itaibn0 comments on A proposed inefficiency in the Bitcoin markets - Less Wrong
You are viewing a comment permalink. View the original post to see all comments and the full post content.
You are viewing a comment permalink. View the original post to see all comments and the full post content.
Comments (138)
Grover's algorithm cuts hash strength in half. As I understand it, the whole point of 256 bit crypto is to survive the advent of quantum computers, when it degrades to 128 bits. Yes, a quantum computer shouldn't break SHA256, but quantum computers would almost immediately account for the vast majority of the hashing power, centralizing control of the currency.* Once everyone has quantum computers, it would work again (with a replacement public key system), but given such a disruption, I don't see much point to salvaging the old currency, rather than starting over.
* I think a gigahertz quantum computer would have the hashing power of the current bitcoin network.
Some relevant numbers: Based on the current target, I estimate that miners compute 5*10^18 hashes per block, 8*10^15 hashes per second. To match that, quantum computers working in mining need to compute 9*10^7 hashes per second.