ABOUT THIS EPISODE
In this episode, Rob and I sit down with Brandon Black (aka Rearden Code) for a deep dive into the quantum-computing debate around Bitcoin. We unpack why Brandon thinks the more useful framing is not “post-quantum” but “post-secp256k1,” and why Bitcoiners should care less about sci-fi narratives and more about understanding the actual cryptographic assumptions that protect coins today. Along the way, we revisit the now-legendary conference panel on quantum risk, talk through exposed pubkeys, xpub leakage, multisig, Taproot, Lightning force closes, and the difference between a theoretical break and an economically viable attack.
We also spend a lot of time sizing risk correctly. Brandon helps us separate slow, visible cryptographic degradation from the far less likely “everything breaks tomorrow” scenario, and we explore how incentives change depending on whether the attacker wants profit, strategic advantage, or chaos. The conversation eventually zooms all the way out to math, physics, and engineering: Shor’s algorithm may exist on paper, but building a machine that can actually matter for Bitcoin is still a very different question. If you want a rigorous, grounded conversation about quantum threats, elliptic curves, MuSig2, FROST, and how to think clearly instead of panicking, this is a great one.
The legendary panel: https://www.youtube.com/watch?v=wbJkODcrz7Q
- Magic Internet Math: https://magicinternetmath.com/
- Brandon Black speaker profile: https://sv23.adoptingbitcoin.org/speakers/brandonblack/
- James O'Beirne: https://jameso.be/
- BIP 360: https://github.com/bitcoin/bips/blob/master/bip-0360.mediawiki
- BIP 327 (MuSig2): https://github.com/bitcoin/bips/blob/master/bip-0327.mediawiki
- BIP 340 (Schnorr Signatures for secp256k1): https://github.com/bitcoin/bips/blob/master/bip-0340.mediawiki
- BIP 341 (Taproot): https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki
- BIP 32 (Hierarchical Deterministic Wallets): https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki
- BIP 39 (Mnemonic code for generating deterministic keys): https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki
- FROST Protocol (RFC 9591): https://www.rfc-editor.org/rfc/rfc9591.html
SHOW NOTES 🔗
TRANSCRIPT 🔗
NOTE
Transcription provided by Podhome.fm
Created: 7/19/2026 5:42:33 PM
Duration: 5010.573
Channels: 1
1
00:00:00.719 --> 00:00:01.839
All right.
2
00:00:02.159 --> 00:00:05.360
Welcome back to the Magic Internet Math podcast.
3
00:00:05.839 --> 00:00:07.600
I am Brian, the host.
4
00:00:08.240 --> 00:00:09.519
Rob, the host.
5
00:00:10.080 --> 00:00:19.914
We have such an awkward introduction. Which one's the host? We gotta make sure the clankers know who we are because we just don't I think by nomenclature, I'm the cohost.
6
00:00:20.634 --> 00:00:30.310
By nomenclature Casey and Aaron situation? Yeah. Like, I'm I think I'm definitely the cohost. Brian, this is I am more just a mathematical shaman guiding you on your journey.
7
00:00:31.190 --> 00:00:33.910
Just to be clear. Yes. Thank you. Yeah.
8
00:00:34.470 --> 00:00:35.910
We got a guest today.
9
00:00:36.150 --> 00:00:37.910
I'm pretty excited about it.
10
00:00:39.545 --> 00:00:41.385
We have Brandon
11
00:00:41.865 --> 00:00:42.665
Reardon.
12
00:00:43.145 --> 00:00:46.825
That's me. Is that okay? Yeah. Well, you know, Brandon Black, Reardon.
13
00:00:47.065 --> 00:00:53.145
Reardon Code. I have all these names. Now I figured this out of my own, by the way. I figured out. I connected.
14
00:00:53.305 --> 00:00:53.625
Yeah.
15
00:00:54.290 --> 00:00:59.410
I was pretty proud of myself. I'll be honest. I was pretty dang proud of myself when I figured that out.
16
00:01:00.770 --> 00:01:02.370
But it's really great to have you.
17
00:01:03.170 --> 00:01:06.210
We kind of just know you. We know you from
18
00:01:07.994 --> 00:01:10.314
Bitcoin technical life, I guess.
19
00:01:11.195 --> 00:01:11.835
And,
20
00:01:12.715 --> 00:01:22.440
you know, we are in a group chat. And I remember I was, you know, we were talking before the show, I remember listening to the episode of TFTC
21
00:01:23.400 --> 00:01:25.640
where with Brandon Black,
22
00:01:26.440 --> 00:01:31.800
and I was driving home driving home from Nashville. I was in Nashville for grassroots. If you guys
23
00:01:32.600 --> 00:01:33.400
remember,
24
00:01:33.640 --> 00:01:40.095
there's a there's an episode on where Rob and I did a live magic internet math episode in Nashville.
25
00:01:40.335 --> 00:01:44.575
So then very next day, I'm driving home and I got that like, oh,
26
00:01:45.295 --> 00:01:50.495
TFTC is a new episode and it's about quantum like that's kind of up my alley.
27
00:01:51.215 --> 00:01:51.455
And
28
00:01:52.750 --> 00:01:54.109
with Brandon Black,
29
00:01:54.590 --> 00:02:02.109
and I don't know, like, I feel like I heard you for about forty minutes and I had to pull over and I started texting Rob. I'm like, is that weird?
30
00:02:02.909 --> 00:02:04.429
It sounds like what
31
00:02:05.149 --> 00:02:06.429
he would sound like.
32
00:02:07.455 --> 00:02:10.175
And Rob's like, yep. Oh, man, did I feel good?
33
00:02:10.415 --> 00:02:12.975
I felt like I felt like a genius.
34
00:02:13.135 --> 00:02:13.615
Anyway,
35
00:02:14.575 --> 00:02:16.975
Reardon, man, you are kind of a genius.
36
00:02:18.095 --> 00:02:20.255
And so you're somebody I do look up to.
37
00:02:22.379 --> 00:02:24.300
I'm still doing the introduction here.
38
00:02:25.099 --> 00:02:28.460
We met in Vegas in person. And that was terrific.
39
00:02:28.540 --> 00:02:35.340
We got to spend a little bit of time. You said something very funny to me. I know you don't remember it. And maybe you'll remember it when I tell you now.
40
00:02:35.580 --> 00:02:36.220
But
41
00:02:36.459 --> 00:02:39.365
I forgot what I was, you know, we're at the beefsteak.
42
00:02:39.445 --> 00:02:40.405
And I was
43
00:02:41.045 --> 00:02:42.245
having a good time
44
00:02:42.565 --> 00:02:45.045
making fun of something. Can't remember what.
45
00:02:45.365 --> 00:02:46.005
And
46
00:02:46.565 --> 00:02:48.645
at some point, you looked up and you said,
47
00:02:49.205 --> 00:02:49.685
fundamentals.
48
00:02:50.645 --> 00:02:54.130
You're as pithy in person as you are online. I
49
00:02:55.570 --> 00:02:57.890
think you meant that as a compliment. I didn't know
50
00:02:58.610 --> 00:03:00.530
what the word pithy meant. I had go look it up.
51
00:03:01.410 --> 00:03:04.130
But it was that I felt good when you said that to me.
52
00:03:05.825 --> 00:03:07.185
Sounds like the old say.
53
00:03:07.425 --> 00:03:08.065
Yeah.
54
00:03:08.545 --> 00:03:13.505
I just I don't know. For some reason, knew you were, like, a real one when you said that to me. Like, oh, you actually
55
00:03:14.465 --> 00:03:17.585
know me online. You don't just block me. That's nice.
56
00:03:19.105 --> 00:03:20.145
I I
57
00:03:20.620 --> 00:03:22.540
there's only a few people I block.
58
00:03:23.820 --> 00:03:24.700
So
59
00:03:24.860 --> 00:03:25.980
I consider
60
00:03:26.220 --> 00:03:28.300
so I in Vegas,
61
00:03:28.380 --> 00:03:31.580
you were on a panel. I still call it the legendary panel.
62
00:03:32.140 --> 00:03:35.180
And it was the one it was the quantum panel in the main stage
63
00:03:36.105 --> 00:03:39.065
where My first time on the main stage. Yeah.
64
00:03:40.985 --> 00:03:43.705
That was like quite an experience.
65
00:03:43.705 --> 00:03:46.985
So first of all, you should know I was with all of your boys.
66
00:03:47.225 --> 00:03:48.505
I was with the whole
67
00:03:48.790 --> 00:03:49.510
crew.
68
00:03:55.510 --> 00:04:00.710
Just happened to be with your crew while that like, and they were all rooting for you. They're like, yeah, yeah.
69
00:04:02.255 --> 00:04:08.895
I'll link it to the show notes, people should watch the panel, I actually think it's really good. But it was like one of the most contentious
70
00:04:09.695 --> 00:04:13.295
panels I feel like you'll ever see. And, you know, all of us
71
00:04:14.950 --> 00:04:20.070
all of us have experience speaking at these conferences. They're usually very nice and polite.
72
00:04:20.710 --> 00:04:27.590
They They take very very rarely seriously that one. Sometimes they get spicy because you have some people who are skilled at doing that
73
00:04:28.225 --> 00:04:29.264
without bringing
74
00:04:29.505 --> 00:04:30.305
like,
75
00:04:31.185 --> 00:04:33.345
without going to fight
76
00:04:33.505 --> 00:04:36.625
level. But on this panel, this was a brawl.
77
00:04:37.425 --> 00:04:39.505
Legit, this was a legit brawl.
78
00:04:40.465 --> 00:04:45.770
And like, I give all credit to James O'Bearn. So you had you James O'Bearn,
79
00:04:45.930 --> 00:04:47.050
Hunter Beast,
80
00:04:48.250 --> 00:04:50.330
Alex Thornton was the moderator.
81
00:04:50.490 --> 00:04:53.530
And Alex Pruden of And Alex Pruden was the villain,
82
00:04:53.849 --> 00:04:54.330
basically.
83
00:04:55.755 --> 00:04:58.155
And like, basically, every time James,
84
00:04:58.315 --> 00:05:02.395
the funny thing if you watch this is that every time James basically
85
00:05:02.395 --> 00:05:03.835
gave a body blow,
86
00:05:04.475 --> 00:05:06.715
which he was doing just constantly,
87
00:05:06.715 --> 00:05:11.850
just body blow after body blow, like you were sitting next to him and it's like you could we could see you
88
00:05:12.410 --> 00:05:14.330
trying not to like react.
89
00:05:15.770 --> 00:05:19.850
I was trying to be like somewhat civilized and failing. Totally. Totally failing.
90
00:05:21.530 --> 00:05:25.595
So yeah, I mean, Rob, I don't know if that was your take. What does it
91
00:05:26.555 --> 00:05:31.275
Well, I was on the news desk doing commentary with Aaron Redwing
92
00:05:31.675 --> 00:05:32.955
for that panel.
93
00:05:33.354 --> 00:05:34.794
So, like, the entire
94
00:05:35.595 --> 00:05:51.080
I mean, like, the, like, the entire time I was trying to, like, listen to it and get ready for the notes and the play by play commentary, and there were so many things happening so quickly, like points getting flown around back and forth to try and give a cohesive, like, ninety second summary when the camera panned back to us.
95
00:05:52.285 --> 00:05:55.645
I did pick up on what you were describing, though, for sure.
96
00:05:56.445 --> 00:06:00.045
Well, like, I there's things I wanted to say on that panel, and
97
00:06:00.445 --> 00:06:08.510
and it it was with four people all with, like, strong points to make, it was it was obviously gonna be a limited time for any one of us to speak.
98
00:06:09.310 --> 00:06:18.975
And and so I was would hear James, and then and then he said something that I had been planning to say. Like, that's why I couldn't not react anymore. We because he's like, oh, there it is.
99
00:06:19.535 --> 00:06:30.655
That's the worst. Oh, that's the absolute worst is when the guy next to you takes your talking point. Makes my point. Yeah. No. It was it was good, though. It was good. He he he crushed it. And he and, of course, you know, he's he's
100
00:06:30.815 --> 00:06:33.000
sharp witted. And so he put it in
101
00:06:33.400 --> 00:06:37.640
ways that were pretty cutting. And so definitely made for entertaining radio.
102
00:06:38.680 --> 00:06:46.440
Well, I don't know anyone who could really pull off what he pulled off on that panel. And people should just People listening should watch it. It was very contentious.
103
00:06:47.254 --> 00:06:47.895
There
104
00:06:48.694 --> 00:06:49.895
was a very specific
105
00:06:50.134 --> 00:06:54.375
idea being debunked. And I think like what I would like to do just to get constructive
106
00:06:54.534 --> 00:06:55.895
around quantum.
107
00:06:55.974 --> 00:06:56.455
The
108
00:06:57.335 --> 00:07:07.990
thing that you said on that podcast that resonated with me the most that still sticks with me to this day. And I think I used this when I was moderating the panel in Prague that I thought was gonna be on quantum,
109
00:07:08.310 --> 00:07:10.870
but I still used it. I've your essence
110
00:07:11.830 --> 00:07:12.710
on this,
111
00:07:13.030 --> 00:07:13.830
which is
112
00:07:14.385 --> 00:07:15.665
this attitude
113
00:07:15.825 --> 00:07:17.585
that like
114
00:07:19.185 --> 00:07:20.945
quantum computers don't exist.
115
00:07:25.665 --> 00:07:28.865
And whether or not you think they do or they will or you think they won't,
116
00:07:29.390 --> 00:07:34.350
it's probably a more constructive view just to think that a classical computer is going to break
117
00:07:35.230 --> 00:07:36.830
elliptic curve cryptography.
118
00:07:37.630 --> 00:07:39.710
And the actions
119
00:07:39.710 --> 00:07:44.590
would be the same. The actions are we better learn the hell out of this cryptography
120
00:07:45.125 --> 00:07:47.605
and better be ready. It could happen tomorrow.
121
00:07:48.164 --> 00:07:50.325
And that resonated with me so much
122
00:07:50.725 --> 00:07:57.525
that like, I think I stopped caring if you're a good person or not or anything like that. It was like that idea
123
00:07:58.485 --> 00:08:00.085
so hit me very, very hard.
124
00:08:00.830 --> 00:08:05.870
Yeah. Mean, I think I think it's so important because people keep saying post quantum cryptography.
125
00:08:06.110 --> 00:08:09.310
And really all they're saying is post SecP256K1
126
00:08:09.310 --> 00:08:15.630
cryptography. Right? We we depend not even on elliptic curve cryptography in general. We depend on one specific
127
00:08:15.630 --> 00:08:20.055
elliptic curve for the security of all of our Bitcoin.
128
00:08:20.375 --> 00:08:26.215
And if that elliptic curve were to have some kind of a break, whether it's quantum or classical,
129
00:08:26.295 --> 00:08:28.135
we don't currently have a fallback.
130
00:08:28.775 --> 00:08:34.980
And so the action of doing all this research And so this is the good side of quantum, is that
131
00:08:35.700 --> 00:08:46.875
it's caused funding to go into doing research into other kinds of cryptography that we could use. And the reason I think it's important to not say post elliptic curve as a general is that one of the new kinds of cryptography is also elliptic curve based,
132
00:08:47.115 --> 00:08:54.395
but based on a different curve and based on different assumptions within elliptic curves. And so is that a place we should go with Bitcoin cryptography?
133
00:08:54.475 --> 00:08:55.115
Maybe.
134
00:08:55.755 --> 00:08:56.635
But, yeah, the
135
00:08:57.610 --> 00:09:06.170
post quantum is just such a silly thing to say because it doesn't matter what breaks it. It matters that it broke and that we need to have something to deal with that. And
136
00:09:06.650 --> 00:09:12.170
treating it like quantum is the only threat could lead us in the wrong direction because then we're looking for a very specific solution.
137
00:09:12.725 --> 00:09:16.085
And we could end up in this case, let's say we did
138
00:09:16.485 --> 00:09:18.805
a different kind of cryptography
139
00:09:18.805 --> 00:09:24.405
but using the same elliptic curve. That would be foolish in my opinion because that would protect us from quantum,
140
00:09:24.959 --> 00:09:29.759
but it wouldn't protect us from a break in the structure of that curve. We don't wanna be so specific
141
00:09:29.759 --> 00:09:38.399
in our new crypto that we're only protecting against quantum. And so I think it is valuable to look at post SECP two sixty k one crypto in particular.
142
00:09:39.245 --> 00:09:41.964
It reminded me of like BPA and plastic.
143
00:09:43.245 --> 00:09:44.605
You know? Like,
144
00:09:44.764 --> 00:09:49.644
do you remember when oh, well, we've identified the only thing dangerous. Bad thing.
145
00:09:50.524 --> 00:09:56.050
And now we've taken it out, so all good. Yeah. And now we're all full of plastic in our balls.
146
00:09:56.610 --> 00:09:58.610
Just not BPA though. Oh,
147
00:09:59.250 --> 00:09:59.810
okay.
148
00:10:00.130 --> 00:10:01.330
You know, that
149
00:10:02.850 --> 00:10:08.615
it's like, I don't know. Was there a name for that fallacy or it's just like a bias? It's just like identification
150
00:10:08.615 --> 00:10:09.415
bias.
151
00:10:09.735 --> 00:10:23.630
Yeah. I don't I don't know the name for it, but it is yeah. Certainly, there's a phenomenon that people go through of the threat that I can see right now is the only threat. And it's like, no. You need to broaden your perspective on threats. Otherwise
152
00:10:23.950 --> 00:10:35.785
and then, frankly, as part of why, like I'll chill for a moment why why I I've been doing what I've been doing, which is kind of helping people with security stuff. Because one of the fundamental things in doing security research and auditing and stuff is
153
00:10:36.185 --> 00:10:41.625
seeing the stuff that other people didn't see, opening your perspective to other ways people could attack a system.
154
00:10:42.105 --> 00:10:51.880
And that's, I think, fundamental to the quantum conversation and a lot of other things in Bitcoin as well, is people hone in on one threat, and then and then that's that's their horse blinders. That's all they see.
155
00:10:52.279 --> 00:10:56.040
Is there, like, a division of labor, though, of, like, maybe certain
156
00:10:56.600 --> 00:11:02.360
people, individuals are only capable of seeing one threat, but we need to get more of them in a room together?
157
00:11:04.755 --> 00:11:06.995
Well, I think it's somewhat natural
158
00:11:07.155 --> 00:11:13.155
for any person to kind of obsess with the thing they're obsessed with right then. And that's kind of the point of but
159
00:11:15.075 --> 00:11:21.360
it's not productive, I would say, even if you are that person. You're the you're the quantum threat person or you're the,
160
00:11:22.720 --> 00:11:24.480
you know, what whatever the the
161
00:11:24.720 --> 00:11:26.240
the centralized
162
00:11:26.639 --> 00:11:31.185
custody person, whatever. Hone in on one threat. But
163
00:11:31.185 --> 00:11:35.025
I think it's important that you don't try to act like yours is the
164
00:11:36.225 --> 00:11:40.945
only possible priority even to other people. And that's, I think, where
165
00:11:41.930 --> 00:11:49.210
everyone tends to get into that mode of my threat, the thing I'm obsessed with is what everyone else should also be obsessed And
166
00:11:49.850 --> 00:11:56.730
that doesn't really help anything. So I think that's maybe what I try to bring in these conversations is helping people open their perspective to other threats.
167
00:11:57.335 --> 00:11:59.175
So curious question.
168
00:12:00.215 --> 00:12:04.935
Do you think this is a natural way we think or is it related to the fact that
169
00:12:05.655 --> 00:12:06.935
to get capital
170
00:12:07.175 --> 00:12:08.535
to solve a problem,
171
00:12:08.935 --> 00:12:09.735
it has to be,
172
00:12:10.389 --> 00:12:13.830
you you have to convince somebody that yours is the most important problem.
173
00:12:15.670 --> 00:12:16.470
I think
174
00:12:16.790 --> 00:12:19.670
both of those are true. So especially,
175
00:12:19.829 --> 00:12:23.190
you know, people that lean towards this like obsessive
176
00:12:23.190 --> 00:12:25.990
mindset that gets you into Bitcoin in the first place
177
00:12:26.445 --> 00:12:53.290
are naturally gonna be prone to thinking in that way, kind of focusing on a singular thing. And then also people who are running companies need to make their threats seem the most important so that they can raise money for this company. So both of those things happen and they kind of feed each other. And I think we've seen that many times in Bitcoin is where those those two tendencies, the fundraising side of it and the natural obsession side feed into each other and kind of amplify a signal. Yeah, mean, and I'm not knocking that. I'm just trying to explain it, right? It's like,
178
00:12:54.295 --> 00:12:55.415
it's natural.
179
00:12:55.495 --> 00:12:56.055
The
180
00:12:56.455 --> 00:13:02.135
reality of competing for capital is if you don't have the most important problem, you shouldn't get it.
181
00:13:03.335 --> 00:13:05.095
Right? Absolutely.
182
00:13:05.415 --> 00:13:06.215
But then
183
00:13:07.350 --> 00:13:08.710
a lot of people just
184
00:13:09.110 --> 00:13:11.430
obsess over their one thing for the love of the game.
185
00:13:12.710 --> 00:13:18.870
It's also just the nature of when you specialize and focus on a specific thing, you become more,
186
00:13:19.584 --> 00:13:29.345
you have this, like, feedback loop where you are the expert in said thing. So you get into more conversations. You get more perspectives since you're at the tip of the spear, so to speak.
187
00:13:29.825 --> 00:13:33.024
And with that, you become the domain expert. And then
188
00:13:33.870 --> 00:13:39.870
your credibility of being able to speak at conferences or to be engaged in in opportunities
189
00:13:39.870 --> 00:13:43.070
is defined in the fact that you have this narrow subdomain
190
00:13:43.790 --> 00:13:49.805
specialty ultimately. So it's almost like the industry also kind of rewards you for concentrating
191
00:13:49.805 --> 00:13:51.085
on something special.
192
00:13:51.245 --> 00:13:53.405
So it's the strength of your brand
193
00:13:54.125 --> 00:14:04.550
or your ability to get capital, all those things. I mean, these aren't shallow things. These are these things matter. These are reasons these are reasons why people care about stuff like this. Right?
194
00:14:05.910 --> 00:14:07.910
Yeah. And I think that that happened with
195
00:14:09.190 --> 00:14:10.710
some of the authors of of
196
00:14:10.950 --> 00:14:17.029
BIP three sixty, for example, where where because they were working on that, they got invited to do lots of stuff and and
197
00:14:17.295 --> 00:14:20.895
that contributed to their focus on that as as the thing to focus on.
198
00:14:21.455 --> 00:14:24.095
It's
199
00:14:24.095 --> 00:14:27.455
like, could we just implement that and then not have
200
00:14:28.015 --> 00:14:35.190
yeah. Just remove the cache. It's like once you implement it, we can So there's can send them on their merry way. Right?
201
00:14:35.830 --> 00:14:37.350
I mean, I was
202
00:14:38.870 --> 00:14:41.990
I I am, I would say, generally supportive of BIP three sixty.
203
00:14:42.390 --> 00:14:46.575
But as it's as it's matured, actually, there have been more
204
00:14:47.295 --> 00:14:48.895
people pushing back on it.
205
00:14:50.334 --> 00:14:54.015
And I think there some of that pushback is is right, actually. For
206
00:14:54.654 --> 00:15:03.370
example, I I as a as a BIP three sixty supporter, I I I would have said, you know, I I like the efficiency of having both a keyed
207
00:15:04.170 --> 00:15:04.890
path
208
00:15:04.970 --> 00:15:08.170
where you use Taproot because you know you have a
209
00:15:09.930 --> 00:15:11.370
you have a cooperative
210
00:15:11.705 --> 00:15:23.705
path, whatever it is, that can use a single key via music or frost, and so you use Taproot. But if you if you don't, if you always need a script, like lightning channel closes, always need a script because they always close through a script, once you've done a force close at least.
211
00:15:24.185 --> 00:15:27.880
Since their force closes always need a script, then you use BIP three sixty,
212
00:15:28.120 --> 00:15:35.320
pay the Merkle root, because you don't have a key at the root, and it saves you a few bytes to not have that key in the case where you don't need it.
213
00:15:37.480 --> 00:15:40.279
But actually, there's now a proposed change to get rid of that
214
00:15:41.055 --> 00:15:47.135
byte savings because it would create an incentive to switch and then defeat the privacy benefits of Taproot.
215
00:15:47.935 --> 00:15:48.575
And so
216
00:15:48.975 --> 00:15:50.735
there's more and more conversation happening
217
00:15:51.375 --> 00:15:54.015
that maybe we shouldn't do something like the $3.60 and we should instead,
218
00:15:55.279 --> 00:15:59.360
and I think, should nobody's been writing about this a bit recently. We should instead have a
219
00:15:59.760 --> 00:16:05.040
fallback plan until that everyone claims their coins if we have to disable Taproot key spends.
220
00:16:06.000 --> 00:16:08.880
And I think we're quite close to having via
221
00:16:09.440 --> 00:16:10.079
these various
222
00:16:10.605 --> 00:16:12.685
methods, whether they're commit reveal
223
00:16:13.084 --> 00:16:13.725
or
224
00:16:14.365 --> 00:16:20.045
post change reveal, there's various ways we can recover coins even in a break of SecP26A1.
225
00:16:20.765 --> 00:16:25.885
And so maybe then BIT360 isn't the way to go. So just to be clear Got it. Yeah. Got it. Just implementing it is not, I think,
226
00:16:26.680 --> 00:16:28.040
an obvious move.
227
00:16:28.280 --> 00:16:29.080
We should
228
00:16:29.480 --> 00:16:32.440
address the concerns that it brings up,
229
00:16:32.680 --> 00:16:35.240
but whether it's through Bit $3.60 in particular or not,
230
00:16:35.880 --> 00:16:37.640
I don't know right now. Yeah. Got it.
231
00:16:38.120 --> 00:16:42.445
I was say maybe we could take it as just a step back and maybe distinguish
232
00:16:43.005 --> 00:16:46.445
like what the solution space is addressing for the most part.
233
00:16:47.565 --> 00:16:48.845
There's a mathematical
234
00:16:51.805 --> 00:16:54.125
solution or there's a mathematical problem
235
00:16:55.170 --> 00:16:58.530
where you know, you've low hanging fruit in Bitcoin of people
236
00:16:59.090 --> 00:17:00.690
whose pub keys are exposed,
237
00:17:01.010 --> 00:17:03.090
right? Those would be the first lot.
238
00:17:04.530 --> 00:17:16.025
People who are afraid of quantum would say that's the first those are the first addresses that'll be attacked. Is that right? That Yeah. And and in particular, it would be it would be large
239
00:17:16.025 --> 00:17:17.225
UTXOs
240
00:17:17.225 --> 00:17:20.825
with exposed public keys because there's a reasonable
241
00:17:21.880 --> 00:17:23.720
I don't know if it's a speculation
242
00:17:23.720 --> 00:17:25.879
or a guess that
243
00:17:25.960 --> 00:17:32.600
the first quantum computer is gonna be very expensive to operate. Right? It might take $500,000
244
00:17:32.600 --> 00:17:39.225
of electricity to break one secret key if there is if if it happens, that first quantum computer. And so you're not gonna attack
245
00:17:40.425 --> 00:17:42.985
Brian's $50 UTXO
246
00:17:43.065 --> 00:17:44.665
because just
247
00:17:44.665 --> 00:17:48.425
waste your quantum computer. And so it's it's large UTXOs
248
00:17:48.425 --> 00:17:49.065
with exposed
249
00:17:49.700 --> 00:17:58.180
pub keys. And I think that's one of the things that is often missed that I also try to bring up frequently in these competitions about quantum is any kind of preemptive
250
00:17:58.180 --> 00:17:58.980
disabling
251
00:17:59.620 --> 00:18:00.419
is like
252
00:18:01.220 --> 00:18:04.580
is gonna just steal people's money for nothing because most people's
253
00:18:04.885 --> 00:18:08.804
points aren't vulnerable to those early quantum computers even if they happen.
254
00:18:09.205 --> 00:18:09.764
This
255
00:18:10.165 --> 00:18:15.684
is also just in general when this problem is talked, it's almost treated as a binary flip of
256
00:18:16.165 --> 00:18:17.924
sec p is now broken
257
00:18:18.110 --> 00:18:22.510
without understanding the economics or the duration thereof? Let's say,
258
00:18:23.230 --> 00:18:24.669
like and maybe,
259
00:18:24.830 --> 00:18:27.789
Brandon, like, if we live in a world where this exists, you could
260
00:18:28.590 --> 00:18:29.710
flesh this out more.
261
00:18:30.345 --> 00:18:42.024
Is it something that once the binary is flipped, you spend a bunch of money and it takes a fraction of a second and it's all short range attacks? Or could you be in a world where this stuff hypothetically turns on and it still takes weeks
262
00:18:42.585 --> 00:18:46.025
to be able to crack a key? Yeah. So it depends on the tech.
263
00:18:46.640 --> 00:18:51.039
If if a superconducting quantum computer is is the one that actually works,
264
00:18:51.440 --> 00:18:54.719
then once that turns on, it'll be pretty quickly
265
00:18:54.960 --> 00:18:56.479
a short range attack.
266
00:18:56.640 --> 00:19:05.284
But if it's a neutral atom, which is what I think is the most promising technology to maybe get there someday right now, that may never get a SecP key in less than two weeks.
267
00:19:06.005 --> 00:19:11.284
And so we just don't know yet even what the solution space is because we don't know what tech is gonna move forward.
268
00:19:12.165 --> 00:19:19.460
And so yeah. So so certainly, if it's if it's a neutral atom type computer that that solves it, you may never wanna disable
269
00:19:19.460 --> 00:19:25.460
secp keys for small values. They'll just give advice like, Hey, don't use this for large UTXOs.
270
00:19:25.539 --> 00:19:34.125
And we have other crypto for large UTXOs, and it kind of makes sense that other crypto is much more expensive to spend, but it protects you because you have a large UTXO.
271
00:19:34.125 --> 00:19:38.044
And then if you don't need that, you forever use the old stuff,
272
00:19:38.365 --> 00:19:39.325
and it's fine.
273
00:19:41.085 --> 00:19:45.325
So now since I know that, Brendan, you're you're into poker,
274
00:19:45.405 --> 00:19:50.169
you're knowledgeable of poker. Correct? I I have played some poker. I'm not super knowledgeable or anything though.
275
00:19:50.490 --> 00:19:53.690
You sounded kinda knowledgeable when we were arguing about it. Definitely
276
00:19:54.410 --> 00:19:57.610
Oh, well, so so my my background here is I've never played that much poker.
277
00:19:58.090 --> 00:20:01.290
My dad played a whole bunch of poker and he was Okay. He was head of this this
278
00:20:02.044 --> 00:20:08.205
I I don't know what what to call it, but he was a table player. So he would he would go to tournaments.
279
00:20:08.205 --> 00:20:11.404
That's what what are we not conferences. We do conferences. He did tournaments. You
280
00:20:12.605 --> 00:20:15.164
know, they're very similar. This culture personality,
281
00:20:15.164 --> 00:20:16.765
like, dominating everything.
282
00:20:16.765 --> 00:20:17.645
Right? Very similar.
283
00:20:18.179 --> 00:20:28.100
Tournaments loved him because he he was a predictable player. So they put him in the early tables, and so they he wouldn't fuck up the really great players. He would play predictable poker, and and he'd get to, you know, the semifinals
284
00:20:28.100 --> 00:20:30.835
or whatever. He'd get to maybe cashing in some of the tournaments.
285
00:20:31.315 --> 00:20:41.714
But they love to have people like him there because they don't mess up the good players. Got it. That's know about poker is from his experiences and stuff more. The poker analogy I would like to make for Quantum
286
00:20:42.195 --> 00:20:45.315
is something called monsters under the bed syndrome.
287
00:20:46.580 --> 00:20:53.860
You see it, if you read online, if you're online a lot and you're reading like hand histories, they'll just say I got MUBS, I got MUBS and
288
00:20:54.900 --> 00:20:56.580
folded a because
289
00:20:57.300 --> 00:21:02.174
I assumed my opponent, had no you know, I just got monsters under the bed syndrome.
290
00:21:02.414 --> 00:21:04.494
It's a very common term in poker.
291
00:21:04.894 --> 00:21:27.835
And I mean, this is where you're like, you lose a huge hand because you have you have pocket kings, someone else had pocket aces or whatever. And you lose this this huge hand because because your hand was strong and it was gonna give bet stupid. But you had, like, a full house, and you let a big bet make you fold because you just assumed that the guy had a straight flow. You just, like, get the Oh, it's at the opposite. Okay. Okay. Yeah. Like, you could not shake the fact that you were beat even though and it's like I
292
00:21:27.835 --> 00:21:30.394
think the Bitcoin space could use that terminology
293
00:21:30.875 --> 00:21:34.715
very much so right now, not just for quantum, but for a lot of things.
294
00:21:36.475 --> 00:21:37.355
In the,
295
00:21:37.755 --> 00:21:39.434
properly sizing risk,
296
00:21:39.914 --> 00:21:41.674
the ability to appropriately size risk.
297
00:21:44.650 --> 00:21:54.730
Sorry. That was a question. Like, the skill to be able to the skill to be able to pick up. That should be kind of Well, yeah. That's really the quest that but when when you say that, it's sort of like,
298
00:21:55.355 --> 00:22:05.675
there's a specific skill, let's say when all the cards are out on the table and you're getting value bet, and you have to ask yourself, what's the probability that he has it versus the probability that he doesn't.
299
00:22:05.915 --> 00:22:11.115
He said a value bet is suggesting by what's a value bet is like a small bet
300
00:22:11.250 --> 00:22:20.210
meant to get paid off. It's like the winning hand usually will put out a small bet. So even if you're bluffing, you're gonna pretend you're gonna still throw a value bet out. You're not gonna try to get too much
301
00:22:21.170 --> 00:22:24.050
because you're gonna that's how you assert that you have the winning hand.
302
00:22:24.865 --> 00:22:34.945
You know, on the river, you might throw like 20% of the pot or something like that, some small bet to get paid off. And you have to sit there and assess, okay, what's the likelihood that
303
00:22:35.904 --> 00:22:40.409
he has what he says he has? And that's, is it more than 20% or is it less?
304
00:22:41.450 --> 00:22:44.090
Then you look at your implied odds with the pots paying off.
305
00:22:45.930 --> 00:22:48.730
That's Rob, is that that's what you mean I assume?
306
00:22:50.570 --> 00:22:51.770
You're on mute my friend.
307
00:22:53.385 --> 00:22:56.265
Yes. That's exactly what I was getting at. Right? Being able to actually
308
00:22:56.425 --> 00:22:59.625
go through risk patterns and understanding calculated payoffs.
309
00:22:59.705 --> 00:23:00.345
You know?
310
00:23:00.825 --> 00:23:01.545
Every
311
00:23:01.785 --> 00:23:11.840
every argument has a proposed underlying wager beneath it. And when we talk about stuff like quantum, it's a question of, well, what are the percent likelihoods
312
00:23:11.840 --> 00:23:19.920
of this exceeding versus the total amount to be lost? And I think everyone would agree in general to throw it into, a general insurance term of this is a
313
00:23:20.565 --> 00:23:21.924
very low frequency,
314
00:23:22.085 --> 00:23:23.364
high catastrophic
315
00:23:23.924 --> 00:23:24.884
at the
316
00:23:25.445 --> 00:23:27.044
high level understanding.
317
00:23:27.284 --> 00:23:32.724
But then the question is is, okay, abstractly that may be hypothetically possible, but then you start getting into the mechanics of,
318
00:23:33.125 --> 00:23:33.605
okay,
319
00:23:33.980 --> 00:23:37.659
Even if this does exist, it is low frequency, high catastrophic
320
00:23:37.820 --> 00:23:44.539
outcome for maybe an individual address. This is not a nuclear bomb that just takes out the entire Eastern Seaboard.
321
00:23:44.620 --> 00:23:45.740
This is more like
322
00:23:46.075 --> 00:23:54.475
a tornado that throughout the entire United States, if you had a low frequency, high high catastrophic event, it's not gonna take out the entire US in one
323
00:23:54.715 --> 00:23:57.595
slew. It's gonna hit, like, one street in a town somewhere.
324
00:23:57.755 --> 00:24:05.729
Right? So even the concentration there to even understand hypothe and this is why, it's almost like a Mott and Bailey
325
00:24:06.049 --> 00:24:30.145
situation where it's like, this is catastrophic. It's gonna destroy everything. You're like, well, wait a second. It's not even practical at scale. Like, what is the time to unlock this stuff? Like, what is the economic overhead? It's well, no. No. No. No. No. No. Like but the fact that's possible is, like, a thing we should be concerned about. So we need to make all of these drastic changes because an individual address may be under extreme threat attack. Right? Like, you you start you start moving around the argument, and I think you have to view the problem in its full
326
00:24:30.970 --> 00:24:31.849
context
327
00:24:32.090 --> 00:24:34.970
that, okay, let's I'm gonna take you at your word. 1000%,
328
00:24:34.970 --> 00:24:38.489
the binary switch is gonna flip from this is not possible to is possible.
329
00:24:38.889 --> 00:24:46.024
Okay. What is the time and the overhead for that? And, okay, let's say it's a multisig instead of just a single signature key.
330
00:24:46.345 --> 00:24:46.825
Cool.
331
00:24:47.304 --> 00:25:00.100
Now you have to do three keys out of five instead of just being one key. So if it takes two weeks, you're not talking six weeks, and you're telling me in that time I won't be able to move funds. Oh, you also have to know it's a multisig, and you have to know there's no passphrase. You have to know
332
00:25:00.420 --> 00:25:04.580
Well, the that doesn't matter. The passphrase doesn't matter because it's a public key that's sitting on the blockchain.
333
00:25:04.820 --> 00:25:19.404
Because it because if if the if you reuse the address I'm not gonna ask. The one that gets talked about a lot is the Binance address. So Binance cold storage is like a three zero five multisig, and they reuse the address. And because they reuse the address, the public key is sitting on the stack so anyone can look at it. So you don't need a passphrase.
334
00:25:19.485 --> 00:25:32.870
Like, when you do the quantum computer unrivaling, you're not rederiving the bit 32 seed, which goes to Lalu and now Shinobi talking about ways you could actually do a zero knowledge proof to recover. And this is an important detail. When you use BIP 39,
335
00:25:33.190 --> 00:25:35.110
what you're actually doing is you take these words,
336
00:25:35.430 --> 00:25:41.735
you smush them together, and then you hash it. I think it's 512 times. And because you hash it a bunch of times,
337
00:25:42.215 --> 00:25:44.054
you now disassociate
338
00:25:44.215 --> 00:25:46.294
yeah. I think I think it's 512.
339
00:25:46.615 --> 00:25:48.775
It's shot it's shot 5122000
340
00:25:48.775 --> 00:25:49.335
times.
341
00:25:49.655 --> 00:25:50.215
Right.
342
00:25:50.535 --> 00:25:51.575
And since you are
343
00:25:52.260 --> 00:25:58.100
doing a hash function, as we've briefly discussed previously on this podcast, you're now outside the domain of the,
344
00:25:59.460 --> 00:26:12.384
traditional quantum computer breaking sec p in the way that would be a problem. So it may break an individual key, but it won't be able to actually reverse derive your seed phrase. And that's the important part Yeah. With doing a zero knowledge proof. Yeah. And that also applies
345
00:26:12.625 --> 00:26:18.144
to every hardened derivation within your wallet. So if you if you make a a
346
00:26:18.784 --> 00:26:25.910
an x pub and then or an XPRIV, I should say, and then you derive hardened for several layers, and then you'd unhardened below there.
347
00:26:26.870 --> 00:26:33.990
Even if a quantum computer were to get your XPUB and get one of the keys I don't know if you guys know this property. Well, Rob probably does. But
348
00:26:34.845 --> 00:26:39.404
if someone gets an XPUB and then an unhardened
349
00:26:39.405 --> 00:26:42.124
derivation below that, they get a secret key,
350
00:26:42.525 --> 00:26:43.244
they can
351
00:26:43.565 --> 00:26:46.764
immediately compute all the secret keys within that unhardened
352
00:26:46.845 --> 00:26:47.565
path.
353
00:26:48.525 --> 00:26:50.765
So if you have one XPUB and one secret key,
354
00:26:52.019 --> 00:26:54.579
can arrive all other secret keys within that path,
355
00:26:55.139 --> 00:26:56.899
just with simple simple computation.
356
00:26:56.980 --> 00:27:01.700
Yeah. It's a it's a thing that's often not discussed with BIP 32 is that if you have the XPUB
357
00:27:01.779 --> 00:27:04.820
and you have a private key belonging to that XPUB,
358
00:27:05.075 --> 00:27:07.554
you can walk across the entire chain
359
00:27:07.795 --> 00:27:15.315
of all of the private keys that exist up to that level, but you stop once you hit a hardened derivation path level.
360
00:27:15.635 --> 00:27:17.395
Because the hardened derivation path
361
00:27:17.830 --> 00:27:21.750
is partially rederived from using your c your private key
362
00:27:22.150 --> 00:27:28.870
your your seed phrase, like your actual ultimate, like, seed level and it's hashed. So there's no algebraic relationship anymore. It's a hash relationship.
363
00:27:29.110 --> 00:27:37.475
And so hard hardened derivations are an important part of any kind of discussion of quantum and everything because one of the things that's also under discussed is
364
00:27:37.715 --> 00:27:42.434
people are like, oh, my I've never used addresses, so I'm totally safe. Well, have you ever
365
00:27:42.674 --> 00:27:45.794
used a web service where you gave them your XPUB for any reason?
366
00:27:46.595 --> 00:28:04.004
Because you have to assume that that XPUB is out there in the world now. And so if now, it doesn't matter if you've reused an address, it matters that you ever spent from any address under that XPUB and you gave that XPUB to a service. Because we have to assume that if a quantum break happens, that not only
367
00:28:04.485 --> 00:28:11.284
are old encrypted traffic on the Internet decryptable, because there's probably archives of a lot of traffic that was out there when you sent that XPUB to that server.
368
00:28:12.005 --> 00:28:22.320
But if that company is compromised because they don't have a quantum hard crypto system on their backups, backups. Their backups get compromised. They get your exome. Like, all your XPOPs that you've ever sent to a web service
369
00:28:22.720 --> 00:28:25.280
are are out there. So so I'm hesitant
370
00:28:25.920 --> 00:28:54.500
to make much of a distinction between addresses whose public keys are are known and not because the the best assumption is that most public keys are known. Like Rob said, the Binance addresses, the Coinbase addresses are, in general, the Uri's addresses as well. So it it's simply the the default assumption is that public keys are public. That's why they're fucking called public. Just to be This is this is an important detail too for take it. But now it's like, yeah. Okay. Someone's gonna come and take it. And just realistically,
371
00:28:54.500 --> 00:28:55.540
you necessarily
372
00:28:55.540 --> 00:28:56.659
have to treat
373
00:28:57.140 --> 00:29:04.374
ex pubs and public keys with a different level of security than private keys. You just necessarily have to. Right? No one is running,
374
00:29:05.095 --> 00:29:06.294
an elaborate
375
00:29:06.294 --> 00:29:10.695
system of security with hardware security HSMs and,
376
00:29:11.095 --> 00:29:15.815
trusted execution environments and air gaps to drive to give you an address.
377
00:29:16.500 --> 00:29:18.580
Like, that's just not happening. Right?
378
00:29:18.980 --> 00:29:19.620
So
379
00:29:19.860 --> 00:29:28.740
because the public keys are relatively free in the sense of, like, yeah, give me another one. Give me another one. Give me another one because you wanna get more deposit addresses. And so the security models of those
380
00:29:29.235 --> 00:29:48.019
XPUBs and public keys necessarily for a functioning service have to be at a different level of security, which means it's much more likely that those are just out and available in the world. Yeah. Like most most people are even told for good reason when when you get like a multisig vault with with, know, whatever Casa or Swan or Anchor Watch or anybody who does multisig,
381
00:29:48.100 --> 00:29:51.460
you're told to like store your descriptors redundantly.
382
00:29:51.620 --> 00:29:56.825
Right? We we treat those which have all the public keys in them as information that should be redundant.
383
00:29:56.905 --> 00:30:11.759
And, yeah, you should be a little bit careful with it because it's a privacy leak. It can reveal your balance if you let it out, but it's not a secret key. And so you might put that in a Google Drive or you might put that in a OneDrive or an Apple Cloud, whatever, might put it somewhere that you would never put a secret key in those places.
384
00:30:12.320 --> 00:30:16.639
And so the only reasonable assumption is that public keys are public.
385
00:30:16.960 --> 00:30:17.759
And so
386
00:30:17.920 --> 00:30:23.440
we've gone off on this tangent, to loop that back to this question of measuring the risk.
387
00:30:24.945 --> 00:30:26.705
So we should assume
388
00:30:26.945 --> 00:30:27.585
that
389
00:30:28.145 --> 00:30:29.984
if a quantum computer happens,
390
00:30:30.544 --> 00:30:37.265
all UTXOs that are within the value range for that quantum computer to to to attack are subject to that quantum computer.
391
00:30:37.730 --> 00:30:49.730
And then It's like they don't care if it's P2PK, they just don't care. It doesn't That's a red herring at this point. That's unlikely to be the difference. It's really about the size of the UTXOs and whether this The current quantum computer can economically
392
00:30:49.730 --> 00:30:51.330
attack those UTXOs.
393
00:30:52.450 --> 00:30:54.955
Okay. So we should also be mindful.
394
00:30:57.355 --> 00:30:59.674
Rob was talking about the risk sizing,
395
00:30:59.835 --> 00:31:02.075
likelihood versus sizing. And there's
396
00:31:03.835 --> 00:31:05.755
There's several of those embedded in quantum,
397
00:31:06.250 --> 00:31:07.769
Right? Because there's
398
00:31:08.570 --> 00:31:10.489
a low severity
399
00:31:10.809 --> 00:31:11.690
risk
400
00:31:12.250 --> 00:31:25.245
that is more likely, and that is we see a gradual progression of quantum computing capability, it gets gradually less expensive, maybe hits some floor, maybe doesn't hit a floor, but either way, it's a gradual process. And so in that case,
401
00:31:26.125 --> 00:31:34.285
the most vulnerable wallets are these large UTXOs with already known public keys. The next most vulnerable are large UTXOs with partially hidden public keys.
402
00:31:34.940 --> 00:31:49.464
And those folks are kind of active companies managing wallets, and they can easily migrate to new crypto. So we'll see the thing coming from a mile away. We'll give them some new crypto. It's going to be expensive and crappy, but it'll be fine for them because they're large UTXOs and they can handle those costs.
403
00:31:49.865 --> 00:31:52.424
So that's kind of the the low severity,
404
00:31:52.585 --> 00:31:53.945
more likely scenario.
405
00:31:54.024 --> 00:31:57.065
And then there's this much less likely
406
00:31:57.384 --> 00:32:00.184
high severity scenario where tomorrow,
407
00:32:00.345 --> 00:32:05.420
a quantum computer or a classical break of SecB comes up that immediately
408
00:32:05.580 --> 00:32:06.780
lets anybody
409
00:32:07.420 --> 00:32:08.220
quickly
410
00:32:08.300 --> 00:32:13.260
reverse any secret key into a public key. Now this is very unlikely,
411
00:32:13.340 --> 00:32:15.500
but if it happens, it is catastrophic.
412
00:32:15.895 --> 00:32:24.855
And what happens, I think, with the quantum conversation is that they put these two things together. There's this moderately likely thing, which is a slow break of SECP over time with quantum
413
00:32:24.855 --> 00:32:34.049
that is not very severe. We can solve this progressively. We have lots of time to work on it, whatever. And then there's this extremely unlikely thing that is the sudden total break.
414
00:32:34.610 --> 00:32:38.610
Mhmm. And that would be somewhat catastrophic. It would really make a mess of our shit.
415
00:32:39.090 --> 00:32:48.264
But it's so unlikely. It's barely even worth talking about the likelihood of that. And and they put them together and say it's it's somewhat likely and it's extremely severe, but those don't come together.
416
00:32:48.585 --> 00:32:55.784
I have a third category potential. So I have a question. Do you think we've covered monsters under the bed now, but do
417
00:32:55.945 --> 00:32:57.465
we have main character syndrome?
418
00:32:59.670 --> 00:33:01.029
Where does Bitcoin
419
00:33:01.030 --> 00:33:07.430
rank? It seems intuitive to us that it would be a target because there's a lot of money there. However,
420
00:33:07.430 --> 00:33:08.230
I would ask,
421
00:33:08.710 --> 00:33:15.644
is there lower hanging fruit out there for a very expensive quantum computer that has to meet a certain bar
422
00:33:16.125 --> 00:33:19.164
for even for them to know it's a tackle be successful,
423
00:33:19.404 --> 00:33:20.044
right?
424
00:33:21.325 --> 00:33:23.164
I think it depends who gets it.
425
00:33:24.130 --> 00:33:27.970
If you're a VC and you're funding a company to break quantum,
426
00:33:29.809 --> 00:33:31.809
definitely one of your payoff
427
00:33:32.770 --> 00:33:33.730
directions
428
00:33:33.970 --> 00:33:35.649
is is is attacking
429
00:33:36.290 --> 00:33:38.690
something like Bitcoin and other cryptocurrency
430
00:33:38.690 --> 00:33:39.250
type system.
431
00:33:39.904 --> 00:33:44.624
Because of the in various ways. Right? Can because of the the what it would mean, the lore,
432
00:33:44.865 --> 00:33:53.184
what it would mean. It would it's like beating the the fucking chess master. It's like beating the computer. You know? It's like Yeah. And you might you might say, oh, part of our revenue plan
433
00:33:54.560 --> 00:34:03.520
is to, let's say, capture Satoshi's coins. We believe they're unowned. We believe we can therefore make a reasonable claim to this being recovering lost property and that we can keep it.
434
00:34:04.080 --> 00:34:04.640
So
435
00:34:05.360 --> 00:34:08.560
our part of our revenue plan is to recover Satoshi's coins and make them spendable by us.
436
00:34:10.005 --> 00:34:13.445
And that'd be maybe a reasonable thing for VC to invest in. On the other hand,
437
00:34:13.765 --> 00:34:15.765
if a government funded actor
438
00:34:16.165 --> 00:34:21.925
is the one who breaks it, they're not gonna go after that. They're gonna go after decrypting old communications
439
00:34:21.925 --> 00:34:24.325
between their enemy states and stuff like that.
440
00:34:25.640 --> 00:34:27.960
There and so it's got a very different attack there.
441
00:34:29.080 --> 00:34:35.240
Yeah. It really depends on the actor. Do we have main character syndrome? Is RSA, like, with everyone's
442
00:34:35.240 --> 00:34:41.645
passwords and access to all that? Is that, like, just maybe something they they might want to Yeah. Yeah. Certainly, like all old PGP
443
00:34:41.645 --> 00:34:49.165
is all gonna be vulnerable too. And there's a lot of stuff, like pretty heavy stuff encrypted with PGP out there. So so, yeah, they're like also that
444
00:34:49.565 --> 00:34:50.765
again, depending on the actor.
445
00:34:53.980 --> 00:35:02.619
Like I said, I would say that Bitcoin is in the target list. I don't think we're over super overdoing it there. I think some people say, oh, it's gonna be all the other stuff. Problem is
446
00:35:03.275 --> 00:35:07.515
everyone knows that Bitcoin is slower to change than a lot of those other things.
447
00:35:08.075 --> 00:35:12.635
So it's basically, if your threat actor is interested in old encrypted stuff
448
00:35:13.115 --> 00:35:13.595
or,
449
00:35:16.700 --> 00:35:21.500
sorry. Yeah. If if if your threat actor is interested in old encrypted stuff, then they're not gonna go after Bitcoin.
450
00:35:22.300 --> 00:35:34.025
But the but the people who are not at risk of quantum the most are like the banks. Everyone's like, oh, banks are gonna be more vulnerable. No, they're not. Because banks can just turn their website off. Totally. The day quantum hits.
451
00:35:35.385 --> 00:35:40.665
Right. And that's why all the other coins same way. Like they can just rewrite their data. They just undo
452
00:35:41.145 --> 00:35:41.305
it.
453
00:35:43.580 --> 00:35:57.035
That is one good point. I heard Alex Pruden make this on a podcast somewhere. And that was one of the one things I ever agreed with him saying was like Bitcoin will be a target for that reason. Yeah. Cause we're slow. Now,
454
00:35:58.075 --> 00:36:06.234
I don't know. Do you know if anyone's funding projects to do this right now? I don't. Just seems very theoretical that yes, we understand why
455
00:36:06.555 --> 00:36:10.290
that would happen. That doesn't mean it's out there happening. But
456
00:36:10.690 --> 00:36:11.410
we
457
00:36:11.890 --> 00:36:16.290
just know that we would do that if we got Yeah, sure, that makes sense to us.
458
00:36:18.610 --> 00:36:23.250
I don't know for sure. I know actually even partially from talking to Alex,
459
00:36:24.144 --> 00:36:26.224
but also other folks in the quantum side.
460
00:36:29.184 --> 00:36:39.580
Some of the funding is certainly in other things like using quantum to improve sensors and stuff like that. So there's like industrial scale quantum stuff that is happening, that is that is getting funding.
461
00:36:40.300 --> 00:36:40.940
I
462
00:36:41.100 --> 00:36:44.620
don't know for sure if there's funding going out there specifically to break Bitcoin.
463
00:36:44.860 --> 00:36:52.380
It feels like it, but it I that's only a feeling. I don't know. We kinda wish there were. It's really good thought there were some VCs that part of their,
464
00:36:53.065 --> 00:37:00.745
like some VCs invested in companies because part of the return on investment was being able to derive Bitcoins and extract it from the network.
465
00:37:02.665 --> 00:37:05.465
I have no facts. I only have a feeling on that. Yeah.
466
00:37:06.720 --> 00:37:10.000
Like, we want it so bad because we wanna be relevant.
467
00:37:10.800 --> 00:37:11.440
I
468
00:37:11.600 --> 00:37:24.745
mean, that to your, like, your main character syndrome, like Bitcoin main character syndrome as it relates to quantum? Like, why is that the focus of it all? Yeah. I wonder. Like, it's so Oh, because it's money. Such an easy target. Such an easy target for this. Because because here's the thing. One, it's money. Two,
469
00:37:25.305 --> 00:37:25.785
most
470
00:37:26.185 --> 00:37:28.185
of the time when people talk about
471
00:37:28.825 --> 00:37:31.785
getting Bitcoin from Quantum, it's Satoshi's coin specifically.
472
00:37:32.185 --> 00:37:37.545
No one no major company is going to employ quantum computers to attack Binance,
473
00:37:37.920 --> 00:37:39.120
I'm assuming.
474
00:37:39.200 --> 00:37:42.160
If North Korea got a quantum computer, sure.
475
00:37:42.319 --> 00:37:46.080
But, like, the the bleeding edge of all this research happening,
476
00:37:46.480 --> 00:37:50.160
they're gonna just try and take Satoshi's coins, which also presupposes
477
00:37:50.240 --> 00:37:51.520
that there needs to be
478
00:37:51.920 --> 00:37:56.755
the the the ceiling has to be at least whatever worth 50 Bitcoin are worth at a time.
479
00:37:57.555 --> 00:38:05.394
And they may pull what's more likely to happen in a world where this does develop is they will spend 100 x the amount of money
480
00:38:05.880 --> 00:38:09.560
to crack the Genesis block key as a show of force.
481
00:38:09.799 --> 00:38:10.359
Yeah.
482
00:38:10.760 --> 00:38:13.000
Not to actually be profitable,
483
00:38:13.000 --> 00:38:19.799
but once you can do because you have to understand, like, if if they're all trying to hack a particular public key, it is the Genesis block public key.
484
00:38:20.545 --> 00:38:29.585
Because, like, you're not doing it to make the 50 Bitcoin. Well, it's just a as an interesting point, in the Bitcoin consensus code, this is a funny quirk. The Genesis block is unspendable.
485
00:38:30.465 --> 00:38:42.880
So they're not gonna do it to actually make money, but they're gonna do it to be able to show that they cracked Bitcoin because it's the original key in the blockchain. Mean, that's more than a funny quirk. It's like literally the linchpin. Right? It's just like it it has to be that way. Right. No.
486
00:38:43.280 --> 00:38:46.320
It doesn't. They they he could have put the Genesis block UTXO
487
00:38:46.320 --> 00:38:48.000
in the. It just didn't
488
00:38:48.555 --> 00:38:50.955
didn't matter. It is poetically,
489
00:38:51.595 --> 00:39:02.234
like, good. Like, ah, yes. I created this. And from this Genesis block, I cannot ever get that money. I can't print myself my own money. Because that's actually what he's saying is that since the only block that was ever just made
490
00:39:03.660 --> 00:39:08.060
without anyone else ever being able to participate in the network is the Genesis blocks.
491
00:39:08.780 --> 00:39:13.740
Right? And then after that, he had to do work by mining the CPU. So there's, like, a philosophical
492
00:39:13.740 --> 00:39:15.980
beauty I see. In making that unspendable.
493
00:39:16.235 --> 00:39:23.035
But if you also remember, it was six days between the first time he created the Genesis block and he actually started mining.
494
00:39:23.515 --> 00:39:43.505
He waited for it was from January 3 to January 9. So he gave an opportunity for the rest of the world to start mining So like, it's much more of a philosophical think boy piece on that. It's not technically a reason why he had to do it that way. What I guess what I wanna ask is we're just flesh out. There's two types of attackers. Right? There's the kind of attacker that wants value.
495
00:39:43.985 --> 00:39:49.665
And there's a kind of attacker that wants to send the Bitcoin network that wants the Bitcoin network control.
496
00:39:50.065 --> 00:39:52.545
These are two clear archetypes.
497
00:39:53.825 --> 00:39:55.185
They probably both exist.
498
00:39:55.750 --> 00:40:05.030
We will assume they both exist. I think it's safe to assume that they both we don't know if they're both well funded and actively trying to do these things. But we can we assume they are right?
499
00:40:05.350 --> 00:40:07.110
Probably correctly assume they are.
500
00:40:08.870 --> 00:40:10.230
So is the value,
501
00:40:11.095 --> 00:40:11.655
right?
502
00:40:13.095 --> 00:40:14.375
Have different incentives,
503
00:40:14.535 --> 00:40:16.695
right? And there's a different ROI
504
00:40:17.175 --> 00:40:21.335
threshold that probably for both of them. Right? So the guy looking
505
00:40:22.775 --> 00:40:27.030
for value isn't attacking isn't going to attack Satoshi's coins, he's gonna try
506
00:40:27.030 --> 00:40:35.910
to prevent anyone from doing that. And he's going to try to another good point Alex made on a podcast somewhere that I'm going to attribute this to him is like, they're going to go after some
507
00:40:36.550 --> 00:40:37.270
three bit
508
00:40:38.465 --> 00:40:56.480
exchange that no one's gonna know that no one's even gonna know they hit them, right? Or some UTXO that's not a Satoshi UTXO, but it's very old and has more than 50 coins in it. So there's a bunch of those out there, right? That have a few 100 coins that someone turned on a miner for few weeks in the early days, mined some Bitcoin and then never moved on, probably because they deleted the wallet at that. I think I may have And done that
509
00:40:57.119 --> 00:41:10.935
so there are outputs out there that are larger than 50 and are probably dead, and they're going to go after those because they'll be able to get those without totally taking the value. You'll be able to liquidate them. Right? And that's less where you're gonna get value. But right. The attackers
510
00:41:10.935 --> 00:41:13.095
want to go after Satoshi's
511
00:41:13.095 --> 00:41:13.975
going strictly
512
00:41:14.055 --> 00:41:16.935
because of the impact that's gonna have. Right. To take the network. Yeah.
513
00:41:18.080 --> 00:41:24.880
Like the price will tank and maybe they again, maybe it's a one two punch, you know, they first they first they scalp the coins
514
00:41:25.200 --> 00:41:27.520
for themselves and then they then
515
00:41:27.680 --> 00:41:45.515
they tank the value and spend the public and buy more coins or whatever. Yeah. Yeah. Who knows? But like that. But I think it's good to see the world as those two type those two archetypes and maybe what they're likely to do. And we don't wanna collapse them into one thing. You'd also do this attack, and then you would go short Bitcoin and double dip on the price volatility.
516
00:41:45.515 --> 00:41:47.995
Nice. Nice. If you're gonna If you're gonna do sell.
517
00:41:48.640 --> 00:41:49.520
Yeah. Yeah.
518
00:41:51.680 --> 00:42:04.195
Yes. Sorry. I was just calling my calling my Yeah. But I think for the main character centric point, was that about Bitcoin always make like, us and Bitcoin culture, I mean, that's always the main character? We still think like so we have this probability space
519
00:42:04.195 --> 00:42:05.315
that we have
520
00:42:07.155 --> 00:42:08.275
we're assessing
521
00:42:08.515 --> 00:42:13.795
what the likelihoods are, right? But then there's if you zoom out of that probably it's like so it's like Venn diagram,
522
00:42:14.820 --> 00:42:17.620
but when you zoom out, there's a world around
523
00:42:18.340 --> 00:42:21.620
that Venn diagram too with other entities. So like,
524
00:42:21.940 --> 00:42:23.860
whatever probability we think,
525
00:42:24.340 --> 00:42:31.775
whatever probabilities we sort of get comfortable with ourselves, they're probably haircuts by the likelihood that Bitcoin is not the main target,
526
00:42:32.015 --> 00:42:32.895
which is not
527
00:42:33.375 --> 00:42:40.015
one, not zero, something between zero and one of right. There's just some likelihood that Bitcoin isn't even the main target of
528
00:42:40.655 --> 00:42:48.780
these first waves of quantum computers is very likely that we'll find out quantum computer exists without Bitcoin being affected at all. I mean,
529
00:42:49.420 --> 00:43:00.300
goes to a thing that's often described about with the game theory if you had a cryptographically relevant quantum computer is you would the the best example we have of this is the cracking of enigma during World War two.
530
00:43:01.045 --> 00:43:06.085
Right, and where the the allied powers actually figured out the German decryption
531
00:43:06.085 --> 00:43:09.125
scheme, was able to decrypt it. They let planes
532
00:43:09.525 --> 00:43:14.645
get shot out of the sky, ships get sank, people die, civilians and military
533
00:43:14.645 --> 00:43:15.525
troops die.
534
00:43:16.779 --> 00:43:17.660
Because
535
00:43:17.740 --> 00:43:24.220
to it was more important to continue the illusion they did not know what was happening because there were higher strategic things at play.
536
00:43:24.539 --> 00:43:25.500
And so
537
00:43:26.059 --> 00:43:27.740
I actually think the biggest
538
00:43:28.140 --> 00:43:28.700
utility
539
00:43:29.385 --> 00:43:32.665
for a quantum computer is not Bitcoin. It is decrypting secrets.
540
00:43:32.905 --> 00:43:36.585
Right? You could hack a server For many the encrypted files,
541
00:43:36.745 --> 00:43:39.225
and you just sit on them and wait until a
542
00:43:39.945 --> 00:43:45.800
cryptographically relevant quantum computer comes to allow you to decrypt the said files. Yep. That is 1000%
543
00:43:46.440 --> 00:43:53.160
the most important tippy top thing. China doing to The US and US doing to China and everyone doing it to each other. That is
544
00:43:53.480 --> 00:43:55.640
the actual most important thing with a quantum computer.
545
00:43:56.275 --> 00:43:58.435
But those are not directly monetizable. Especially
546
00:43:59.155 --> 00:44:04.675
can I just add on to that? Especially if you are like, you know what? I can I can
547
00:44:04.835 --> 00:44:15.670
I can wax Bitcoin whenever I want, by the way, with this thing, but it's not the most important thing? Right. Well, that that's right. And and the moment you whack Bitcoin and you make this a public show that you've cracked Bitcoin,
548
00:44:15.750 --> 00:44:20.630
everyone's going to assume now that all encrypted secrets that have ever been lifted are now revealed.
549
00:44:21.750 --> 00:44:23.750
So it's it's a very big deal.
550
00:44:24.465 --> 00:44:27.665
Like, Bitcoin could easily 10 x in value,
551
00:44:28.145 --> 00:44:48.390
and the and the US government could have a way to break all of Bitcoin, and they still wouldn't do it. Like, that would make sense in a game theory playing out of the structures of the system. Like, that's an entirely plausible thing that people don't talk about. They assume the moment you get to a cryptographically relevant quantum computer, you're gonna pop Bitcoin. And it's like That's my point. You know, like, US
552
00:44:48.950 --> 00:44:52.150
Right. That's the haircut that I was talking about. Right? So it's like,
553
00:44:53.195 --> 00:44:59.995
maybe it's zero. It's You know, it's like You've, like it could you just made a case that it could never happen potentially. It could never happen. So just to be clear,
554
00:45:00.395 --> 00:45:09.660
the The US gross domestic product, and you can have caveats on how it's measuring all that, but this is just one year of economic activity is $33,000,000,000,000.
555
00:45:09.900 --> 00:45:13.100
So, like, Bitcoin is, like, It's two
556
00:45:13.100 --> 00:45:18.540
worth 2% of that. And that's every year. Right? So ten years of economic activity,
557
00:45:18.860 --> 00:45:25.045
the value of the Bitcoin is now a basis point in basis points. Or if you're talking about a decade. So, like, why
558
00:45:25.924 --> 00:45:35.765
why would you give up that edge? Because The US would be able and, you know, from a military strength and coordination. What if, like, janitor breaks in breaks into the room where the quantum computer is?
559
00:45:37.059 --> 00:45:39.940
Goodwill hunting. I did that just to see Brandon's face.
560
00:45:40.339 --> 00:45:43.300
So so the do you even even put kind of a finer point on it?
561
00:45:44.420 --> 00:45:46.900
If you have a a cryptographically
562
00:45:46.900 --> 00:45:48.180
relevant quantum computer,
563
00:45:48.740 --> 00:46:03.175
let's say you're a let's say you're a shady actor. Right? So people are like, oh, what about what about if some some bad actor, whether it's North Korea or whoever else? Maybe they're gonna go after Bitcoin. Rob Rob said it earlier even. Well, but, you know, the also they could do, if they could get some Internet traffic that might reveal
564
00:46:05.175 --> 00:46:05.895
business plans,
565
00:46:06.320 --> 00:46:14.240
They could they could make more money trading the market with the information they get from a quantum computer than they could from buy from from stealing Bitcoin.
566
00:46:14.640 --> 00:46:28.275
So so there I mean, it it is really this kind of mixed thing where, yes, Bitcoin could be a target. I said that earlier and I stand by that, but it's not the only target and it really depends on who the actor is. Who gets it makes a huge difference.
567
00:46:30.115 --> 00:46:30.835
Bingo.
568
00:46:30.915 --> 00:46:32.355
And also how fast it is.
569
00:46:35.119 --> 00:46:36.400
Is there any chance
570
00:46:37.359 --> 00:46:40.640
that there has been one that's existed for a long time and we just
571
00:46:41.039 --> 00:46:44.000
don't know? And think it's With this wild goose chase. It
572
00:46:44.880 --> 00:46:47.440
wouldn't surprise me at all. This is what
573
00:46:48.375 --> 00:46:50.855
quantum proponents point to that, like, basically,
574
00:46:51.415 --> 00:46:55.175
when the nuclear bomb development happened, like, paper started
575
00:46:55.335 --> 00:47:05.390
not being published anymore, and all of the professional industry leading people kind of disappeared from Indi because they were just working at Los Alamos. Like, they were just working for the US government,
576
00:47:05.630 --> 00:47:08.110
on a on a field somewhere
577
00:47:08.190 --> 00:47:15.869
to try and, like, advance this stuff. You could make that case that's already happened with Quantum, and and maybe it has. And that would and if that's true,
578
00:47:16.805 --> 00:47:39.820
we're living in the thesis we're just talking about right now where, like, they would they have cracked it, and they do not care about Bitcoin because Bitcoin is still such and this could be a point about main character syndrome. We think Bitcoin is literally everything as a 1 and a half trillion dollar asset. It's like, buddy, that's percent that's that's 2% of The US GDP per year. And at the level of nation states, you're talking about wealth and you're talking about centuries time horizons.
579
00:47:40.140 --> 00:47:49.425
It's it's irrelevant for them today. Also think it's the top priority of all governments in the world to eliminate it. We think it's the we just Yep. Bitcoin
580
00:47:50.305 --> 00:47:54.305
strategic reserve though, man. Come on. It's gonna It's change
581
00:47:54.305 --> 00:47:59.450
weird though that it's it may end up just being such a poison pill that it never gets touched.
582
00:48:00.650 --> 00:48:02.490
Because it's a public disclosure.
583
00:48:03.930 --> 00:48:05.530
Because it's a public ledger.
584
00:48:05.770 --> 00:48:10.250
So yeah, I just think it's good to zoom out and think about this rationally.
585
00:48:10.410 --> 00:48:10.569
And
586
00:48:12.355 --> 00:48:14.755
one of the things I had objected to from
587
00:48:14.995 --> 00:48:17.155
Alex's framing was this
588
00:48:17.155 --> 00:48:18.035
is such a
589
00:48:18.915 --> 00:48:22.115
non mathematical appeal to people. But he would say,
590
00:48:22.435 --> 00:48:25.475
if there's only 1% chance, we have to take this very, very seriously.
591
00:48:26.270 --> 00:48:32.830
And like, after everything we just said, you have to like the likelihood is so much less than 1%.
592
00:48:33.790 --> 00:48:36.430
But like that talking point is very powerful still.
593
00:48:37.150 --> 00:48:40.349
Yeah. And that's part of why
594
00:48:39.285 --> 00:48:43.925
I've used it various times, this background of of of a unicorn farting next to a quantum computer.
595
00:48:44.005 --> 00:48:45.685
Because the reality is
596
00:48:46.005 --> 00:48:46.565
that
597
00:48:47.045 --> 00:48:54.484
it's very easy to claim that there's a threat that has a low probability but a high severity and that we have to do something about it.
598
00:48:54.885 --> 00:48:57.900
And and so it cannot be the case
599
00:48:58.380 --> 00:48:59.100
that
600
00:49:00.300 --> 00:49:01.420
people running
601
00:49:01.980 --> 00:49:05.820
trillion dollar assets, not that huge in certain ways, but quite huge other ways,
602
00:49:06.300 --> 00:49:10.555
take action based on every tiny probability risk
603
00:49:10.555 --> 00:49:22.955
that has high severity that could be presented. Because I could probably come up with 20 of those in the next half hour and write write about them using a clinker. And, of course, Bitcoin is not gonna respond to those. So quantum these quantum folks, they have to have
604
00:49:23.195 --> 00:49:23.675
evidence
605
00:49:24.230 --> 00:49:26.070
that it actually is coming.
606
00:49:26.309 --> 00:49:32.070
And and more papers published does not necessarily equate to evidence that it's coming.
607
00:49:32.549 --> 00:49:37.109
No. It doesn't. It explicitly doesn't. Just one thing to close out there, the concept of parallel construction
608
00:49:37.825 --> 00:49:45.345
in, like, law enforcement. Like, you actually would it would actually be much more straightforward if you use a quantum computer to break inside of an exchange
609
00:49:46.145 --> 00:49:49.905
and lay out a plausible set of facts and then within
610
00:49:49.905 --> 00:49:56.120
exploit their business processes to hack them and not use the quantum computer to move the funds.
611
00:49:56.280 --> 00:50:00.200
You just entirely pwn their entire architecture using a quantum computer.
612
00:50:00.520 --> 00:50:01.960
And then you steal the funds,
613
00:50:02.280 --> 00:50:15.065
and you can bread crumb out a parallel construction of this was just sloppy security and bugs and breaking that happened, and you take the funds. So you used a quantum computer to move the funds, but you did not literally crack the keys and move them without consent.
614
00:50:15.145 --> 00:50:16.345
Like, that's just infinitely
615
00:50:16.505 --> 00:50:26.930
This is a five d man in the middle of But this literally happened in World War two. Yeah. That's exactly It's like the secret. Yes. That's exactly right. 11. You know, like, it's like what they that was Ocean's 11 where they just
616
00:50:27.250 --> 00:50:28.930
recreated a whole set.
617
00:50:29.250 --> 00:50:33.410
Right. Right. Yeah. Look like they were doing the thing. Yeah. Yeah. No. Bingo. But that that's
618
00:50:34.555 --> 00:50:49.835
and if you're talking about people, like, this is something I think in Bitcoin, we don't give enough credibility to the amount of intelligence someone who is trying to attack the network in one way or another would actually do. They just think that, like, they go to a level one analysis and, like, this is what they're gonna do. They don't think that maybe
619
00:50:50.370 --> 00:50:51.570
my enemies
620
00:50:51.730 --> 00:50:55.890
or people people who are trying to attack the Bitcoin network are more sophisticated
621
00:50:55.890 --> 00:50:58.530
than I would like them to think. And since I'm
622
00:50:58.770 --> 00:51:05.410
well, I'm a brilliant Bitcoiner. So I am a multilevel thinker, but those opponents You are. They are they are trivial,
623
00:51:05.410 --> 00:51:11.205
and they are not serious people. So they're gonna just do the first level analysis and the level of the threat attack.
624
00:51:12.005 --> 00:51:18.165
Did I ever give my NBA analogy on this? Where like, they're gonna grow 12 foot people
625
00:51:18.510 --> 00:51:20.510
because they're gonna make some no,
626
00:51:20.910 --> 00:51:25.790
there's a big financial incentive to grow 12 foot people because they can go and look at Victor Wimmin Yanma
627
00:51:26.190 --> 00:51:26.750
right now.
628
00:51:28.670 --> 00:51:30.750
Going to ruin the game. So like,
629
00:51:31.155 --> 00:51:34.355
that's obviously going to happen. And they clearly want to
630
00:51:34.595 --> 00:51:45.555
do that. So we probably should start changing the rules now. Right, we should make there be a height limit or move the basket now or whatever. Yeah, probably move the basket now is probably how we should. I
631
00:51:44.600 --> 00:51:48.440
it just sort of illustrates, I don't mean to be that absurd and dismissive.
632
00:51:48.440 --> 00:51:48.840
I
633
00:51:49.480 --> 00:51:55.400
don't like that I'm that way that that's somehow how I always have to communicate. But like, I don't mean to be that absurdist about it.
634
00:51:55.880 --> 00:51:57.720
But it does illustrate
635
00:51:58.585 --> 00:51:59.305
why
636
00:51:59.545 --> 00:52:09.945
it's stupid to start making changes when the probability is so far, no matter how catastrophic it is, when the probability is so far objectively below 1%.
637
00:52:10.400 --> 00:52:14.160
I don't think anyone can make a case that the probability is even close.
638
00:52:15.040 --> 00:52:16.240
Yeah, mean, that's where,
639
00:52:17.120 --> 00:52:21.600
you had a, in the pre show, we talked a little bit about this question of the mathematicians
640
00:52:21.600 --> 00:52:38.925
versus the physicists. I think it was a good time to segue into it because I would rather say and the physicists than versus. I don't know that we're a fancy Yeah. Term, but The mathematicians and the physicists working on quantum. And so one of the things that I think is really fascinating to watch, and actually also the engineers, so we need to add them in there as well, is that
641
00:52:39.450 --> 00:52:41.210
it is definitely the case,
642
00:52:42.730 --> 00:52:45.450
I would say with with almost certainty
643
00:52:45.530 --> 00:52:46.250
that
644
00:52:47.050 --> 00:52:47.770
if
645
00:52:48.089 --> 00:52:49.690
a low enough error,
646
00:52:49.849 --> 00:52:53.930
fast enough quantum computer with long enough coherence times could be built,
647
00:52:54.565 --> 00:53:05.125
that using Shor's algorithm, you can break Bitcoin secret keys into their public keys. Right? That's almost certainly true. So that's where we can say people say, well, the math is done. And that's, I think, a reasonably true thing to say.
648
00:53:06.460 --> 00:53:10.060
So if you're looking at quantum computing purely from the mathematical side,
649
00:53:10.780 --> 00:53:11.580
you can say,
650
00:53:11.900 --> 00:53:14.060
yes. It is done. It will work.
651
00:53:15.020 --> 00:53:24.695
And then you go to the physics side. And on the physics side, it's the view is a little bit different. The physics side says, well, we don't have proof because that's not really how physics works
652
00:53:24.934 --> 00:53:29.335
that a quantum computer could be built. We have theories
653
00:53:29.414 --> 00:53:34.855
under which it is highly likely a quantum computer of cryptographic relevance could be built.
654
00:53:35.255 --> 00:53:36.375
Right? But
655
00:53:37.359 --> 00:53:51.375
there are other possible theories that also explain all of our observable facts under which a quantum computer of cryptographic relevance cannot be built, and we don't know what's true yet. And so that's where physics is. Now the most popular theories
656
00:53:51.455 --> 00:53:54.495
say a quantum computer that's relevant is possible.
657
00:53:55.535 --> 00:54:00.815
But most popular and true most true are not the same. Right? Obviously,
658
00:54:01.970 --> 00:54:05.650
going back, to the very early days of kind of physics of this type,
659
00:54:06.849 --> 00:54:07.890
you know, the the
660
00:54:08.849 --> 00:54:09.650
heliocentric
661
00:54:09.890 --> 00:54:16.609
the sorry. The geocentric view of the of the solar system was wrong, but it was the most popular theory, and it explained
662
00:54:16.974 --> 00:54:19.215
the presently observable fact at the time.
663
00:54:19.615 --> 00:54:21.215
It's coming back, by the way.
664
00:54:21.694 --> 00:54:29.950
Fuck. So so so we we have to say we don't know which physics is correct yet because we yet haven't had
665
00:54:30.510 --> 00:54:47.495
the engineering, and we'll get to that next, to build a quantum computer of a size that would tell us which physics is more correct. Or if there's a whole other theory, like neither of the existing theories or none of the existing theories actually match the facts at some point, and we have to revise our theories. That's always the progress of science.
666
00:54:47.815 --> 00:54:49.495
And so when you go to the physics
667
00:54:49.655 --> 00:54:52.775
position, it's like, well, what we think is most likely
668
00:54:53.095 --> 00:54:56.135
makes it possible to build this quantum computer of of relevance,
669
00:54:56.775 --> 00:54:57.895
but we don't know yet.
670
00:54:58.214 --> 00:55:03.040
And then if you go to the engineering, well, we are still in the process of building the quantum computer
671
00:55:03.040 --> 00:55:06.400
that is advanced enough to even tell us which physics is correct.
672
00:55:07.200 --> 00:55:15.120
Right. And so far, we haven't even been able to get a quantum computer to the coherence time and the size where it can tell us which physics is right.
673
00:55:15.974 --> 00:55:18.695
And so depending on where you query
674
00:55:18.934 --> 00:55:26.375
the quantum computing research, you get totally different answers as to whether it's likely or unlikely that it's possible. Mathematically,
675
00:55:26.454 --> 00:55:28.375
totally, we are there. Physics,
676
00:55:29.230 --> 00:55:30.110
we think
677
00:55:30.350 --> 00:55:33.870
the best theory would support it. Engineering,
678
00:55:33.950 --> 00:55:35.870
we haven't even been able to test the theory yet.
679
00:55:39.630 --> 00:55:41.310
Mathematically though, you've only
680
00:55:41.964 --> 00:55:43.645
done Shor's algorithm though.
681
00:55:44.765 --> 00:55:47.645
Would argue there's more probably if
682
00:55:49.005 --> 00:55:51.965
you looked into what is stopping the physics from working,
683
00:55:53.885 --> 00:55:56.684
may be Well, yeah, we kind of go back and forth physics to math. Yes.
684
00:55:57.630 --> 00:56:02.270
That are, So like the physicists will say, well, we ran into this problem in building
685
00:56:02.349 --> 00:56:06.430
Well, the engineers will say, we built the thing and it broke in this way. The physicists will say,
686
00:56:07.230 --> 00:56:08.030
here's
687
00:56:08.349 --> 00:56:12.030
the physics behind why that broke. Mathematicians, is there a way we could use
688
00:56:12.714 --> 00:56:21.595
this evidence to create error correction that will overcome these challenges? And kind of go back and forth, engineering, physics, math, back and forth. And so that's where the new Google paper was basically
689
00:56:22.234 --> 00:56:23.915
a mostly pure math paper
690
00:56:24.075 --> 00:56:30.110
that said, Oh, if we can get the physics and the engineering to work in this way,
691
00:56:30.589 --> 00:56:31.869
we can dramatically
692
00:56:31.869 --> 00:56:38.430
reduce the number of physical qubits we need to build to achieve a certain level of computation to run Chor's algorithm.
693
00:56:39.230 --> 00:57:03.390
But there's several layers of ifs in that. And now we go back down to the physics and the engineering and we say, okay, physicists figure out what physical properties we exploit to build that kind of qubit, can run this math, and then the engineers go and try and physically build that. And so far in quantum computing, every time we do that loop, the engineers go and say, oh fuck, we built it the way you said based on the physics, and we hit some roadblock where
694
00:57:03.470 --> 00:57:10.750
the errors are higher, the noise is greater, the heat is too high, whatever the thing is, the engineers say, actually, everything you said
695
00:57:11.595 --> 00:57:14.315
that worked in theory, when we tried to put it into practice,
696
00:57:14.555 --> 00:57:18.955
we ran into a hard roadblock, run it back up the tree, get some new math, get some new physics, and try it again.
697
00:57:20.075 --> 00:57:20.635
Yeah.
698
00:57:21.035 --> 00:57:21.595
And
699
00:57:22.315 --> 00:57:25.435
I got triggered when you said the pure math guys because they're
700
00:57:26.760 --> 00:57:29.640
working for Google, right? And it's almost it's like a
701
00:57:30.200 --> 00:57:32.200
little nefarious. This is why I
702
00:57:34.680 --> 00:57:39.960
get so concerned about like my child who's a pure math major ending up working for
703
00:57:41.435 --> 00:57:46.875
the enemy like that, you know, and we're having their skills build, like, you build somebody
704
00:57:47.355 --> 00:57:51.755
to be able to do that. And then they end up in a hay, they end up working towards,
705
00:57:52.315 --> 00:58:00.470
it's a little nefarious, don't you? Like I just think it's a little bit nefarious because I feel like at Google, they understand how the public views this. They understand the low bar
706
00:58:01.030 --> 00:58:06.230
for causing a ruckus. So like they have a bunch of egg, they have a bunch of people that are,
707
00:58:06.845 --> 00:58:12.205
they, you know, maybe they studied pure math, but then they end up they're like high paid think tankers.
708
00:58:12.845 --> 00:58:18.525
And, you know, they have them do a paper. And then the next thing you know, BlackRock is leaning on miners to change
709
00:58:19.299 --> 00:58:24.900
the Bitcoin protocol. Like what you know what I mean? Like that, but like that chain of events is,
710
00:58:26.900 --> 00:58:28.900
you know, it's not entirely accidental.
711
00:58:28.900 --> 00:58:30.900
And it's not, it's definitely not
712
00:58:31.215 --> 00:58:33.375
driven by pure curiosity
713
00:58:33.935 --> 00:58:34.975
and concern.
714
00:58:35.215 --> 00:58:40.575
Yeah. I suspect that the the people who made the decision to redact that
715
00:58:42.095 --> 00:58:55.660
circuit layout for the the Google paper, at least some of those people did that intentionally to cause a ruckus. Now, I don't know exactly who to what but it would be surprising to me, frankly, if there wasn't intentionality
716
00:58:55.660 --> 00:58:57.980
on creating a ruckus with that redaction.
717
00:58:58.305 --> 00:59:12.065
They're like, this is good enough that we can get away with redacting it in this way. Let's use that to our advantage. Right? And and, of course, like, you can't just redact every little result because that would look foolish, but they're like, this one's good enough. We can redact it and make it look even worse. Right? Like, I I I they had to Totally.
718
00:59:12.830 --> 00:59:14.510
Totally. Yeah. Because
719
00:59:14.830 --> 00:59:15.710
just like,
720
00:59:16.590 --> 00:59:21.950
BC's researcher labs, like, if you're purely academic are also trying to get attention and funding.
721
00:59:22.110 --> 00:59:29.865
Like, it's not just companies. Anyone who's in a university or doing any leading research in anything is is trying to play a game in What was the redaction?
722
00:59:29.945 --> 00:59:38.265
Sorry. It was the circuit. The exact circuit to run this simple not simplified. This this lower More efficient. Version of Shor's algorithm.
723
00:59:38.745 --> 00:59:39.385
Yeah.
724
00:59:39.625 --> 00:59:59.985
And wasn't that, like, a week after, like, everyone just used AI to, like, partially reconstruct it? They're, like, 85%. Like like, people just started just racing to it because they revealed enough information that experts with large language models could basically closely approximate the exact layout of that circuit. I see. They leaked it temporarily and then redacted it too.
725
01:00:00.465 --> 01:00:05.505
No. They I think they were from the start, it was redacted. From the start, it was redacted.
726
01:00:05.985 --> 01:00:08.145
Oh, to give the illusion that it was like
727
01:00:08.785 --> 01:00:13.130
But it was legitimately an improvement in performance. It wasn't it wasn't an illusion,
728
01:00:13.210 --> 01:00:14.650
but it was to get attention.
729
01:00:15.450 --> 01:00:22.730
Like, it reminded they redacted me because they didn't wanna create risk. And it was like, but the the devices that could run this algorithm are are
730
01:00:22.970 --> 01:00:25.930
decades away. What what do you mean? What risk are you reducing?
731
01:00:26.170 --> 01:00:30.235
Like, it just didn't make any sense. The risk of not getting funding. Yeah.
732
01:00:31.035 --> 01:00:39.755
There used to be this old there used to be a radio show that would play, Obama speeches, but they would bleep out certain words that made it sound like he was cursing his head off.
733
01:00:42.075 --> 01:00:42.555
It's hilarious.
734
01:00:43.240 --> 01:00:47.000
And so like that so I'm wondering that is that what is that what this is
735
01:00:48.040 --> 01:00:49.880
a little bit? It just trying to create
736
01:00:50.360 --> 01:00:57.800
to that degree because they believe that's something something real. It wasn't like they made it up, but they did certainly use it to get more attention. I I think it's almost certain.
737
01:01:01.214 --> 01:01:02.175
Oh, man.
738
01:01:02.895 --> 01:01:09.694
Yeah, it's it would be like having a 12 guy, but it's just like having a funeral for that in a coffin.
739
01:01:12.620 --> 01:01:18.060
You know, we just we're gonna put a 15 foot coffin in the ground, say, Oh, that was part of our experiment
740
01:01:18.140 --> 01:01:23.340
to ruin the NBA. That's right. I'm
741
01:01:23.340 --> 01:01:24.300
committed to this analogy.
742
01:01:25.805 --> 01:01:26.845
No, mean, it
743
01:01:27.725 --> 01:01:30.365
does actually somewhat work. There's
744
01:01:30.365 --> 01:01:31.485
a thing that could happen
745
01:01:32.045 --> 01:01:36.285
maybe in the next thousand years. And so we're gonna start changing the rules now.
746
01:01:38.310 --> 01:01:41.750
Yeah. And the other thing with quantum that I think is so fascinating
747
01:01:42.310 --> 01:01:43.190
is that
748
01:01:47.110 --> 01:01:48.390
we all imagine
749
01:01:48.630 --> 01:01:52.275
that the engineering progress is gonna be straight line.
750
01:01:52.355 --> 01:01:57.954
And we think that, of course, because in many domains that ends up being true. I'm,
751
01:01:57.954 --> 01:02:02.195
of course, obsessed with Elon Musk. I'm a little bit of a sycophant, so I'll use some of his companies. Like,
752
01:02:02.595 --> 01:02:03.635
when Elon
753
01:02:03.714 --> 01:02:04.035
started
754
01:02:04.560 --> 01:02:05.520
Tesla,
755
01:02:06.480 --> 01:02:08.080
the reason he well,
756
01:02:08.400 --> 01:02:09.440
anyway, whatever.
757
01:02:10.880 --> 01:02:15.520
The reason that he got involved in Tesla was because someone convinced him that
758
01:02:15.680 --> 01:02:15.920
all
759
01:02:17.135 --> 01:02:19.535
of the necessary physics was solved.
760
01:02:20.575 --> 01:02:26.335
Because he he he had he had actually turned down getting involved in other battery electric company car companies before,
761
01:02:26.575 --> 01:02:45.270
and it was it was I think it was JB Struble convinced him that the battery tech was actually solved, and so it was time to do it. And so it had already been fully reduced to a engineering and production problem before he got involved. And so people like to to kind of imagine that that's where we are with Quantum, that it is fully reduced to an engineering and production problem.
762
01:02:48.335 --> 01:02:58.415
But that's obviously not the case. And we see this over and over again because we go back to fundamental physics over and over again to figure out new ways to try and get the quantum thing rolling.
763
01:02:58.895 --> 01:03:06.470
And so every time, there's a new advancement in it, like, oh, it's just engineering. It's just engineering. It's just engineering. It's not just engineering.
764
01:03:06.549 --> 01:03:09.109
And you can tell that because we see
765
01:03:09.270 --> 01:03:10.070
I think
766
01:03:10.549 --> 01:03:21.355
every few years for the last three decades, we've seen a totally new approach to building a quantum computer with different underlying physical materials, different physics rules, different qubits.
767
01:03:21.515 --> 01:03:24.955
Is it an atom? Is it a photon? Is it an electron? What's the qubit?
768
01:03:25.515 --> 01:03:34.040
And so it's obviously still in the fundamental research phase, not the engineering phase. And one of the ways you'll know it's in the engineering phase is that you'll see someone
769
01:03:34.920 --> 01:03:35.720
like
770
01:03:36.360 --> 01:03:38.200
a Steve Jobs and Elon Musk,
771
01:03:38.440 --> 01:03:39.480
what's this guy?
772
01:03:39.960 --> 01:03:48.095
Brett Scholl of Boom. There's these people out there who have a nose for, I can build a company on this. And
773
01:03:48.335 --> 01:03:50.815
those people, the really big hitters who know
774
01:03:51.135 --> 01:03:55.135
when it's time to build a company, are not investing in quantum. It's VCs,
775
01:03:55.215 --> 01:04:03.200
and it's these kind of smaller time CEOs who are hoping to be the next Elon Musk, Steve Jobs, etcetera. It's not the kind of the known
776
01:04:03.280 --> 01:04:06.880
decision makers who know how to smell when it's just an engineering problem.
777
01:04:07.440 --> 01:04:12.045
Yeah. VC can make their return on narrative. Doesn't have to deliver.
778
01:04:12.765 --> 01:04:13.165
It's
779
01:04:15.405 --> 01:04:19.245
very interesting. I guess it's like if I'm still committed to this analogy to
780
01:04:19.805 --> 01:04:26.050
the 12 foot people are the shores algorithm and teaching them how to walk. Like, we've never had one walk.
781
01:04:26.210 --> 01:04:27.090
So like,
782
01:04:27.250 --> 01:04:33.010
they all without breaking their feet. Like, there's no like, we haven't figured out how they how that works yet. Right?
783
01:04:35.010 --> 01:04:35.650
Yeah.
784
01:04:35.810 --> 01:04:38.690
Yeah. There's still fundamental problems in our 12 people.
785
01:04:39.714 --> 01:05:00.810
Yeah. It's like their bone structure just doesn't. I mean, I don't I mean, if you know the NBA at all, like, even anyone significantly over seven feet has all they've all like, none of them have ever delivered on their potential because they've all had foot problems. Well, I mean, once you I mean, the the the biological systems of how our joints and our bodies and our skeletal structures evolve assumed a certain range of heights.
786
01:05:01.530 --> 01:05:10.335
And to just because you technically could get the larger than that does not mean that the rest of the system was designed with those in mind and things, you know, entropy takes you down.
787
01:05:10.895 --> 01:05:11.375
Yeah.
788
01:05:11.695 --> 01:05:27.290
And we see this what's funny in other species too. Right? Like, large dog breeds have have major physical problems too. Their architecture supports a certain fairly wide range of sizes, but not up to the size of a of a a mastiff or a Great Dane. They really have a lot of physical problems.
789
01:05:29.290 --> 01:05:30.810
Rob, unfortunately, does
790
01:05:31.290 --> 01:05:32.490
knows this firsthand.
791
01:05:32.650 --> 01:05:38.090
I have a large dog. And by large dog, I mean, like, a 80 pound golden retriever yellow lab mix.
792
01:05:38.685 --> 01:05:43.645
And both both of both of his legs have been replaced in the past eighteen months.
793
01:05:44.605 --> 01:05:49.405
He tore his ACLs on both legs, and so he's now in fully in recovery. He's fine, but
794
01:05:49.725 --> 01:05:53.990
the it's a very common thing with that breed. Yeah. But these
795
01:05:54.310 --> 01:05:55.430
yeah. But it
796
01:05:55.830 --> 01:06:05.670
boy, we think think we we kinda went off. This is I'm gonna I'm gonna take the Allen. Yeah. If we're talking about my dog, we're really in the, the the bottom of the barrel. I love your dog, man. He's great.
797
01:06:08.255 --> 01:06:10.495
But he's not gonna play in the NBA.
798
01:06:11.215 --> 01:06:12.175
There
799
01:06:13.375 --> 01:06:16.415
is a valid point here in I
800
01:06:18.015 --> 01:06:18.495
think
801
01:06:19.550 --> 01:06:22.510
it's hard to even address people who think that
802
01:06:22.510 --> 01:06:26.830
it's just an engineering problem. It's such an absurdity,
803
01:06:26.830 --> 01:06:30.430
I guess, right? Because we're so far, again, we're so far away
804
01:06:30.990 --> 01:06:32.750
from that even being a serious statement.
805
01:06:33.875 --> 01:06:34.435
Well,
806
01:06:34.915 --> 01:06:39.635
problem of course is that the companies working on each of these different technologies publish
807
01:06:39.795 --> 01:06:40.915
PRs,
808
01:06:40.994 --> 01:06:51.260
which are picked up by the media and which say exactly that, right? Google posts the Majorana paper and they're like, This is now just an engineering problem. We have made reproducible qubits and we're going to just build chips.
809
01:06:51.660 --> 01:06:54.780
And then a few weeks later, they're like, Well, actually,
810
01:06:55.660 --> 01:06:58.540
we didn't really solve that and we only made one qubit.
811
01:06:59.500 --> 01:07:06.285
But they said that really quietly. The loud part is we've solved it, we're going to start building the production facilities next week is basically what the PR says.
812
01:07:06.685 --> 01:07:19.010
Yeah. And And so we can forgive people for thinking that because it's literally what the media tells them. And we know that most people, what they believe comes from the media. That's why I said to you, we started the whole thing with, I said to go read the papers. That's why I said to read the papers.
813
01:07:19.170 --> 01:07:20.130
Because the media,
814
01:07:20.849 --> 01:07:32.255
you cannot become informed about this topic or any other by reading the media. You have to go to more direct source material that applies to medicine, that applies to quantum physics, that applies to whatever you want to learn about. You have to read the source material.
815
01:07:32.815 --> 01:07:34.575
You're right about that. So when
816
01:07:35.935 --> 01:07:39.375
I met Brandon and I was like, can you help
817
01:07:40.095 --> 01:07:52.250
me get up on this issue? And he's like, yeah, but you got to read the papers. And I'm like, okay, great. I can read any paper. I don't care. It's fine. Good. Send them over. And he sent one over. And I'm like, after five minutes, I'm like, no, I'm not reading this paper.
818
01:07:52.569 --> 01:07:53.530
I couldn't. It
819
01:07:54.650 --> 01:07:59.775
was a bit The gap was so wide that I couldn't even see that I could
820
01:08:00.255 --> 01:08:01.535
attack the rabbit hole.
821
01:08:03.375 --> 01:08:03.935
So
822
01:08:04.415 --> 01:08:07.215
Yeah. No. That's totally understandable. I think it it
823
01:08:08.600 --> 01:08:24.094
I basically got tricked into going down the quantum rabbit hole and reading enough of the papers that I could start to put together the tree, if you will, you know, the the whole tree trunk analogy. You know? Yeah. When you start out and you're just reading a leaf, it's very, very hard to understand anything. And then you have to build a tree trunk and then you can start reading the leaf papers and and make sense of it. So
824
01:08:24.655 --> 01:08:25.695
sorry about that.
825
01:08:26.335 --> 01:08:26.974
When
826
01:08:28.255 --> 01:08:31.454
I found myself unable to grok
827
01:08:32.335 --> 01:08:34.094
the SecP256
828
01:08:34.255 --> 01:08:34.894
curve,
829
01:08:35.295 --> 01:08:36.815
I said to myself, this
830
01:08:37.614 --> 01:08:41.030
is within my aptitude in my lifetime, I will learn it.
831
01:08:42.150 --> 01:08:49.190
When I read, when I spread the paper you said to me, I was like, no, this is not. That was that sort of like how I assess these things.
832
01:08:49.670 --> 01:08:52.150
Yeah, I mean, again, it makes total sense.
833
01:08:52.804 --> 01:08:53.525
I
834
01:08:53.925 --> 01:08:58.324
got tricked into it. I I I didn't want to be the guy who goes on podcasts talking about quantum,
835
01:08:58.485 --> 01:09:21.900
but I could tell people were wrong on the Internet. I think Rob mentioned this earlier. But You it's an important thing. If people are wrong on the Internet, it has to stop, And I alone have the ability to fix it. It's basically I can fix I I can fix her. Like, that's what this whole thing is is I can fix it. I know you're being sarcastic, but I don't I I'm like, yeah. I know. You have to fix it. That's why it's good. That's why it's a good line. Exactly.
836
01:09:25.105 --> 01:09:28.065
No. And frankly, I think I've I've hopefully,
837
01:09:28.065 --> 01:09:35.345
I've actually helped in this area by being someone who got who got sniped into going down the quantum rabbit hole and reading a lot of the papers and then being able to kind of explain
838
01:09:35.860 --> 01:09:39.620
the gaps in where we are versus where the PRs say we are.
839
01:09:40.420 --> 01:09:41.620
Again, I
840
01:09:42.020 --> 01:09:48.100
can't like rule out that quantum computers could happen. It's just that it's not obvious and it's not tomorrow
841
01:09:48.340 --> 01:09:53.784
with extremely high probability. Right. I think if I'm being honest, I think the reason you
842
01:09:54.585 --> 01:09:55.304
saying
843
01:09:55.784 --> 01:09:58.184
a classical computer is gonna beat
844
01:09:58.585 --> 01:09:59.224
beat
845
01:09:59.545 --> 01:10:00.584
cryptography anyway,
846
01:10:02.025 --> 01:10:05.304
we should just I think the reason why that resonated with me so much
847
01:10:06.090 --> 01:10:10.170
is probably a cope because I had the aptitude to understand that.
848
01:10:11.370 --> 01:10:11.929
You
849
01:10:13.050 --> 01:10:17.209
could reason about the classical break potential more than Now I'm wondering did
850
01:10:18.489 --> 01:10:19.530
I screw myself up there?
851
01:10:21.275 --> 01:10:27.594
But that's like, that was a very that hit me very strong. And I think it's because it just validated for me that I'm okay.
852
01:10:28.554 --> 01:10:30.474
Maybe I should question that. Oh humans.
853
01:10:31.114 --> 01:10:31.755
Yeah.
854
01:10:33.355 --> 01:10:38.760
This we could like I have five other podcasts that I look at my own biases and
855
01:10:39.080 --> 01:10:41.400
do this laboriously trying to do here.
856
01:10:41.640 --> 01:10:42.200
But
857
01:10:43.240 --> 01:10:47.640
that's like that really is like you put me face to face with potential. I
858
01:10:48.040 --> 01:10:49.880
don't know something I might have
859
01:10:50.280 --> 01:10:51.080
made a boo boo here.
860
01:10:51.825 --> 01:10:52.385
There Maybe is a
861
01:10:53.425 --> 01:10:55.184
I have to learn the physics. I
862
01:10:55.265 --> 01:10:56.304
hope that's not the case.
863
01:10:57.425 --> 01:10:59.505
Well, the physics are just applied math.
864
01:10:59.825 --> 01:11:01.905
Well, not in these papers, dude.
865
01:11:03.025 --> 01:11:03.665
Not
866
01:11:04.305 --> 01:11:09.590
in the papers that Well, it applied math layers deep. There's a lot of jargon,
867
01:11:10.230 --> 01:11:12.630
which frankly, I think another bit
868
01:11:12.870 --> 01:11:13.749
of evidence.
869
01:11:15.750 --> 01:11:17.429
In my experience of the world,
870
01:11:18.070 --> 01:11:19.830
the higher the jargon content
871
01:11:20.375 --> 01:11:21.575
in a domain,
872
01:11:22.055 --> 01:11:28.135
the further it is from being kind of reduced to correctness. Now that's not an absolute,
873
01:11:28.535 --> 01:11:30.455
but it is commonly the case.
874
01:11:31.815 --> 01:11:36.480
And so I think with quantum, we're still in the very high jargon phase because
875
01:11:36.800 --> 01:11:38.320
there's so much uncertainty.
876
01:11:38.560 --> 01:11:43.600
And once we have more certainty around the theoretical basis and around the engineering,
877
01:11:43.680 --> 01:11:50.445
it'll actually start to get simplified. And why is that? Well, because in order to get enough people working on something to bring it to full production,
878
01:11:50.685 --> 01:11:53.485
you have to simplify and bring the language into readily
879
01:11:54.525 --> 01:11:55.325
accessible
880
01:11:55.325 --> 01:11:57.005
terminology that people can work with.
881
01:11:58.230 --> 01:12:04.869
So I think that's another piece of evidence in a certain sense that we're far from it is that we're still in these very high theoretical jargon
882
01:12:04.870 --> 01:12:14.864
areas. We haven't come up with the simple terminology that applies to the thing that's gonna actually work. That's what happens in those environments is Dun Kruger
883
01:12:15.025 --> 01:12:16.065
is
884
01:12:16.385 --> 01:12:19.985
a big factor and you end up with LARPs who
885
01:12:20.225 --> 01:12:21.985
have chauffeur knowledge who
886
01:12:23.105 --> 01:12:24.145
know the jargon.
887
01:12:24.545 --> 01:12:27.665
It's kind of wild, right? And then they pass it because
888
01:12:27.930 --> 01:12:31.610
somebody like me is like, yeah, you must be right. I can't read those papers.
889
01:12:33.290 --> 01:12:36.490
They got people just learn the jargon because they can,
890
01:12:36.890 --> 01:12:42.685
that's their access. And you end up with people who not only just learn the jargon, but they actually learn
891
01:12:43.005 --> 01:12:43.565
the
892
01:12:44.525 --> 01:12:45.805
the relationships
893
01:12:45.805 --> 01:12:47.485
between the jargon words
894
01:12:47.645 --> 01:12:52.765
between the the between the concepts represented by the jargon words only. They don't learn
895
01:12:53.005 --> 01:12:58.550
the the full stack, like, depth of it. And so there are people writing papers right now about quantum
896
01:12:58.630 --> 01:13:17.765
that are absolutely correct within all the relationships between the jargon words, but have no relationship to physical reality. And they don't know it yet because they think all those jargon words in the quantum space have a physical analog that they're working with. But what they're really doing is manipulating symbols that are disconnected from reality and hoping they someday become connected to reality later,
897
01:13:18.165 --> 01:13:19.205
but they don't know that.
898
01:13:20.725 --> 01:13:27.050
It's wild. And it's I mean, one of the reasons Rob and I do this podcast is so that we can get people used to the jargon
899
01:13:27.210 --> 01:13:31.130
going on in math. And if you do that thing here,
900
01:13:31.850 --> 01:13:40.614
you're gonna just learn math. Like you're not you know what I mean? You're not going to get wrecked by some misunderstanding. You're just gonna get used to math.
901
01:13:41.175 --> 01:13:42.294
But we do it
902
01:13:42.534 --> 01:13:44.454
here so that people just get used to
903
01:13:45.335 --> 01:13:46.614
the terms,
904
01:13:47.335 --> 01:13:57.600
closure, identity, all these things we talk about in groups and things like that. So the I was gonna say, man, I really hope that the solution involves elliptic curves because we spent like six episodes on it.
905
01:13:58.160 --> 01:13:59.040
That'd be cool.
906
01:13:59.840 --> 01:14:03.840
Have you done an episode on isogeny based crypto yet? Not yet. Not yet. But
907
01:14:04.775 --> 01:14:06.055
But let's
908
01:14:06.055 --> 01:14:08.295
hit that for a second if you don't mind.
909
01:14:08.935 --> 01:14:11.495
Because what we have talked about are
910
01:14:12.135 --> 01:14:13.495
isomorphisms.
911
01:14:13.815 --> 01:14:14.375
Okay.
912
01:14:14.695 --> 01:14:16.054
Really in the power,
913
01:14:16.375 --> 01:14:16.855
like
914
01:14:17.389 --> 01:14:24.030
the power of an isomorphism for me the whole when I started studying abstract algebra to learn cryptography,
915
01:14:24.510 --> 01:14:27.309
I had a light bulb moment that
916
01:14:28.829 --> 01:14:30.110
an isomorphism.
917
01:14:30.110 --> 01:14:34.545
So what's an isomorphism? It's basically two things that have the same exact,
918
01:14:34.785 --> 01:14:38.945
like algebraic structure. They preserve the same mathematical
919
01:14:39.105 --> 01:14:47.905
operation maps between them without loss. Perfect map, like backwards and forwards without loss, right? And what I saw was like, Oh my God, we might be
920
01:14:49.300 --> 01:14:50.739
convinced that
921
01:14:50.980 --> 01:14:53.860
we might be told that there's a solution
922
01:14:54.100 --> 01:14:56.260
to that's an isomorphism.
923
01:14:56.420 --> 01:14:57.860
But like who has
924
01:14:58.180 --> 01:15:00.020
the ability to do the proofs
925
01:15:00.595 --> 01:15:03.715
and validate these things? And then I was like, Oh, I guess
926
01:15:04.355 --> 01:15:12.515
we're just gonna have to trust Andrew Polstra or Jonas, Nick or whoever it is that tells us and they're probably I mean, certainly they're trustworthy. But is that really how we want to be here?
927
01:15:13.719 --> 01:15:17.000
But it was really came down to the power of an isomorphism
928
01:15:17.000 --> 01:15:20.119
where you have two things that don't look like each other at all.
929
01:15:20.840 --> 01:15:22.679
But have they're essentially
930
01:15:22.920 --> 01:15:24.599
equal for the mathematical
931
01:15:24.920 --> 01:15:30.675
purposes of what you're trying to do. And one of them can be operated on very easily and one can't.
932
01:15:33.795 --> 01:15:38.035
Me that so that's my understanding of an isogeny. It's not an isomorphism,
933
01:15:38.035 --> 01:15:39.475
it's called an automorphism,
934
01:15:39.475 --> 01:15:40.915
right? Which is essentially
935
01:15:41.130 --> 01:15:43.610
similar idea, but onto itself.
936
01:15:45.290 --> 01:15:48.489
But you have an elliptic curve that's something
937
01:15:48.889 --> 01:15:53.850
morphic either isomorphic or automorphic to the Bitcoin elliptic curve. Is that correct?
938
01:15:56.985 --> 01:16:00.185
It's not that it's to the Bitcoin curve. So in
939
01:16:00.185 --> 01:16:04.344
a strategy based crypto, we would start from a totally different curve. And actually,
940
01:16:04.824 --> 01:16:10.264
you'd end up having several curves involved. And what you're doing with isogenies is
941
01:16:10.750 --> 01:16:14.910
you're writing the relationship between points on one curve and the other curve
942
01:16:15.870 --> 01:16:17.469
and discovering
943
01:16:18.750 --> 01:16:21.550
that relationship. That relationship is your secret key.
944
01:16:22.270 --> 01:16:26.915
So it's an extra layer of abstraction, basically. Instead of being told it's x
945
01:16:27.715 --> 01:16:39.320
cube plus seven. We're actually just saying there's a it's the image now it's not the actual curve itself. Now we're going to speak in terms of like the image of that curve with
946
01:16:39.320 --> 01:16:41.639
a secret abstraction between a and b.
947
01:16:42.520 --> 01:16:48.599
Yeah. And there would be one curve that's like the base curve because there are certain curves have the property that
948
01:16:49.159 --> 01:16:49.959
it's
949
01:16:50.679 --> 01:16:52.599
easy to create isogenies
950
01:16:53.315 --> 01:16:55.715
based on from them to another curve.
951
01:16:57.155 --> 01:17:06.515
Easy to create, but difficult to reverse. Is that what you mean? Difficult to discover that relationship. So just because you know a bunch of points on both curves, you can't tell what the fundamental relationship is
952
01:17:06.950 --> 01:17:09.590
that's that's being used to map points between the two.
953
01:17:11.750 --> 01:17:21.794
Yeah. I that's about as far as I can go on it so far. I need to reread Conduition stuff on it and and load it up again. But but the the long and short is that when you're doing isogeny is you're no longer
954
01:17:22.195 --> 01:17:24.675
It's no longer about whether one curve
955
01:17:24.914 --> 01:17:29.635
has certain properties with the generator point and stuff. Instead, it's about the relationships between curves.
956
01:17:30.275 --> 01:17:34.114
Right. That makes sense. So what makes sense is that
957
01:17:35.940 --> 01:17:43.220
this may not be the greatest analogy in world, but it's the one that's coming to my mind now. It's sort of, it's Endomorphism,
958
01:17:43.220 --> 01:17:45.060
that's the word we were looking for before. Endomorphism,
959
01:17:45.060 --> 01:17:45.780
which
960
01:17:46.180 --> 01:17:51.684
is image based. That's really now it's image based. So the analogy coming to my mind is basically
961
01:17:53.045 --> 01:17:55.524
a pay to pub key versus a pay to pub key hash.
962
01:17:56.485 --> 01:18:00.484
You're taking one extra, you're making it one degree harder.
963
01:18:01.605 --> 01:18:05.720
Yeah, and it getting bigger because instead of having a point,
964
01:18:06.120 --> 01:18:07.000
you now have
965
01:18:07.480 --> 01:18:13.320
I forget exactly what the keys are. There's several points that define an isogeny that become your key.
966
01:18:13.880 --> 01:18:18.840
And so you end up with a multipoint key, I forget exactly all of that. The details are blurry at this point. I have to read it again.
967
01:18:19.875 --> 01:18:23.395
But yes, it is somewhat similar where you're still using elliptic curve,
968
01:18:24.355 --> 01:18:29.954
but instead of the relationship, instead of the secret key being something that can be derived by going from a point through
969
01:18:30.435 --> 01:18:31.715
the generator back to
970
01:18:32.700 --> 01:18:34.380
its scalar.
971
01:18:34.540 --> 01:18:35.179
Instead,
972
01:18:35.420 --> 01:18:41.980
it's being able to take the multiple points that define which endomorphism you're exploiting and discover
973
01:18:42.540 --> 01:18:47.340
that relationship. And if you have that relationship, then you can generate more points and that lets you therefore
974
01:18:48.115 --> 01:18:50.594
make signatures. But if you don't know the relationship,
975
01:18:51.315 --> 01:18:54.755
just because you know points doesn't give you that relationship and you can't make signatures.
976
01:18:55.795 --> 01:18:56.435
Yeah.
977
01:18:56.595 --> 01:18:57.715
I'm
978
01:18:57.715 --> 01:19:05.650
seeing an analogy with Schnoor too here, just in terms of we're attracting another layer and how it's so interesting. We talked we talked about before where Schnorr,
979
01:19:06.130 --> 01:19:07.810
the in ECDSA,
980
01:19:07.810 --> 01:19:08.610
the signature
981
01:19:10.370 --> 01:19:14.050
is not part of the closure. It's just the points on elliptic curve, but in Schnorr,
982
01:19:14.370 --> 01:19:24.554
signature itself is a variable that's part signature plus another signature is also is is also a signature. So it's it's also I I see it right there. There there's the they are
983
01:19:24.954 --> 01:19:25.915
algebraically
984
01:19:25.915 --> 01:19:26.635
related,
985
01:19:27.034 --> 01:19:28.315
but both the the points
986
01:19:29.070 --> 01:19:43.950
the the public keys, the secret keys, the signatures are all algebraically related within Schnorr. Whereas in ECDSA, you break the algebraic relationship between the signature and the two points, the public and private key. Yeah. Yeah. We literally talked about this on our last episode. This isn't this is not I'm comfortable that our audience is good with this.
987
01:19:44.695 --> 01:19:45.414
Cool.
988
01:19:46.135 --> 01:19:47.655
There are dozens of us.
989
01:19:51.895 --> 01:19:53.414
Yeah, I mean, and I love
990
01:19:54.135 --> 01:19:57.415
that it went here finally, right? Because this is
991
01:19:57.590 --> 01:20:02.469
so Rob and I made a study guide and we spent six ish episodes
992
01:20:02.630 --> 01:20:03.989
strictly on
993
01:20:04.630 --> 01:20:08.309
how to validate a private key from a public key
994
01:20:08.949 --> 01:20:09.909
in
995
01:20:10.389 --> 01:20:20.664
the current elliptic curve cryptography, like how you know that you can do that because you know the properties, you know the algebraic properties, you understand that elliptic curve is
996
01:20:22.745 --> 01:20:36.800
a group, the points in the elliptic curve under the operation of addition or a group and you can go backward and you know a group has an inverse and an identity and you can, if you know the public key, you know, it's possible to back into the private key, you may not be able to do it
997
01:20:37.280 --> 01:20:40.639
with your classical computers or all of them. But you know that
998
01:20:41.520 --> 01:20:42.080
it resolves.
999
01:20:44.215 --> 01:20:48.454
Slight side note, we have distinguished that somebody we have not proven.
1000
01:20:49.175 --> 01:20:53.255
Rob and I have not done a proof to say that the elliptic curve is a
1001
01:20:53.575 --> 01:20:54.135
group.
1002
01:20:54.695 --> 01:20:55.095
So
1003
01:20:55.590 --> 01:20:59.510
and that's actually not easy to do, and I've assigned my daughter with that problem.
1004
01:21:01.190 --> 01:21:05.909
Yeah. That that's actually the part where my knowledge of of elliptic curve cryptography, your current
1005
01:21:06.310 --> 01:21:08.550
ECDL based elliptic curve
1006
01:21:09.155 --> 01:21:09.955
cryptography,
1007
01:21:09.955 --> 01:21:12.835
I don't understand the math of
1008
01:21:13.075 --> 01:21:13.795
how
1009
01:21:14.835 --> 01:21:16.675
when someone says, oh, it's it's
1010
01:21:17.315 --> 01:21:25.370
what is it? It y equals b x plus seven or something or a x plus seven? Y y squared equals x cubed plus seven. There we go.
1011
01:21:25.770 --> 01:21:26.810
How
1012
01:21:26.810 --> 01:21:27.850
do you prove
1013
01:21:28.250 --> 01:21:29.690
that that curve
1014
01:21:30.090 --> 01:21:31.449
has
1015
01:21:33.210 --> 01:21:34.010
the same
1016
01:21:34.570 --> 01:21:35.929
group properties
1017
01:21:36.330 --> 01:21:39.130
as what you as the
1018
01:21:41.015 --> 01:21:46.855
field within which you're operating. So you define the group within a finite field of
1019
01:21:47.095 --> 01:21:53.669
possible x and y values for the points. And then how do you know that each point is
1020
01:21:54.949 --> 01:21:57.269
uniquely represented and can be reached
1021
01:21:57.510 --> 01:22:00.789
through the through the the the cycle of addition
1022
01:22:01.989 --> 01:22:06.704
so that there's a a one to one mapping, therefore, between the possible secret keys and the possible points.
1023
01:22:07.025 --> 01:22:20.480
I don't understand that. I know it I know that they do that before they accept one of these curves and and and and decide on the the secret keys and everything, but I I don't understand it. That is a priority of the Magic Internet Math Academy is to publish that paper.
1024
01:22:21.440 --> 01:22:24.239
We we took that for granted this entire time.
1025
01:22:24.960 --> 01:22:34.184
But when you get to that point, I wanna read it and learn it because that's the part where my knowledge breaks down. I know there are cryptographers out there who, like, study the curves Mhmm. And and develop
1026
01:22:34.344 --> 01:22:35.464
kind of demonstrations
1027
01:22:36.744 --> 01:22:40.824
essentially that Yes. The curves are correctly mapped, but it's it's beyond me.
1028
01:22:41.385 --> 01:22:51.079
Yes. So that's I I we had been calling that a bit of a red herring, but that's now now that we've gotten now that we've gotten there I mean, we've done 10 episodes just on libsec p.
1029
01:22:51.560 --> 01:22:55.800
Lib not the the curve itself and libsec p is implementation of said curve.
1030
01:22:56.885 --> 01:22:57.684
That's great.
1031
01:22:59.445 --> 01:23:04.405
Next level, I'm not sure if you have anything else left, Brian. Don't It's always you know, so I think
1032
01:23:04.725 --> 01:23:10.965
it's always good when a guest gives us homework. That's right. That's right. We have to get through the rest of our Allen homework next.
1033
01:23:11.550 --> 01:23:13.469
We're gonna have to do hash functions.
1034
01:23:13.630 --> 01:23:14.749
We're getting there.
1035
01:23:15.150 --> 01:23:16.429
Allen's coming back.
1036
01:23:16.750 --> 01:23:19.389
We've talked about it. It's happening. Excellent.
1037
01:23:19.469 --> 01:23:20.429
This was great.
1038
01:23:20.989 --> 01:23:21.389
Was great.
1039
01:23:22.158 --> 01:23:24.558
Brandon, thank you so very Thank you.
1040
01:23:25.278 --> 01:23:29.438
Good talking to you guys. Yeah. Awesome. Thanks guys. See you for fun. Catch you later.