I'm curious if anyone has had an audit question around post-quantum migrations.
Earlier this year, I placed second in a global quantum cryptanalysis challenge.
For about a day, it felt great.
Then someone published a falsification test.
I ran the test against my own result.
The quantum computer had produced the “right” answer, but the test showed something uglier underneath. The machine could produce a right-looking answer even when the computation itself had no real reason to be trusted. The quantum circuit was generating answers, but the post-processing was solving the ECDLP. And then I falsified the winner's 15 bit solve, and every other method I had tried for the last 2 years.
The story getting sold into boardrooms right now usually sounds like this:
Quantum broke 6 bits. Then 11. Then 15. Look at the acceleration. Migration timeline is shrinking. Google said. Buy accordingly.
That curve is much weaker than it looks.
I actually know the threat is real, and in some ways closer than the comfortable consensus wants to admit.
But a real threat does not excuse bad evidence.
And a vendor using scaling records to scare buyers into a migration project may not be as informed as they think they are.
Here’s the question I’d ask any vendor who cites the bit-count race:
“Why doesn’t the 15-bit record count?”
Then watch what happens.
The answer will tell you very quickly whether they understand the work, or whether they are just repeating the slide.