Post quantum cryptography: is it already on your devices?

Started by TechPriest, Today at 11:57 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Post quantum cryptography: is it already on your devices?   Views(Read 68 times)
Active members in this topic:
TechPriest(1)

TechPriest

Q-Day, the day quantum computers can break today's public key encryption, may still be years away. But the move to post quantum cryptography has already begun, mostly behind the scenes. In 2024, the US National Institute of Standards and Technology published its first finished post quantum standards, including ML-KEM for key exchange and ML-DSA for digital signatures. Since then, they have started appearing in everyday software

Some big names moved early. Signal added post quantum protection to its messaging protocol in 2023, and Apple introduced its PQ3 protocol for iMessage in 2024. Google Chrome and other browsers have enabled hybrid post quantum key exchange for many websites, combining classic and quantum resistant methods. Cloudflare has said that a large share of the traffic it handles now uses post quantum key agreement. OpenSSH, used by system administrators everywhere, has also made post quantum key exchange the default

The reason for the rush is the harvest now, decrypt later threat. Data intercepted today could be stored and decrypted once a powerful enough quantum computer exists. For secrets that need to stay private for decades, like medical records, state secrets or financial data, waiting until Q-Day would be too late

Most people will never notice the change, which is exactly the point. But it is interesting to check what your own devices and services are already using. Some browsers and tools will show the key exchange method used for a connection, if you know where to look

Have you noticed post quantum cryptography on your devices? And do you think the migration is moving fast enough?