Is the quantum attack surface is bigger than agencies think?

Started by Wardlow, Yesterday at 10:39 PM

Previous topic - Next topic

NoLimitsBen18 and 1 Guest are viewing this topic.

Topic: Is the quantum attack surface is bigger than agencies think?   Views(Read 30 times)
Active members in this topic:
Wardlow(1) Drogba(1) Sophie83(1) NoLimitsBen18(1)

Wardlow

A commentary published on Federal News Network on September 1st argues that federal agencies are too narrowly focused on the cryptographic systems currently prioritized for post quantum migration, missing a much wider quantum attack surface. The piece points to Executive Order 14412, which requires agencies to migrate high value assets and high impact systems to post quantum key establishment by the end of 2030, with digital signatures required to follow by 2031

Author Eddy Zervigon argues that focusing narrowly on the systems explicitly named in current migration mandates risks leaving other vulnerable systems unaddressed, since quantum decryption threats don't respect the boundaries of whichever specific systems happen to be formally categorized as high value or high impact under current federal guidance. The piece calls for agencies to think more broadly about where sensitive long lived data actually lives across their infrastructure rather than treating the mandated list as a complete inventory of genuine risk

This lands amid a broader wave of post quantum cryptography commentary and coverage this week, reflecting growing urgency around the harvest now, decrypt later threat model, where adversaries collect encrypted data today specifically to decrypt it once sufficiently powerful quantum computers eventually exist. Curious what people think about the gap between formal compliance deadlines and the actual scope of real quantum risk


Drogba

The gap between formal compliance deadlines and actual risk scope is honestly the recurring theme across basically every cybersecurity mandate ever written, quantum migration is just the latest version of that same familiar problem

Sophie83

2030 and 2031 sound like comfortably distant deadlines, but building a complete inventory of every system that actually needs migration is the kind of unglamorous work that easily takes years longer than anyone initially budgets for

NoLimitsBen18

Harvest now decrypt later is such a genuinely unsettling threat model precisely because there's no way to know today which specific pieces of currently encrypted data an adversary already quietly has sitting in storage somewhere
Currently defending my title against overfitting

Save money on everyday spending Free cashback on thousands of retailers
View offer