tsimionescu

I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.

show comments
dredmorbius

PQC: Post-Quantum Cryptography.

The concern is systems which won't be resistant against quantum cryptographic attacks.

The US's NIST has an explainer page, "Post-Quantum Cryptography PQC":

<https://csrc.nist.gov/projects/post-quantum-cryptography>.

colmmacc

I was at ANSSI headquarters last year doing a technical presentation and several of their questions were about Post-Quantum Cryptography, "Q day" (when a practical Quantum Computer is expected) and other related things. They keep a close eye on this stuff and it's to their credit. Similarly the BSI in Germany have been promoting Post-Quantum security for some time now.

I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!

cold_pizz4

Related: https://news.ycombinator.com/item?id=48992806 (Are 128-bit symmetric keys really secure against quantum computers?)

vaadu

Will they decertify previously certified PQC-free products?

show comments
6r17

TBF it's the healtiest approach to it. It's just risk mitigation. Nobody cares about it - there are nice papers to implement it ; just freaking do it.