38:45,428 --> 01:38:58,856
And there are people out there who are just bearish that Bitcoin can even survive it Are you optimistic that Bitcoin will solve it Why or why not I am totally optimistic that Bitcoin will solve it That is it insane to say that Bitcoin will
1638
01:38:58,856 --> 01:39:02,516
not solve the quantum problem. It is? That's how you feel? That is insane. Of course,
1639
01:39:02,596 --> 01:39:08,316
Bitcoin will survive it. And of course, Bitcoin will solve it. Okay. So that goes without saying.
1640
01:39:08,316 --> 01:39:10,856
What gives you that confidence? What do you want to communicate about?
1641
01:39:10,856 --> 01:39:15,256
We know where to go. We need to move to post-quantum addresses, post-quantum signatures.
1642
01:39:15,256 --> 01:39:37,696
We know where to go. The only, you know, everything we've been discussing in this podcast is really just kind of technical nuances of exactly what should you do. But the big picture is very well known. We know what to do. So anyone who is worried that quantum is going to affect the security of blockchains is wrong.
1643
01:39:38,236 --> 01:39:40,656
Overly paranoid, basically, or just.
1644
01:39:40,656 --> 01:39:58,216
The post-quantum technology exists. You know, we have many, I guess, it's actually the fact that we're even having this conversation says we have many solutions and we're just debating which path to take in order to solve the problem. But there are definitely this will get solved and the blockchains will survive.
1645
01:39:58,336 --> 01:40:07,036
Do you have a message that you want to communicate to like the developers and builders that are actually trying to solve this? Like something you want the builders and developers to remember?
1646
01:40:07,036 --> 01:40:24,816
Yes, actually two sentences. The first one I've already said, which is don't panic, but don't ignore. The other one is if you try to aggressively move to a post-quantum architecture, like for example, by 2029, I think that would be a mistake for the blockchain. I think we need to take our time.
1647
01:40:24,816 --> 01:40:37,416
And the reason is that a hasty transition to post-quantum, in my mind, is more likely to cause a catastrophic bug than it is to be.
1648
01:40:37,756 --> 01:40:43,856
It's more, you know, higher probability that we'll end up with a catastrophic bug than we'll be attacked by a quantum computer.
1649
01:40:44,476 --> 01:40:49,576
On that note, would you support a BIP-361 that just had longer timelines for migration?
1650
01:40:49,576 --> 01:40:54,516
Like, is that your primary criticism, BIP-361? Is that the timeline is just too compressed for migration?
1651
01:40:54,816 --> 01:41:04,856
Yeah, I think BIP-361, I think there are a bunch of elements missing from BIP-361 because BIP-361 doesn't specify post-quantum signatures.
1652
01:41:05,316 --> 01:41:07,816
So there are a bunch of elements missing from BIP-361.
1653
01:41:07,896 --> 01:41:09,456
I wish it was a more complete proposal.
1654
01:41:09,916 --> 01:41:14,776
Well, I think that the proposals will ultimately, and we kind of talked about this earlier, will be more modular, right?
1655
01:41:14,836 --> 01:41:18,476
Like BIP-361 is kind of addressing the Satoshi's coins issues specifically.
1656
01:41:18,476 --> 01:41:25,716
And I think there will be like separate BIPs for, you know, signature schemes and BIP 361, Payton Merkle route, et cetera.
1657
01:41:25,836 --> 01:41:26,776
I mean, do you?
1658
01:41:27,096 --> 01:41:27,856
Yeah, that's the right path.
1659
01:41:27,916 --> 01:41:30,456
You think that is the right path, the modular approach?
1660
01:41:30,816 --> 01:41:31,576
Yes, yes, of course.
1661
01:41:31,656 --> 01:41:33,456
And we need to be, like I said, we should take our time.
1662
01:41:33,916 --> 01:41:34,636
We shouldn't rush.
1663
01:41:36,016 --> 01:41:37,636
We should debate these things.
1664
01:41:37,916 --> 01:41:40,016
And again, my opinion is we have time.
1665
01:41:41,076 --> 01:41:43,696
Not forever, but we have the time.
1666
01:41:44,276 --> 01:41:46,976
We should decide on a plan of action.
1667
01:41:46,976 --> 01:41:51,256
And we should agree by a reasonable point on what to do.
1668
01:41:51,296 --> 01:41:56,236
And then it's just a matter of executing and then waiting for people to transition and then deprecating.
1669
01:41:56,236 --> 01:42:03,376
When would you like to see a plan, given how much time you assume it will take to actually execute that kind of plan?
1670
01:42:03,856 --> 01:42:04,376
Oh, my God.
1671
01:42:04,916 --> 01:42:06,596
Like, what's the timeline to just have a plan?
1672
01:42:06,636 --> 01:42:07,636
Oh, I see. I see.
1673
01:42:09,676 --> 01:42:13,396
You know, I'm going to play the academic card here.
1674
01:42:13,856 --> 01:42:14,876
I don't know.
1675
01:42:14,876 --> 01:42:17,676
that is really up to the community.
1676
01:42:18,296 --> 01:42:20,476
The one thing that worries me a little bit
1677
01:42:20,476 --> 01:42:24,736
is there's some quantum fatigue among Bitcoin Core.
1678
01:42:25,276 --> 01:42:26,816
It's been discussed so much
1679
01:42:26,816 --> 01:42:30,636
that people are a little bit tired of talking about it.
1680
01:42:31,116 --> 01:42:33,836
And I don't think that's the right attitude.
1681
01:42:34,476 --> 01:42:36,776
We do need to kind of decide on a plan.
1682
01:42:38,516 --> 01:42:41,736
Look, hopefully the community can come together on a plan.
1683
01:42:41,856 --> 01:42:43,356
Let's let more BIPs.
1684
01:42:43,356 --> 01:42:45,816
let's put things in writing, right?
1685
01:42:45,876 --> 01:42:47,936
Let's kind of, instead of it just being
1686
01:42:47,936 --> 01:42:50,076
informal conversations and blog posts,
1687
01:42:50,116 --> 01:42:51,096
let's put things in writing.
1688
01:42:51,476 --> 01:42:53,716
I thought BIP 360 was a step in the right direction.
1689
01:42:54,556 --> 01:42:57,956
I thought BIP 361 is the fact that they even wrote
1690
01:42:57,956 --> 01:42:59,636
that it was a step in the right direction.
1691
01:43:00,356 --> 01:43:01,436
Let's have more of that.
1692
01:43:02,716 --> 01:43:04,896
You know, then the question of whether to deploy or not,
1693
01:43:04,996 --> 01:43:07,276
hopefully, you know, that can be resolved
1694
01:43:07,276 --> 01:43:08,476
by the end of the decade.
1695
01:43:09,016 --> 01:43:10,476
And then we'll have the time,
1696
01:43:10,676 --> 01:43:12,116
then we'll allocate the time to transition.
1697
01:43:12,116 --> 01:43:18,696
Sounds like you're saying by end of the decade, we should have a pretty clear plan and execution should be underway by 2030.
1698
01:43:19,236 --> 01:43:20,216
At the latest.
1699
01:43:20,416 --> 01:43:20,936
At the latest.
1700
01:43:21,456 --> 01:43:21,556
Yeah.
1701
01:43:21,896 --> 01:43:22,476
Fair enough.
1702
01:43:23,176 --> 01:43:24,676
Dan, thank you so much for coming on.
1703
01:43:24,756 --> 01:43:25,276
This was great.
1704
01:43:25,376 --> 01:43:28,636
I know there are so many people who are curious to hear your thoughts on this very topic.
1705
01:43:28,876 --> 01:43:32,436
So I really, really appreciate you sharing all of this with us.
1706
01:43:32,716 --> 01:43:34,756
And yeah, anything in particular?
1707
01:43:34,856 --> 01:43:38,676
I know you had mentioned a couple things that you want to make sure people Google or chat GBT afterwards.
1708
01:43:38,676 --> 01:43:42,796
words, anything in particular you want to make sure people or that you want to encourage
1709
01:43:42,796 --> 01:43:44,216
people to just take a look at.
1710
01:43:44,336 --> 01:43:46,476
Yeah, I think we covered it during the hour.
1711
01:43:46,476 --> 01:43:47,196
We'll link to everything.
1712
01:43:47,236 --> 01:43:50,076
I would say, again, thank you so much for running this podcast.
1713
01:43:50,456 --> 01:43:52,696
I think it's a great service for the Bitcoin community.
1714
01:43:53,016 --> 01:43:53,316
Thank you.
1715
01:43:53,536 --> 01:43:55,756
And it's, yeah, it's fun to have this technical conversation.
1716
01:43:56,096 --> 01:43:56,356
Awesome.
1717
01:43:56,516 --> 01:43:56,836
Thank you.
1718
01:43:56,976 --> 01:43:57,376
Thanks, Dan.
1719
01:43:57,516 --> 01:43:58,316
Yeah, my pleasure.