[Cryptography] Why full-fledged quantum computers might always be five years away

Jon Callas jon at callas.org
Tue Aug 4 03:45:43 EDT 2026



> On Aug 3, 2026, at 04:01, Pierre Abbat <phma at bezitopo.org> wrote:
> 
> On Sunday, August 2, 2026 10:52:07 AM EDT Henry Baker wrote:
>> So, our current best hope for QC is more effective "quantum error
>> correction" (QEC).
> 
> How long will it take to make QEC good enough that Shor's algorithm can break 
> a 512-bit elliptic curve? A 4096-bit Diffie-Hellman field or RSA key?
> 
> It's pretty easy to generate a Fouvry prime with thousands of bits to make it 
> hard for Shor's algorithm. How hard is it to generate an elliptic curve so 
> that the number of points is a small multiple of a Fouvry prime?

I'll see your question and raise you.

How long will it take to make a QEC that can factor a 32-bit RSA key, or ECC key?

We're not there yet, as Peter has shown with amazing graphs.

Getting back to your questions, I think it will be a while -- because we haven't seen anything like what happened in older days where there were challenge numbers to factor. They're not doing it because they can't.

There are reputable quantum physicists who have opined that they don't think that it will ever be possible to factor RSA 2048. I don't buy this, myself, and at the same time I mention it because it's not just us cryptographers looking askance here, it's quantum physics experimentalists, too, who know how hard it is. I mean -- my guess is RSA 3K-4K around 2050 or so. I realize that the message that we have to do PQC as soon as is possible because we don't know, we're all just guessing, and cryptographic transitions take decades. It took us about twenty years to get integer public keys working right, twenty to iron the difficulties out of ECC, and things are still shaky in the PQC realm. And me -- I want a PQC transition so we can just stop talking about quantum computers here in math-engineering land.

	Jon



More information about the cryptography mailing list