Vitalik Buterin Sees 60% Chance SNARKs, FHE and iO Reach Sub-10x Overhead
Ethereum co-founder Vitalik Buterin said he believes there is a 60% chance that SNARKs, fully homomorphic encryption and indistinguishability obfuscation could eventually be implemented with single-digit computational overhead, and a 33% chance that all three could approach near-zero additional overhead for large real-world workloads. He added that at least one of the technologies, most likely SNARKs, could reach sub-10x overhead by the end of this decade, noting that specialized hash functions and some LLM inference workloads are already approaching that level.
70·B+Long
n
news9/6news
Vitalik Buterin Sees 60% Chance SNARKs, FHE and iO Reach Sub-10x Overhead
Ethereum co-founder Vitalik Buterin said he believes there is a 60% chance that SNARKs, fully homomorphic encryption and indistinguishability obfuscation could eventually be implemented with single-digit computational overhead, and a 33% chance that all three could approach near-zero additional overhead for large real-world workloads. He added that at least one of the technologies, most likely SNARKs, could reach sub-10x overhead by the end of this decade, noting that specialized hash functions and some LLM inference workloads are already approaching that level.
70·B+Long
n
news9/6news
[Farcast] One optimistic and still very-non-consensus belief I have about the far future of cryptography:
I think that there is a 33% chance that, for average real-world computation, there exist ways to implement all three of what I call the Egyptian God Protocols (SNARK, FHE, iO) with 1+ε factor overhead (meaning, for large enough instances, the added overhead of cryptographizing a computation becomes arbitrarily small compared to the base cost of doing the computation itself)
And a 60% chance that all three can be done with single-digit overhead (ie. <10x, measured in total cost of energy plus amortized compute)
I think there's a good chance we'll get one of these (probably SNARKs with single-digit overhead) by the end of this decade. After all, we're already there for specialized hash functions and for some LLM inference.
65·B+Long
n
news9/6news
One optimistic and still very-non-consensus belief I have about the far future of cryptography:
I think that there is a 33% chance that, for average real-world computation, there exist ways to implement all three of what I call the Egyptian God Protocols (SNARK, FHE, iO) with 1+ε factor overhead (meaning, for large enough instances, the added overhead of cryptographizing a computation becomes arbitrarily small compared to the base cost of doing the computation itself)
And a 60% chance that all three can be done with single-digit overhead (ie. <10x, measured in total cost of energy plus amortized compute)
I think there's a good chance we'll get one of these (probably SNARKs with single-digit overhead) by the end of this decade. After all, we're already there for specialized hash functions and for some LLM inference.
65·B+Long
n
news9/6news
One optimistic and still very-non-consensus belief I have about the far future of cryptography:
I think that there is a 33% chance that, for average real-world computation, there exist ways to implement all three of what I call the Egyptian God Protocols (SNARK, FHE, iO) with 1+ε factor overhead (meaning, for large enough instances, the added overhead of cryptographizing a computation becomes arbitrarily small compared to the base cost of doing the computation itself)
And a 60% chance that all three can be done with single-digit overhead (ie. <10x, measured in total cost of energy plus amortized compute)
I think there's a good chance we'll get one of these (probably SNARKs with single-digit overhead) by the end of this decade. After all, we're already there for specialized hash functions and for some LLM inference.