Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Tuesday, July 21, 2026

Why Quantum Computing Matters, Even If You Never Touch One

I logged into my bank app last week to move some money to pay some bills. A padlock icon appeared next to the address bar. Secure connection. I didn't think about it again. Somewhere, someone already has a copy of that session, sitting on a hard drive, waiting.

That padlock runs on a math problem: factor a huge number into its two prime components. A classical computer needs longer than the age of the universe to do that. A large enough quantum computer, running an algorithm built for exactly this job, does it in hours. That computer does not exist yet. It is being built right now, funded by billions of dollars, and no government or company controlling that funding will announce the day it works.

You do not get to wait for that announcement. Security researchers call the attack already underway harvest now, decrypt later. Think about what you have touched on the web this year: your bank, your medical portal, your voter registration, your immigration or legal filings, your tax return, your cloud photo backup. State-backed intelligence services and criminal groups are copying that same traffic from millions of other people today, and storing it cheaply. Almost none of it needs to be cracked now. It needs to still exist, on somebody's drive, the day a quantum computer catches up. Then all of it becomes readable at once.

NIST finalized three new encryption standards built to resist this and set 2035 as the deadline to retire the vulnerable ones. Cloudflare and Google are not waiting until then; they have committed to migrating by 2029. Banks, hospitals, and government agencies holding decades-long records are moving faster still, because for them the clock already ran out on some of what they are protecting.

The fix is not a patch on the old method. It replaces the math underneath it. Government researchers finalized a new set of encryption methods built to survive a quantum computer, the same way today's methods survive an ordinary one. Companies are not waiting to switch over all at once, either. Cloudflare, Google, and Apple already run two locks on the same connection at the same time: the old one and the new one. If someone finds a weakness in the new lock, the old one still holds. If a quantum computer breaks the old lock, the new one still holds. Traffic protected this way stops being worth harvesting, because breaking one lock alone gets an attacker nothing.

Getting every bank, hospital, and government agency onto the new locks is the slow part. It means finding every place the old encryption sits inside a system and replacing it without breaking what depends on it. The federal government has published a shared plan for doing exactly that, across every agency and industry. None of it requires anything from you. It happens inside the apps and websites you already use.

The fix only protects what gets encrypted after it is installed, though. Anything copied under the old lock before that happens is already sitting on somebody's drive, and nothing reverses that. New encryption prevents future harvesting. It does not undo what has already been taken.

Diagram claude.ai generated

Nothing solves the data that is already sitting on somebody's drive. There is no way to reach into another party's storage, revoke a copy, or make it unreadable again. The new locks protect what gets encrypted after they are installed. They have no effect on a copy that left your device years earlier.

How much that matters depends on what kind of data it is. A password can be changed after the fact, so a stolen password loses most of its value once you reset it. A medical record, a Social Security number, or a biometric scan cannot be changed. Whatever gets exposed on that front stays exposed for good. It also depends on how long the data needed to stay private in the first place. Something that only mattered for a few years is probably already safe by the time a quantum computer shows up. Something that needed to stay private for decades, a government file, a company's trade secrets, a hospital's records, is running on a clock that started the day it was copied, not the day the quantum computer arrives.

Most people are not personally worth the effort. A patient attacker spends storage on high-value targets: government communications, corporate research, hospital systems, banks. If you end up exposed, it is more likely through one of those institutions holding your data than through anyone singling you out.

There is not much a consumer can do about data that is already gone. A few things still help:

   Rotate what can be rotated. Change passwords regularly. A password manager makes it cheap enough to do more than once.

   Turn on two-factor authentication. It stops a harvested password from being enough to log in on its own, since an attacker also needs your phone, an authenticator app, or a security key. It does not protect the data itself. A hospital record, a legal filing, or an old email that already left your device is untouched by it, because it only fires at login, not on the traffic that carries the data.

   Not every two-factor method is equal. A text message code can be intercepted or rerouted if someone tricks your phone carrier into moving your number to a new SIM. An authenticator app is safer, since the code generates on your phone instead of traveling over the phone network. A hardware security key is safer still, a small physical device that checks a site's real address before it responds, so it does not work on a convincing fake login page. Use one for your email, your bank, and your password manager itself.

   Assume what cannot be rotated is already out. Watch for misuse instead of trying to prevent something that may have already happened. A credit freeze and fraud alerts catch someone using a stolen Social Security number long before you would otherwise notice.

   Keep your software current. The new locks only work if your browser, phone, and apps are recent enough to use them. An old browser is still running the old lock alone.

   Think twice about what you put online today. Anything sent through email, cloud storage, or a messaging app now can still be harvested under the old lock until your provider finishes switching over.

   Ask the institutions holding your data. A bank or hospital's own migration timeline affects your exposure more than anything you do personally, and it is a fair question to put to them directly.

None of it undoes what has already been copied. It limits what is still worth harvesting and reduces the damage from what is not.

The padlock on my banking app will look exactly the same through all of this. Behind it, the locks are being swapped one at a time: bank by bank, cloud provider by cloud provider. The question left is not whether the new lock exists. It is how much of your data got copied before it arrived.

Friday, July 17, 2026

Quantum Keys Move Onto Production Routers

Quantum Keys Move Onto Production Routers

I led the telecommunications curriculum for Verizon's Next Step New England program and directed National Science Foundation, or NSF, funded Centers of Excellence at Springfield Technical Community College and the University of Central Florida through the transition from my Dad's Plain Old Telephone Service, or POTS, landlines to Internet Protocol, or IP, based voice, video, and data over copper, fiber and wireless. Our center worked closely with Cisco through that transition. The physics and the protocols changed rapidly snd it was a wild ride. What made the transition real was not the standards documents. It was carriers running the new transport on switches and routers in the central office, and technicians who did not need an advanced degree to keep it running.

Quantum key distribution, or QKD, is a way to generate an encryption key using the behavior of individual photons instead of math. Two machines exchange specially prepared light particles over fiber. If anyone taps the line and looks at those particles, the particles change in a way both ends can detect. That gives you a key exchange where eavesdropping does not stay hidden, which is a different from anything conventional encryption offers.

Aliro Technologies, the Vienna based quantum networking firm zerothird, and Cisco just ran a live version of this over Cisco's production routers at Cisco's Photonics Center in Vimercate, Italy. The hardware was Cisco's 8000 Series routers, the same platform Cisco sells into data centers today. That detail is the news. QKD has existed in labs for years. Running it on hardware a customer can already buy is the harder problem.

The system runs on the BBM92 protocol, which uses paired entangled photons rather than a transmitted key to establish a shared secret. Entangled photons are pairs of light particles created together so that measuring one instantly tells you something about the other, no matter the distance between them. A source creates these pairs and sends one photon from each pair to each end of the link. Both ends measure what arrives and use those measurements to build an identical key, without the key itself ever traveling across the fiber. zerothird supplies the hardware that does this: the photon source, the equipment that keeps the light polarized correctly, synchronizing clocks, and the software that cleans up errors and strengthens the final key. Aliro's Orchestrator software sits on top and manages the link, the way network management software already watches a conventional router. It tracks error rates and photon counts in real time and can reroute traffic or shut a link down safely if something looks wrong. The finished keys reach the routers through Cisco's Secure Key Integration Protocol, a standard interface, where they secure encrypted sessions between routers the same way a conventional key would, just generated a different way.

Diagram Gemini AI Generated

Chapter 1 of Quantum from the Ground Up covers the fiber problem in quantum networking through the University of Illinois work on ytterbium-171 emitters built for existing telecom infrastructure. That chapter is about getting a quantum signal onto fiber that already exists. This deployment answers the other half of the problem: getting the output of that signal into a router that already exists, with the monitoring and failover a network operations center can actually run day to day.

Chapter 14 frames quantum security as a race between two approaches. Post quantum cryptography, or PQC, keeps using math for encryption, just math that a quantum computer cannot easily break, and the National Institute of Standards and Technology, or NIST, has already published standards for it. QKD, the approach in this demonstration, does not rely on hard math at all. It relies on physics: any attempt to intercept the entangled photons changes them in a way both ends can detect. That is also its limit. A QKD key only protects the specific fiber link between two endpoints, while PQC can protect data anywhere the software runs. That is why Cisco is running both approaches rather than picking one. AT&T's coming quantum resilient Software-Defined Wide Area Network, or SD-WAN, service runs PQC on that same 8000 Series router line, which puts both approaches on the same hardware within the same product family.

The public announcement described the deployment as moving QKD out of isolated research setups and into standard enterprise infrastructure. Coverage of the announcement also framed the three way pairing as proof that quantum networking gear from separate vendors can interoperate in a live deployment, which matters more for enterprise adoption than any single performance number. A separate technical paper from the zerothird team tested the same entanglement based approach over a 22 kilometer fiber link between two data centers, which gives the enterprise demonstration a research paper trail worth reading alongside the press coverage.

What This Changes in the Book

Chapter 1 currently ends at the physics of getting quantum signals onto standard fiber. This deployment extends that story into the network operations layer: orchestration, telemetry, and automated remediation running on hardware already shipping. Chapter 14's framing of PQC and QKD as separate paths still holds, but the AT&T and Cisco pairing on the same 8000 Series router line is worth adding as a concrete case where one operator runs both approaches at once instead of choosing sides.

This post will fold into the next edition of the book, due September 1. The current edition is at gordostuff.com/p/quantum-from-ground-up-hardware.html.

POTS to IP took a decade of this kind of work: new transport riding on racked equipment. Quantum key distribution is passing the same tesst. The obstacle was never the physics. Here it's whether the keys can ride on a router Cisco already sells, watched by software a network operations center knows how to run.



Tuesday, July 14, 2026

Where the Jobs Actually Are

Some graduates spent the 2026 commencement season blaming AI for a job market that shut them out, loud enough that tech executives got booed at graduation ceremonies over it. Recruiters tell a different story.

Matt Walsh, CEO of the Phoenix search firm Blue Signal, works semiconductor hiring daily and says the problem isn't automation. "There aren't enough people," he says. The United States is heading toward what labor economists call the largest workforce shortage in its history, and it shows up hardest in the fields that build things.

The semiconductor industry expects to add close to 115,000 jobs by 2030. The Semiconductor Industry Association projects a shortfall of 67,000 technicians and engineers to fill them. That gap sits squarely in associate degree and bachelor's degree technical programs, not in the AI research labs getting most of the headlines.

Construction and the skilled trades show the same pattern. Branka Minic, CEO of the Building Talent Foundation, says fewer than half the workers needed in construction are entering the field, even with starting wages hitting $50 an hour in some markets. College graduates aren't matching that pay in comparable years of training.

Cybersecurity tells a similar story. CyberSeek, the workforce tracker built by CompTIA and NIST, counts hundreds of thousands of open cybersecurity positions in the U.S. against a supply of qualified workers that consistently falls short. The roles span network defense, security operations, and incident response, and they don't require a computer science PhD. A two-year degree with the right certifications gets a candidate into the field.

This is good news if you're building a technical career instead of chasing a headline. Employers in semiconductors, cybersecurity, advanced manufacturing, robotics, and skilled trades are competing for candidates, not filtering through thousands of applicants for one opening. Two-year technical programs, apprenticeships, internships and engineering degrees put graduates directly into that competition.

States have noticed too: several are merging workforce and higher education agencies or offering loan payoff incentives to pull people into these pipelines.

The AI panic makes for a cleaner headline than a demographic and skills pipeline problem. But the demand for people who can build, install, test, and maintain physical systems is not shrinking. It's the part of the labor market with the fewest applicants and the most openings.

Thursday, July 2, 2026

The Second June 22, 2026 Quantum Executive Order

In a post Tuesday, I covered the executive order setting hard federal deadlines for post-quantum cryptography migration: key establishment by 2030, digital signatures by 2031. That order dealt with defense. On the same day, June 22, the president signed a second order that deals with offense.

Executive Order 14413, "Ushering in the Next Frontier of Quantum Innovation," directs the federal government to build a large-scale quantum computer for scientific use. The centerpiece is the Quantum Computer for Application Development and Discovery Science effort, called QC-ADDS. The order directs the Department of Energy to deliver at least one QC-ADDS system to a DOE facility and make it available to the scientific community.

Here's some details - within 90 days, DOE must publish the technical specifications required for QC-ADDS to perform transformative scientific applications beyond current classical computer capabilities. Within 180 days, DOE must explore private-sector partnership models and report on cost, scope, and delivery timeframe. DOE has already responded: its Quantum Genesis initiative targets a fault-tolerant, scientifically relevant quantum computing capability by 2028, with a National Quantum Supercomputing User Facility to give U.S. researchers access to systems across multiple qubit modalities.

The Commerce Department must develop a plan for advance market commitments to pull in commercial quantum vendors. The Defense Department gets its own track, establishing programs for national security applications of quantum computing, potentially including a dedicated center. The order also establishes a national center for quantum performance assessment and directs a government-wide quantum workforce recruitment strategy, including special pay rates and retention incentives.

The workforce section carries the most direct relevance for technical education programs. The order tasks NSF to stand up a network of National QIST Workforce Development Institutes within 180 days. Federal money for hands-on QIST training will flow somewhere; the question is where.

There is a thread connecting both orders. The PQC migration order sets a deadline for protecting existing systems. EO 14413 sets a timeline for building the systems that will eventually make those protections necessary. Both orders treat 2030 as the planning horizon. Harvard's Mikhail Lukin put fault-tolerant, large-scale quantum computers at end-of-decade in a recent assessment, five to ten years ahead of earlier estimates.

Wednesday, July 1, 2026

Inside the ST54M: One Chip, Three Jobs, and a Post-Quantum Upgrade

Yesterday I wrote about our government setting a new deadline for quantum-safe encryption. At the end of the post I briefly mentioned STMicroelectronics introduced the ST54M, the first mobile chip with a dedicated hardware accelerator for post-quantum algorithms. I got a question from a reader – what the heck does that mean....?!  Fair question! Here’s some detail on what that chip does, and how it works. If you use your phone for payments – this is a very good thing.

Tap your phone against a payment terminal and several things have to happen in well under a second. The device has to prove its identity, encrypt the exchange, and complete the transaction before you lift your hand away. Most people never think about the chip doing that work. STMicroelectronics just gave that chip a significant upgrade.

The new chip is called the ST54M. It is a single chip that combines three functions that used to live on separate pieces of silicon: an NFC controller, a secure element, and eSIM support. NFC is the short range radio that lets your phone talk to a payment terminal, a transit gate, or a hotel door lock. The secure element is a locked vault inside the chip that holds your credentials and keys. eSIM is the embedded SIM that lets your carrier profile live in the device itself instead of a removable card. Folding all three into one die (small piece of silicon that contains the electronic circuits needed) simplifies the phone and tightens the security boundary between them.

The bigger story is what ST54M adds on top: a hardware accelerator built for post-quantum cryptography. Today's encryption relies on math problems that are hard for ordinary computers to solve. A sufficiently capable quantum computer could solve some of those problems quickly, which would undermine the locks protecting your payments and your identity data. ST54M supports two newer algorithms, ML-KEM and ML-DSA, designed to resist that kind of attack. Building the acceleration into hardware means a phone can run this stronger cryptography without slowing down.

STMicroelectronics has samples available now, with production and certification targeted for July 2026. The certifications matter for adoption; payment networks and government identity programs will not deploy a chip until it clears those bars.

None of this changes what happens when you tap your phone tomorrow. It changes what is quietly defending that tap a few years from now.

Tuesday, June 30, 2026

Government Sets New Deadline for Quantum-Safe Encryption

A student in one of my summer courses asked the question I get every time encryption comes up in discussion: why does this matter now? RSA (Rivest-Shamir-Adleman) and ECC (elliptic curve cryptography) have protected data for decades. The quantum computer that breaks them does not exist yet. 

My usual answer leans on Q-Day estimates: Google's Gidney put the threshold at roughly one million physical qubits to break RSA-2048, and an IonQ fidelity result last October pushed the realistic window to somewhere between 2029 and 2033. Most expert estimates before that sat closer to 2035. On June 22, the federal government answered the student's question for me. President Trump signed 

an executive order setting hard deadlines for federal post-quantum cryptography migration (PQC): agencies must move high value assets to post-quantum key establishment by December 31, 2030, and post-quantum digital signatures by December 31, 2031. Federal contractors get the same 2030 deadline for FIPS (Federal Information Processing Standards) compliance.

That replaces the prior government baseline. Under the Biden administration's National Security Memorandum 10, agencies were planning around 2035. The new order compresses that by four to five years and adds teeth: agencies must name a PQC migration lead within 30 days, the Commerce Department must run a migration pilot by the end of 2027, and contractors face FIPS enforcement through procurement rules. 

Coverage from Cybersecurity Dive notes the order also pushes CISA (the Cybersecurity and Infrastructure Security Agency) to publish guidance on cryptographic bills of materials, the inventory work agencies need before they can migrate anything.

How the Industry Responded

Two days after the signing, STMicroelectronics introduced the ST54M, the first mobile chip with a dedicated hardware accelerator for post-quantum algorithms. It runs ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) and ML-DSA (Module-Lattice-Based Digital Signature Algorithm), the NIST (National Institute of Standards and Technology) standards finalized in 2024, on a single die alongside NFC (near-field communication), secure element, and eSIM (embedded SIM) functions. Commercial sampling is available now, with certification targeted for July 2026. That is the hardware path the federal order is pushing the rest of industry toward on the same compressed timeline.

I tell students today: nobody knows the exact day a cryptographically relevant quantum computer arrives, but the government just stopped waiting to find out. And.... I would not be surprised at all to see the deadline moved forward again.... soon.

Sunday, June 28, 2026

STEM at Two Years: Community College Degrees That Pay

Most of my career has been at the community college. I directed an NSF Center of Excellence at Springfield Technical Community College and taught electronics, computer systems, and photonics there. At Holyoke Community College I still teach engineering transfer courses part time for students heading to four-year universities. Over forty years I have watched students come through two-year STEM programs and go directly into careers that surprised people who assumed a bachelor's degree was required. This post is the third in a series on degree choice and outcomes. The first two covered bachelor's programs and two-year degrees broadly. This one focuses specifically on STEM at the associate degree level: what the programs are, what they pay, and how the job outlook looks in 2026.

The macro case for STEM at any credential level is straightforward. The BLS projects STEM occupations will grow 8.1 percent between 2024 and 2034, nearly triple the 2.7 percent rate for all other occupations. The median salary across STEM occupations sits at $101,600, well above the all-occupation median. The two-year credential does not open every STEM door, but it opens more of them than most people expect, and it does so at a fraction of the cost and time of a four-year path.

The highest-paying two-year STEM programs in 2026, per BLS occupational data: information security analysts (cybersecurity) median at $119,860 with 32 percent projected job growth through 2032; radiation therapy at a median above $100,000; dental hygiene at $94,260; and registered nursing at $93,600. Below those, nuclear technicians median around $84,000, electronics engineering technicians around $67,550, and laser electro-optics technicians in the $55,000 to $65,000 range depending on industry and region. HVAC technology and computer network support round out the middle of the table at $58,000 to $62,000.


A point worth making clearly: the two-year STEM credential typically leads to technician and support roles, not engineering or research positions. That distinction matters for career planning, but it does not diminish the outcomes. An electronics engineering technician working in manufacturing or test and measurement earns $67,550 median with stable demand. A cybersecurity analyst with an associate degree and relevant certifications, CompTIA Security+ in particular, enters a field with 32 percent projected growth and a six-figure median salary. The ceiling in those careers depends more on certification, experience, and specialization than on whether the entry credential was a two-year or four-year degree.

The cost side of this decision matters as much as the salary side. Average annual tuition at a public two-year college runs about $3,990, versus over $11,500 at a public four-year institution. A student completing a two-year cybersecurity or nursing program graduates with little or no debt and enters a field paying $90,000 to $120,000. A student completing a four-year program in the same field earns more in some cases, but starts with average student loan debt above $29,000 and two additional years of foregone income. For STEM technician roles specifically, that math favors the two-year path more consistently than in most other fields.

Before committing to a two-year STEM program, check three things. First, verify that the program carries the right accreditation for your field. Nursing programs must be accredited by ACEN or CCNE for graduates to sit for the NCLEX. Engineering technology programs are credentialed by ABET. Second, check whether the career path requires licensure or certification beyond the degree itself, and build the cost and timeline for those credentials into your plan. Third, look at your specific college's job placement data for that program. National medians are a baseline; local labor market conditions move those numbers significantly in both directions.

One pathway that gets less attention than it deserves: the two-year degree as the first half of a four-year degree, paid for by an employer. Many community college STEM graduates enter the workforce directly, then pursue a bachelor's degree part time while their employer covers tuition. This is not rare. A significant share of working adults completing bachelor's degrees are doing exactly this, particularly in nursing, engineering technology, and information technology. The RN-to-BSN pathway is the most established example: a graduate earns an associate degree, passes the certification, enters the workforce as a registered nurse, and completes a BSN online or part time over two to three years, often with hospital tuition reimbursement covering most of the cost. The same model applies in engineering technology and cybersecurity, where employers in manufacturing, defense, and infrastructure actively fund continuing education. The credential upgrade from technician to technologist, meaning from associate to bachelor's degree, also typically comes with a pay bump and expanded career options. For students weighing cost, this route splits the financial risk: two years of low-cost community college tuition, then employer-subsidized completion of the bachelor's, with income throughout. The total credential is the same four-year degree. The debt load and the timeline are very different.

The community college students I’ve watched who did best in two-year STEM programs were not picking a fallback. They were picking a specific job in a specific field and treating the degree as the direct path to it. That approach still works in 2026. For some, the two-year degree is also the starting point for a four-year degree the employer ends up paying for. The programs are there. The jobs are there. Check the current numbers before you decide. Know the program, know the credential requirements, know the market.

Wednesday, June 17, 2026

Authentication, Not Encryption, Is Now The Big Quantum Worry

In the chapter on the threat to encryption in Quantum from the Ground Up, I cited a 2025 estimate from Craig Gidney at Google Quantum AI that RSA-2048 could be factored by a quantum computer with roughly one million noisy physical qubits, and noted that most experts placed Q-Day, the point at which a quantum computer can break current encryption, at around 2035. That estimate did not survive the spring.

In late March and early April 2026, two independent research results arrived within weeks of each other. Google published a major improvement to the quantum algorithm used to break elliptic curve cryptography, the math behind most of the internet's key exchange. Then Oratomic, a quantum computing startup, published a resource estimate suggesting RSA-2048 and P-256 could be broken with as few as 10,000 qubits on a neutral atom machine. That is roughly two orders of magnitude below the prior million-qubit estimate.

Why 10,000 Qubits Instead of a Million

The efficiency gain comes from error correction overhead, not from a change in the underlying mathematics. Shor's algorithm, the quantum algorithm that breaks RSA and ECC, has not changed. What changed is how many physical qubits it takes to build one reliable logical qubit on a neutral atom platform. Reporting on the Oratomic estimate put the ratio at roughly three to four physical qubits per logical qubit, a dramatically smaller overhead than superconducting platforms have required.

That ratio matters because it is the number that determines whether an attack is a research curiosity or an engineering project with a budget and a timeline. A million-qubit machine is not something any organization is building in this decade. A 10,000-qubit machine is in the range that QuEra, Atom Computing, and Pasqal have all stated as roadmap targets for 2026 to 2028 in the neutral atom chapters of this book. The number did not just get smaller. It got small enough to be plausible on hardware roadmaps that already exist.

How the Industry Responded

Cloudflare's response is the clearest signal of how seriously the industry is taking this. Cloudflare secures a significant fraction of global internet traffic, and the company had already completed most of its post-quantum encryption rollout, protecting against harvest-now-decrypt-later attacks where adversaries collect encrypted traffic today and decrypt it once a quantum computer is available. That work was largely done. The Google and Oratomic results changed what Cloudflare is worried about next.

Cloudflare's senior product director told reporters that authentication, not data confidentiality, is now the bigger concern. The distinction is worth sitting with. If a quantum computer can forge access credentials, an attacker does not need to decrypt anything. They can log into systems they are not supposed to have access to, or compromise a software update channel directly. That is a more immediate and more damaging failure mode than data theft, and it requires a different and more complex migration than swapping out an encryption algorithm.

Cloudflare set 2029 as its target for full post-quantum security across its platform, including authentication, and has accelerated its existing roadmap to hit that date. Google made a similar 2029 commitment. Coverage of the shift described the timeline change as a direct response to the two breakthroughs, and one report quoted the view that a coordinated attack against a high-value target, what the article called a moonshot attack, could plausibly arrive by 2030.

What This Changes in the Book

Chapter 13 of the first edition gave a 2029 to 2033 range as the accelerated estimate, driven by IonQ's October 2025 fidelity result. That range still holds, but the reasoning behind it has shifted. The IonQ result was a hardware fidelity improvement on an existing approach. The Google and Oratomic results are an algorithmic and architectural efficiency gain that reduces the qubit count needed for the same outcome. Both push in the same direction, but they are different kinds of progress, and the second edition will need to explain both rather than treating the timeline as a single number that moves around.

The Oratomic estimate specifically relies on high-rate quantum error-correction codes to achieve its 3:1 physical-to-logical overhead ratio. It is worth emphasizing that we are talking about 10,000 physical qubits here. Because the cybersecurity industry has spent a decade hearing that breaking RSA requires millions of physical qubits, highlighting that this breakthrough brings the physical hardware requirements down to the low thousands underscores just how radical this architectural shift is. Furthermore, this timeline collapse wasn't driven by hardware breakthroughs alone; as noted in the landmark paper co-published by Caltech and Oratomic, the team heavily leveraged AI-assisted algorithmic design and reconfigurable arrays to optimize these error-correcting codes, proving that classical AI is actively accelerating the software running on quantum roadmaps. Meanwhile, Google Quantum AI's joint research demonstrated that the logical qubit threshold to break elliptic curve cryptography could be slashed by 20x, creating a compounding effect where hardware requirements dropped while algorithm efficiencies spiked.

The organizational guidance from Chapter 13 does not change, it gets more urgent. Inventory your cryptographic dependencies. Specify quantum-resistant encryption in procurement. Re-encrypt long-term sensitive data. Build crypto agility into your architecture so algorithms can be swapped without a system rebuild.

The new addition, following Cloudflare's formal roadmap acceleration announcement, is that authentication systems deserve the same attention as encrypted data. As industry infrastructure leaders begin locking down their platforms against these newly compressed timelines, a compromised root certificate or access token is recognized as a far more catastrophic failure than a decrypted file, and it is the exact vulnerability the industry is now scrambling to patch.

This post will be incorporated into the second edition of Quantum from the Ground Up, out September 1. The full book, updated quarterly, is free at gordostuff.com/p/quantum-from-ground-up-hardware.html

Thursday, June 11, 2026

Quantum from the Ground Up: First Edition Now Available


I have been learning and writing about quantum computing on
gordostuff.com since October 2025. The posts started as a way to make sense of announcements as they happened: IonQ hitting 99.99% two-qubit gate fidelity, Microsoft unveiling Majorana 2, IBM running a 12,635-atom protein simulation, Apple releasing a 50,000-step formal proof of its post-quantum cryptographic library. Each one went up as a standalone post. After eight months and seventeen posts, it made more sense to put them together in one place.

The result is Quantum from the Ground Up, a free PDF now available at gordostuff.com. This first edition covers posts through June 2026 and runs 50 pages across 19 chapters. It is written for someone entering the quantum workforce, or seriously considering it, who has a technical background but has not taken a graduate course in quantum mechanics.

Download: Download PDF

The book covers six qubit fabrication platforms in sequence: superconducting circuits, trapped ions, photonics, neutral atoms, silicon spin qubits, and topological qubits. Each chapter describes the physical mechanism, the fabrication or trapping method, current performance numbers, and the specific engineering problems that remain unsolved. The qubit chapters are followed by sections on hybrid classical-quantum protein simulation, AI-assisted hardware calibration, post-quantum cryptography, and the hardware landscape as it stands in mid-2026.

Two chapters address the workforce directly. The first maps the adjacent skill sets the quantum supply chain actually needs: semiconductor process engineering, cryogenic systems operation, RF electronics, machine learning for hardware calibration, and cryptographic implementation. None of those require a physics PhD. The second chapter maps the full degree pathway from a two-year associate degree through a PhD, with specific programs, what each credential prepares you to do, and salary ranges at each level. The field has a real workforce shortage. The shortage is not only at the PhD tier.

The plan is to update the book quarterly as new posts are published. The field moves fast enough that a quarterly cycle makes sense: slow enough to let any given announcement settle, fast enough to stay current with actual engineering progress. This edition covers October 2025 through June 2026. The next update will incorporate posts from Q3 2026.

Seventeen posts, fifty pages, fifteen images, one dark navy cover. The posts were worth writing individually. They are more useful together. Download free at Download PDF.

Support This Work

The book is free and will stay free. If you find it useful and want to support future editions, you can contribute at ko-fi.com/gordostuff.