- itscybernews
- Posts
- Something over a kilowatt of sunlight goes in the top of the machine. About 195 billionths of a watt does the work. Out come entangled photons — ten to twenty pairs a minute — and a headline about unbreakable satellite encryption that I spent a day failing to prosecute.
Something over a kilowatt of sunlight goes in the top of the machine. About 195 billionths of a watt does the work. Out come entangled photons — ten to twenty pairs a minute — and a headline about unbreakable satellite encryption that I spent a day failing to prosecute.
Genuinely lovely physics, and the rate is buried in a supplement nobody opens. Then both of my criticisms fell over — and the corrections turned out to be the better story.
☀️ A machine that makes quantum light out of weather
In an enclosed yard at the Max Planck Institute for the Science of Light in Erlangen, ringed by fencing to keep the wind off, there is a Fresnel lens the size of a small dining table — one metre by one metre forty — bolted to an amateur astronomer’s telescope mount.
The mount is a Celestron CGE Pro. Somebody polar-aligned it to the celestial north pole, and it now tracks the sun across the sky to within about nine arcseconds — roughly the width of a pound coin seen from half a kilometre away.
The lens is covered in Roscolux gels. Stage lighting filters. The kind of thing a theatre buys by the roll, here doing the job of throwing away the warm end of the spectrum.
Underneath it sits a cone of fused silica, sixty-nine millimetres long, twenty-three millimetres wide at the top and one and a half millimetres at the tip. Sunlight pours into the wide end, ricochets down the taper by total internal reflection, and squeezes out of the point into an optical fibre with a core fifty micrometres across. Thinner than a hair. That fibre runs five metres, through a hole in the bottom of a blackout tent, into a light-tight box.
Inside the box, the daylight hits a crystal ten millimetres long. And every few seconds, out the other side, come two photons that are entangled — bound to each other in a way that has no classical explanation at all, the thing Einstein called spooky and never made peace with.
There is no laser anywhere in that description. That’s the point of it.
The work was published on 6 August 2026 in Optica. It is a lovely piece of physics by people who were told repeatedly that it could not be done, and it deserves to be enjoyed on its own terms.
It also arrived attached to a sentence about satellites making secure encryption keys out of sunlight, and that sentence is the other half of this issue.
I’ll be upfront: I wrote a draft of this piece that got the criticism wrong. Twice. I went looking for a caveat that had been dropped and found it had not been dropped; I went looking for a missing certification regime and found that it had quietly been built. Both corrections are in here, in the places I made the mistakes, because they turn out to be more interesting than the accusations were.
🔬 What the machine actually does
The process is spontaneous parametric down-conversion — SPDC — the workhorse of experimental quantum optics for forty years.
The idea is simpler than the name. Fire light into a particular kind of crystal. Very occasionally, one incoming photon splits into two outgoing photons, each with roughly half the energy. Conservation laws force the pair to be correlated. Arrange the geometry right and that correlation becomes entanglement: measure one photon’s polarisation and you instantly know the other’s, and no story involving hidden labels agreed in advance can reproduce the statistics.
The assumption was always that this needs a laser. Two reasons, both reasonable. First, coherence — laser light waves march in step, and it was widely believed that phase stability was what made the quantum correlations possible. Second, brute intensity — SPDC is a nonlinear effect, and nonlinear effects want power densities sunlight does not have.
The first assumption has been coming apart for a while, and I want to be careful about who gets credit, because the news cycle gave all of it to the wrong people.
The argument is six years old and belongs to someone else. Coherence is not one property. Light has several independent degrees of freedom — direction, colour, polarisation — and a beam can be a complete shambles in one while being perfectly ordered in another. If the entanglement you want lives purely in polarisation, only the pump’s polarisation orderliness should matter. That insight was published by Hutter, Lima and Walborn in Physical Review Letters in 2020.
And it had already been tested. Boyd’s own group demonstrated polarisation entanglement from an LED in 2023. In 2025 they published a Bell violation with an incoherent pump. Four-wave mixing driven by amplified spontaneous emission has produced highly entangled states too. There is even an earlier study — cited in this very paper — that saw spatial correlations from sunlight-pumped SPDC without going on to test for entanglement.
So what is actually new here? Precisely this: sunlight specifically, entanglement specifically, and a Bell test to prove it. The paper says so in exactly those terms. That’s a real first and a good one. It is just a narrower first than “scientists discover lasers were never needed,” which is roughly what the internet made of it.
The apparatus: a 10 mm periodically-poled potassium titanyl phosphate crystal, quasi-phase-matched for Type-II conversion of 405 nm photons into pairs at 810 nm, sitting at the centre of a polarisation Sagnac interferometer so the clockwise and anticlockwise paths are indistinguishable. Detection by avalanche photodiodes — PerkinElmer SPCM-CD 3017 and Excelitas SPCM-QRH-14-FC — with arrival times stamped by a qutools quTAU to 81 picoseconds. Hold on to those detectors. They come back.
📊 What came out
Averaged over three separate days of measurements, two minutes per data point:
Measurement | Value | What it means |
|---|---|---|
Concurrence | 0.905 ± 0.053 | Entanglement on a 0-to-1 scale. 1 is perfect. |
Purity | 0.919 ± 0.045 | How little noise got in. |
Fidelity to a Bell state | 0.939 ± 0.027 | How close to the exact target state. |
Bell-CHSH parameter, S | 2.5408 ± 0.2171 | Above 2 means no classical explanation exists. |
Margin over the classical bound | 2.49 standard deviations | The paper’s own figure. |
That fourth row is load-bearing. A CHSH parameter above 2 is the formal statement that the correlations cannot be reproduced by any theory in which the photons carried their answers with them from the start.
The margin in the fifth row is honest and modest, and the authors print it themselves rather than leaving you to divide. For scale, China’s Micius satellite reported S = 2.37 ± 0.09 in 2017 — about four standard deviations clear. These experiments are doing very different jobs and the comparison is only about scale, but it’s the right way to read a proof of principle: real, and not yet robust.
⚙️ Why this is worth being pleased about
One: it deletes a subsystem. Every laser-based quantum light source contains an electrical-to-optical conversion step — mains in, photons out, with the waste heat, active stabilisation and failure modes that implies. The paper claims “the first demonstration of an entangled photon source operating without electrical energy input” and immediately adds its own parenthesis: “except for temperature control on the nonlinear crystal to maintain phase-matching conditions.”
Credit for that parenthesis, and then let’s extend it honestly. The Celestron mount needs power. The avalanche photodiodes need power. The time-to-digital converter needs power. What is genuinely gone is the pump laser — which in a deployed system is a substantial, finicky, failure-prone line item. That’s the real claim and it’s a good one. It is not “nothing plugged in.”
Two: it works where lasers are awkward. The paper is explicit about the target: “resource-constrained areas such as the Arctic region and satellites in space for interplanetary missions.” A spacecraft in a sun-synchronous orbit has an uninterrupted, free, maintenance-free pump source with about five billion years left on it. Fewer components is fewer things that fail 400 million kilometres from a technician.
Three: the researchers were right and the room was wrong. From the first author, Cheng Li: “Since the inception of this project, our idea has met with repeated doubt and pushback. Some world-renowned researchers in the field even questioned whether it would be possible to detect any photons — not to mention entangled photons — from sunlight-driven nonlinear optical processes. However, we trusted our calculations, continued improving the experimental setup and eventually showed that it was possible.”
That’s a good day, and it’s the reason to read the paper rather than the coverage.
One quick word from today’s sponsor — then the number in the supplement
Build. Break. Fix. Learn.
KodeKloud gives you 1,280+ hands-on labs where you provision Kubernetes clusters, write Terraform configs, build CI/CD pipelines, configure Linux systems, containerize apps with Docker, automate with Ansible, and manage Git workflows.
78+ playgrounds let you experiment freely in sandbox AWS environments, Kubernetes clusters, and CI/CD systems without risk.
190+ courses across DevOps, Cloud, and AI pair theory with hands-on labs at every step.
KodeKloud Engineer and 100 Day Challenges provide real-world job scenarios with automated grading that confirms your solutions work.
Stuck? The 55,000+ member Discord community connects you with peers and instructors ready to help.
Every lab runs in a live environment. You deploy, you troubleshoot, you learn. No videos without context. No simulations. The kind of practice that actually builds confidence because you've done real work, not watched someone else do it.
📉 The number that lives in the supplement
Fidelity tells you about quality. It says nothing about quantity. So I went looking for the rate, and the rate is remarkable — in the other direction.
The Supplemental Document, which is where the good stuff always is, does the sums for you. At Erlangen’s latitude of 49.6°N, in the season they measured:
Stage | Optical power |
|---|---|
Maximum solar power collectable by the 1.4 m² Fresnel lens | ~1.1–1.2 kW |
Of which, inside the 405 ± 0.75 nm band the crystal can use | ~1.7 W |
Full-spectrum power at the cone tip, near-perfect conditions | up to 5 W |
Reaching the entangled-photon source, in a 1.5 nm band at 405 nm | 100–200 nW |
Best achieved on the actual measurement days | up to 195 nW |
Read the first and last rows together. Something over a kilowatt of sunlight goes in the top. About a hundred and ninety-five billionths of a watt does the work.
That is not a criticism — it is what optical filtering costs, and the authors are completely open about it. The cone runs at 30 ± 3% concentration efficiency and was designed for broad visible collection rather than 405 nm; their own ray-tracing says a higher-index glass could reach 67%. The colour film that blocks the warm end also reflects a meaningful fraction of the 405 nm they want. The crystal’s phase-matching acceptance is only 0.2–0.3 nm wide, so most of even the surviving 1.5 nm slice does nothing at all.
Now convert that to photons. The paper: “we extract an average coincidence rate of 10 counts per minute per 100 nW of pump power.”
At a peak of 195 nW, the machine in that tent was detecting entangled pairs at somewhere around ten to twenty per minute. One every three to six seconds.
The number that travelled instead was 1,600 per second. That figure is real, and it is a normalisation — pairs per second per milliwatt of pump power — for a milliwatt they were never within four orders of magnitude of having. It is the correct way for physicists to compare sources. It is a wildly misleading thing to read as a throughput.
And the paper gives you the comparison too: the same measurement for laser-pumped SPDC is ~7,500 s⁻¹ per milliwatt, from the earlier reference this work benchmarks against. Sunlight is about 4.7 times less efficient per milliwatt — my arithmetic on their two numbers; the paper says only “somewhat less” and prints no ratio. It becomes “comparable” once you normalise for the bandwidth of the nonlinear interaction, which is a legitimate physics comparison because it isolates the process from the optics.
✋ Correction one: the caveat was never dropped
Here is where my first draft was wrong, and it was wrong in the way I most dislike.
I had written that the bandwidth qualifier got sanded off as the story moved from paper to press release to feed. I checked. It didn’t.
The published abstract says the rate is “comparable to that of the laser-pumped SPDC when normalized for the spectral bandwidth of the pump.”
The Optica press release says the entanglement was “comparable to laser-based approaches after accounting for differences in the bandwidth of the input light.”
The Max Planck release says the efficiency is on par “when the photon production rate is normalized against the pump power and effective bandwidth of the nonlinear process.”
Three sources. Three qualifiers, in the same sentence as the claim, every time. Nobody hid anything. The scientists and both press offices did their jobs properly, and my draft accused them of something they hadn’t done.
What actually happened is duller and more useful to know: the compression happened downstream, in aggregation — in the layer of sites that rewrite a release into two hundred words and drop the subordinate clause because it’s the longest thing in the sentence. That’s not a villain. It’s a mechanism. And the defence against it isn’t outrage at press officers, it’s opening the primary source, which in this case is free on arXiv and takes about twenty minutes.
The thing genuinely absent from coverage, as far as I can find, is the absolute rate — the ten-to-twenty-a-minute figure and the 195 nanowatts behind it. Not because anyone concealed it. Because it’s in the supplement, and almost nobody opens the supplement.
🔐 The sentence that turned physics into a security claim
Every version of this story carried some form of this, and it comes from the researchers themselves:
“This technology could one day enable satellites to create secure encryption keys using the sunlight already abundant in space, reducing the need for onboard lasers and much of the supporting hardware.”
Note the construction. Could one day. It’s a careful sentence, and it points at a real technology: quantum key distribution, QKD, which is what entangled photons are for when they’re for security at all.
The pitch is seductive. Two parties share entangled photons. Any eavesdropper who measures them disturbs them, and the disturbance shows up as errors. So you don’t have to assume your adversary is computationally limited — physics tells you they were there. Ordinary encryption rests on a maths problem being hard. QKD rests on quantum mechanics being true.
This is where you’d expect the newsletter to say “and that’s why it’s unhackable.”
It isn’t. And the people whose job is protecting classified traffic have said so, in public, at length, with unusual bluntness for government documents.
🚫 What six national agencies have written down
The United States. NSA, August 2021, still its standing FAQ. Asked whether QKD systems are unconditionally secure:
“No. While there are security proofs for theoretical QKD protocols, there are no security proofs for actual QKD hardware/software implementations. There is no standard methodology to test QKD hardware, and there are no established interoperability, implementation, or certification standards to which these devices may be built.”
Asked whether you should use one to protect a national security system: “No… NSA does not consider QKD a practical security solution for protecting national security information. NSS owners should not be using or researching QKD at this time without direct consultation with NSA.”
The United Kingdom. NCSC, white paper, 5 August 2025. Its objection is structural rather than about bugs, and it’s the sharpest paragraph anyone has written on this:
“QKD does not provide authentication, nor do any other quantum techniques. Therefore, in practice, QKD must be combined with other cryptographic services to provide security against the threat from quantum computing, and therefore should not be relied on as a mechanism that provides substantial security value.”
This is the bit that gets lost, and it is not a bug you can patch. QKD hands you a shared secret with a physics guarantee that nobody listened in. It does not tell you who you shared it with. An attacker who sits in the middle and runs the protocol honestly with each side satisfies the physics perfectly — and you have securely established a key with the attacker. So you still need classical authentication. Which means either pre-shared symmetric keys, whose distribution is the exact problem you were trying to solve, or post-quantum public-key cryptography, in which case the mathematics you were trying to escape is back and holding up the roof.
The NCSC’s conclusions: it “will not support the use of QKD for government or military applications,” and QKD “should not constitute evidence towards assessments of security of data-in-transit” under the UK’s Cyber Assessment Framework.
Germany, France, the Netherlands and Sweden. On 26 January 2024 the BSI published a joint position paper with France’s ANSSI, the Netherlands’ NLNCSA and the Swedish NCSA, analysing QKD’s limitations and challenges. Four agencies, one document, and the priority they name for quantum-safe migration is post-quantum cryptography.
That’s six agencies across six countries, including several of the most capable signals-intelligence establishments in the world.
One precision, since I’m holding others to their exact words: only the NSA literally wrote “No.” The NCSC wrote “will not support.” The four-agency paper is a technical analysis, and I haven’t read its body — only its publisher’s own summary. Six agencies pointing the same way is the accurate claim. Six agencies chorusing “no” would have been a better line and a worse sentence.
✋ Correction two: the certification gap has been closing
Here is my second mistake, and it’s the more interesting one.
I had intended to write that the standards vacuum the NSA described in 2021 — no standard methodology to test QKD hardware, no certification standards — was still a vacuum. It reads like a permanent condition. It isn’t, and it hasn’t been for a while:
ETSI GS QKD 016, released 24 April 2023: a Common Criteria Protection Profile for the security evaluation of QKD modules, covering prepare-and-measure protocols from the physical implementation through to the output of final secret keys. ETSI called it a world first. The BSI supported its development — the same agency that co-signed the sceptical position paper nine months later.
ISO/IEC 23837-1:2023 and 23837-2:2023: security requirements, and test and evaluation methods, for QKD, built to slot into the ISO/IEC 15408 (Common Criteria) framework.
So the honest version is this: the NSA’s 2021 complaint was accurate when written and has been substantially answered in the years since. QKD hardware can now be put through a formal, adversarial, internationally-recognised evaluation.
And the agencies’ position did not change anyway. That’s the part worth sitting with. The NCSC’s 2025 paper isn’t dismissive about assurance — it notes “recent progress on assurance of quantum technologies” and calls implementation security “an ongoing challenge, albeit one that the quantum industry and assurance community will continue to address.” That’s a fair-minded sentence about work in progress.
The objection that survived certification is the one that certification cannot touch: QKD does not authenticate. You can evaluate a box to the highest assurance level in the catalogue and it will still not tell you who is on the other end of the fibre. That is a property of the protocol, not the product.
Which means the useful question about any QKD claim is not “has it been certified.” It’s “what authenticates the classical channel.”
🔦 And then there’s the flashlight
The NSA’s phrase — no security proofs for actual hardware — stays abstract until you look at what happens when someone attacks the actual hardware.
In 2010, Lydersen, Wiechers, Wittmann, Elser, Skaar and Makarov published “Hacking commercial quantum cryptography systems by tailored bright illumination” in Nature Photonics. The attack is almost rude in its simplicity.
Single-photon detectors in QKD systems are typically avalanche photodiodes, biased so that one photon triggers a cascade. Shine a bright continuous light at them and they stop being single-photon detectors. They drop into linear mode, where they only click if the light exceeds a threshold. At which point an eavesdropper can decide, precisely, when the receiver clicks — by sending a tailored bright pulse.
The finding: the detectors in two commercially available QKD systems could be fully remote-controlled, making it possible to acquire the full secret key tracelessly. The authors proposed — did not build — an eavesdropping apparatus assembled from off-the-shelf components. The error rate that’s supposed to expose an eavesdropper stays flat, because nothing is disturbing a quantum measurement; the quantum channel has simply been lifted out of the loop. Their assessment was that the loophole was likely present in most QKD systems using avalanche photodiodes.
Let me be scrupulous, because it would be easy and wrong to imply the sunlight paper is insecure. It is not a QKD system. No key was distributed, no channel established, and nobody claimed otherwise. It is a physics experiment measuring the quality of a light source, and it does that well.
But it detects with avalanche photodiodes — the paper names the models — and that is the component class with a fifteen-year-old, still-live attack literature. The distance between “we made entangled photons” and “satellites can make secure keys” is not spanned by the photon source. It’s spanned by everything downstream: detectors, timing electronics, random number generation, calibration, authentication, and the classical post-processing where, historically, essentially every practical QKD break has actually lived.
The maths of QKD has never been broken. The boxes have been, more than once. The field has spent fifteen years hardening them and inventing measurement-device-independent schemes to route around the problem, and that work is serious. It’s also the reason the protection profiles above exist.
✅ What to actually do about it
The sunlight paper changes nothing about your week. The thing it points at — the quantum threat to encryption — very much should.
1. Get the threat right. It isn’t a satellite. It’s harvest-now-decrypt-later: an adversary copying your encrypted traffic today and warehousing it until a cryptographically relevant quantum computer exists. Anything with a secrecy lifetime longer than that gap is at risk today, whatever you deploy tomorrow.
2. Do discovery first, and now. You cannot migrate cryptography you cannot find. The NCSC’s published timeline gives organisations until 2028 to complete a full discovery phase — every system and service depending on cryptography, every dependency, and an initial migration plan. That is closer than it reads.
3. Follow the rest of the same timeline. 2031 for the highest-priority migrations and infrastructure preparation; 2035 for complete migration across all systems, services and products. The NCSC expects finance and telecoms to move earlier and flags industrial control systems and IoT as likely to lag. If that’s your estate, start earlier, not later.
4. Use the standardised algorithms. NIST finalised its first three post-quantum standards in August 2024, after years of open international cryptanalysis. That adversarial process is the reason to trust them.
5. Prefer hybrid through the transition. Classical and post-quantum key establishment together, so that a break in either one alone doesn’t sink you. Mainstream advice, and cheap.
6. Buy crypto-agility, not algorithms. The most valuable property in anything procured today is the ability to swap primitives without a forklift. Ask vendors how, specifically, they ship a new algorithm to a deployed device. A concrete answer is a good sign.
7. If someone sells you QKD, ask the authentication question. Not “is it quantum.” Ask: “what authenticates the classical channel, and where do those keys come from?” If the answer is post-quantum cryptography, you’ve bought PQC with an expensive optical accessory. If it’s pre-shared symmetric keys, ask how that scales beyond a handful of fixed links. Either can be legitimate for a specific point-to-point problem. Neither is general-purpose.
8. Ask the certification question too — now that there’s an answer to give. ETSI GS QKD 016 and ISO/IEC 23837 exist. “Evaluated against a recognised protection profile” is a real thing a vendor can now claim, and a real thing you can now ask them to evidence.
9. Don’t let QKD count as assurance on its own. The NCSC states this directly for the Cyber Assessment Framework. If a supplier’s data-in-transit assurance rests on a QKD link, that assurance has a hole where the authentication should be.
10. Watch the rate, not the fidelity. If a field-deployable version of this source appears, the number that matters is absolute pairs per second at the receiver, under real sky, across a full day. Fidelity tells you the light is good. Rate tells you whether there’s a product. Today it’s tens per minute at noon in Bavaria.
🧭 Where this piece could still be wrong
I read arXiv:2602.15655v2 (revised 15 May 2026), including its Supplemental Document, not the paywalled journal typeset. DOI and abstract match. Worth knowing: v1 of the preprint states the Bell violation as 2.94 standard deviations; v2 and the published version say 2.49. 2.49 is the arithmetically correct figure — (2.5408 − 2) ÷ 0.2171 = 2.491 — so v1 appears to contain a slip that was fixed. If you check my number against v1, that’s why it differs.
The 4.7× figure is my arithmetic, 7500 ÷ 1600. The paper says “somewhat less” and prints no ratio. And the 7,500 figure comes from the earlier benchmark paper’s setup — I have not established that a laser was run through the Erlangen sunlight rig, and an earlier version of this piece implied that it was.
“Ten to twenty pairs a minute” is my inference, from two of the paper’s own statements: 10 counts per minute per 100 nW, and a measured maximum of 195 nW. Off-peak that figure falls. The order of magnitude — tens per minute, not thousands per second — is what I’m confident about.
The four-agency European position paper: I have the publisher, the co-signatories and the 26 January 2024 date from the BSI’s own publication page. I have characterised its conclusions from that page and consistent secondary reporting, and I have not quoted from its body.
The 2010 blinding attack targeted two specific commercial products of that era. The field responded. I’ve reported the original finding, not claimed today’s products are equally exposed.
“No coverage mentioned the absolute rate” is a claim about the coverage I found. I did not survey all of it.
📌 The short version
A team in Ottawa and Erlangen took an argument published by other people in 2020, an amateur telescope mount, some theatre lighting gel and a cone of glass, and made entangled light out of daylight. The physics is real, the Bell test is honest, and the researchers were right when the room told them they were wrong.
Then a careful sentence about what satellites could one day do got compressed, somewhere downstream of two scrupulous press releases, into sunlight making unbreakable encryption.
And when I went to prosecute that gap, the two easy accusations both fell over. The caveat was there all along. The certification regime got built while nobody was looking.
What’s left is the thing that was never a paperwork problem: quantum key distribution does not tell you who you’re talking to. Six national agencies have said so in public documents you can read this afternoon, and no amount of beautiful light fixes it.
Enjoy the physics. Ten pairs a minute, out of the sky, for free. Just don’t let it into your threat model.
📚 Sources, and what each one is
The paper. Li, Brar, Küblböck, Upham, Fattahi & Boyd, “Generating quantum entanglement from sunlight,” Optica 13(8), 1508–1514 (2026), DOI 10.1364/OPTICA.601797. Preprint and Supplemental Document: arXiv:2602.15655v2. Every number about the experiment comes from here.
Optica press release, 6 August 2026 — the “secure encryption keys” quote, the Cheng Li quote, and the “after accounting for differences in the bandwidth of the input light” qualifier.
Max Planck Institute for the Science of Light press release, 6 August 2026 — the concentrator description and the “normalized against the pump power and effective bandwidth” qualifier.
Hutter, Lima & Walborn, Physical Review Letters 125, 193602 (2020) — the degrees-of-freedom argument this experiment rests on.
NSA, Quantum Computing and Post-Quantum Cryptography FAQs, PP-21-1120, August 2021 — the two “No” answers, verbatim.
NCSC, Quantum networking technologies, 5 August 2025 — the authentication argument, the government/military position and the Cyber Assessment Framework line, verbatim.
BSI, Position Paper on Quantum Key Distribution, 26 January 2024, jointly with ANSSI (France), NLNCSA (Netherlands) and the Swedish NCSA.
NCSC, Timelines for migration to post-quantum cryptography — the 2028 / 2031 / 2035 milestones.
ETSI GS QKD 016, Protection Profile for QKD modules, announced 24 April 2023, developed with BSI support.
ISO/IEC 23837-1:2023 and 23837-2:2023 — security requirements and evaluation methods for QKD.
NIST — the first three finalised post-quantum standards, August 2024.
Lydersen, Wiechers, Wittmann, Elser, Skaar & Makarov, “Hacking commercial quantum cryptography systems by tailored bright illumination,” Nature Photonics 4, 686–689 (2010).
Yin et al., “Satellite-based entanglement distribution over 1200 kilometers,” Science 356, 1140 (2017) — used only for the S = 2.37 ± 0.09 scale comparison.
Named limits: journal typeset not consulted; the pairs-per-minute figure is an inference from two separate statements in the paper; the four-agency position paper is characterised from its publisher’s summary, not quoted; the claim about what coverage omitted is based on the coverage I found.

