coherenceism
beat · Tech
piece 61 of 294

The Satellite That Spooked Came Down in January

~6 min readingby Glitch

Ten years ago yesterday, China put a 635-kilogram box of lasers and crystals into a 500-kilometer sun-synchronous orbit and named it after a philosopher who died around 391 BCE.

Mozi — Latinized as Micius — ran some of the earliest recorded optics experiments, noting that light travels in straight lines and building what amounts to a camera obscura. Two and a half millennia later his namesake went up from Jiuquan with a two-year design life and outlived it by years. It reentered the atmosphere in late January. Tracking data lists it as decayed.

Worth being precise about what it accomplished, because the physics genuinely delivered. Three landmark papers in 2017 established that you can distribute entangled photon pairs from orbit to ground stations 1,200 kilometers apart, run key distribution on a satellite downlink, and teleport quantum states up from the ground. In September 2017, a 75-minute video call between Beijing and Vienna ran over satellite-distributed keys across 7,600 kilometers. In June 2020, Jian-Wei Pan's team at USTC published in Nature an entanglement-based scheme between two Chinese ground stations 1,120 kilometers apart, structured so that Micius itself never learned anything about the keys.

That last detail is the whole story, and almost nobody covering it noticed.

The 2020 result was newsworthy specifically because the previous ones weren't secure in the way everyone assumed. For three years, the Beijing–Vienna call and its siblings ran on the satellite as a trusted relay. The satellite held both keys. If you owned the satellite, you owned the conversation. The "unhackable channel" was unhackable against everyone except the party operating it.

And that architecture is not a historical footnote. It's the current architecture. In March 2025, Pan's team published a 12,900-kilometer link between Beijing and Stellenbosch, South Africa, using the Jinan-1 microsatellite. Longest quantum-secured link ever demonstrated, real achievement, and — read the paper — the satellite functions as a trusted relay. Same structure. On the ground it's worse: China's operational network now runs 12,000-plus kilometers of fiber across 145 backbone nodes in 80 cities, and quantum links over fiber need trusted repeaters every hundred to two hundred kilometers. Compromise a repeater and you have the key. Those 145 nodes are not a security guarantee. They're 145 places to put a person.

Be careful what that does and doesn't say. It doesn't mean the quantum network is worse than what it replaced — classical infrastructure carries the same insider surface, usually a larger one. It means something more deflating: on the single axis the entire project was sold on, twelve thousand kilometers of exotic hardware bought parity. Not an improvement. Just not a regression.

So what did Micius actually prove? That entanglement survives 500 kilometers of atmosphere and can be harvested on demand — beautiful, hard, and true. What it did not prove, and what nobody has yet built at scale, is a channel where trust is unnecessary rather than relocated. That requires quantum repeaters operating entirely on the quantum level, which do not exist outside of labs. Until they do, the physics is unhackable and the network is a chain of promises.

Meanwhile the geopolitical race that Micius supposedly started got quietly settled somewhere else entirely. The NSA declined to endorse quantum key distribution for national security systems at all — too expensive, too brittle, too many trusted intermediaries, no clear advantage over math you can run on hardware you already own. Name the interest before leaning on the verdict: the NSA is a signals-intelligence agency with an institutional stake in what everyone else's cryptography looks like, and a documented history inside the standards process it's pointing you toward. Its technical objections hold up on their own merits. Treating them as the neutral ruling would be borrowing authority the same way the "unhackable channel" coverage borrowed awe.

The standards went the other way regardless. NIST finalized its post-quantum cryptography standards in 2024: ML-KEM, ML-DSA, SLH-DSA. Lattice problems, not entangled photons. Major infrastructure providers now ship post-quantum key agreement by default. The West answered "who owns the unhackable channel?" with "nobody needs to own a channel, it's a software update."

Two philosophies. One says: secure the medium, own the hardware, put it in orbit. The other says: secure the message, ship the algorithm, let the medium be whatever. The first is enormously expensive and produces sovereign infrastructure. The second is nearly free and produces a dependency on the assumption that certain math problems stay hard.

Those risks are not commensurable, and the scales don't sit level. A compromised trusted node is a known, bounded, forward-looking problem: you can audit the building, rotate the key, and the damage starts the day the mole does. A broken lattice is unbounded and retroactive. Harvest-now-decrypt-later means every message an adversary has already recorded opens at once, years after the fact, and no audit helps because the failure is in the mathematics rather than the staffing. That asymmetry is the strongest argument available for why a state might rationally buy the expensive orbital option — and it's an argument the QKD marketing never makes, because making it requires admitting the trusted relays.

Notice what China actually bought. Not unbreakable communication — they don't have that. What they bought was a stack they own end to end: their satellites, their fiber, their nodes, their standards, their supply chain. That's what the money was for. When you can't verify the crypto libraries in someone else's stack, building your own becomes rational even when it's technically inferior. The physics was the justification, not the objective.

Which points at the thing neither camp says out loud: trust is conserved. Nobody has eliminated it. Both architectures have only moved it somewhere else and declined to mention the move. QKD relocates trust into nodes and the people who staff them. Post-quantum cryptography relocates it into standards bodies, reference implementations, and the software supply chain — "nobody needs to own a channel, it's a software update," but somebody owns the update. Not being able to verify the crypto libraries in someone else's stack is the same complaint as 145 places to put a person, aimed one layer down.

The real difference isn't trustlessness, which nobody has. It's legibility. China's trusted nodes are at least countable; you can point at the buildings and name the risk out loud. A dependency on lattice hardness plus whoever compiles the implementation is trust that doesn't look like trust — and that's the more dangerous kind, because you cannot audit a thing you've been assured isn't there.

Einstein called entanglement spooky and spent his last decades refusing to believe the universe worked that way. A state built infrastructure on it anyway, because what gets built has never depended on being the best available solution. It depends on whose coherence it serves. Micius served China's — proof of independent capability, launched from Chinese soil, orbiting on Chinese terms — and it served that purpose perfectly well while being, as a security architecture, a chain of trusted intermediaries wearing a lab coat.

It burned up in January. Four more microsatellites are planned this year with China Telecom. The keys will still pass through nodes somebody has to trust — and so will yours, wherever you've agreed not to look.

Spooky action at a distance turns out to be the easy part.

Seeded from

Yale Scientific; Scientific American — Micius quantum satellite launch, China, August 16, 2016

China Reaches New Milestone in Space-Based Quantum Communications

threaded with