Hope
The core working unit of a quantum computer is arguably not one qubit, but two. Single qubits give you superposition; two give you entanglement.
Today’s leading trapped-ion hardware, like Quantinuum’s 98-qubit Helios system, achieves an impressive two-qubit gate fidelity of 99.921%.
But in quantum computing, 99.921% is not good enough. Not even close.
For long calculations like Shor’s algorithm, there is only one right answer, and tiny errors compound across billions of sequential gates.
Therefore hardware roadmaps rely on Quantum Error Correction (QEC), bundling hundreds of noisy physical qubits into a single, fault-tolerant “logical” qubit.
At a 0.079% physical error rate (99.921 % fidelity), traditional 2D surface codes require roughly 1,000 to 1,200 physical qubits to yield one useful logical qubit.
A single entangled pair of logical qubits therefore requires over 2,000 physical qubits, before counting the extra overhead for dynamic routing, syndrome measurement, and fault-tolerant gate operations.
Noting that running Shor’s algorithm for RSA-2048 requires roughly 6,000 logical qubits, using standard surface codes we would need a staggering requirement of over 20 million physical qubits.
The solution? Trapped-ion systems can hopefully achieve all-to-all qubit connectivity, enabling denser codes (like qLDPC) that lower the physical-to-logical ratio down toward 100:1.
Even with optimistic 100:1 code rates and algorithmic shortcuts reducing the target to ~2,000 logical qubits, breaking RSA still demands hundreds of thousands of physical qubits.
Google says 2029. I’m more with 2129. But it doesn’t matter at all.
Public-key cryptography requires a mathematical operation that is easy to solve one way and effectively impossible to reverse without the private key.
But there is no known public-key cryptosystem with unconditional security. Every one depends on the proposition that nobody will discover a sufficiently efficient attack.
Some post-quantum candidates have already been mathematically cracked before useful quantum computers even exist.
My guess is that there will never be a permanently secure post-quantum public-key system. We will just move from one computational hardness assumption to another until mathematics catches up with each one.
If that is right, quantum computing does not merely threaten RSA. It eventually will kill the idea of public-key cryptography itself.
Symmetric encryption will survive. But then you have to distribute the secret key somehow, usually with carrier pigeons.
And we will have to find another use for all those groovy quantum computers.
But then, there was a time when Coke without calories looked technically impossible. And look at us now!
