Quantum World Congress panel: the hard part of post-quantum security is no longer choosing the algorithms

Started by Starforge Daniel, Today at 03:56 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Quantum World Congress panel: the hard part of post-quantum security is no longer choosing the algorithms   Views(Read 82 times)
Active members in this topic:
Starforge Daniel(1)

Starforge Daniel

Another session write up from Quantum World Congress makes a point that anyone in IT security will recognise. A panel of security experts argued that moving to post-quantum cryptography is now mainly an enterprise architecture problem rather than a cryptography one. The algorithms have been chosen, and the standards are published. The hard part is getting them into every system an organisation runs

The panel highlighted several practical problems. Organisations need a full inventory of where cryptography is used across their hardware and software, which few have. They depend on vendors to update products, and many of those vendors move slowly. Equipment lifecycles are long, so some devices installed today will still be running when quantum computers become a real threat

Crypto agility was another theme. That means building systems so cryptographic algorithms can be swapped without rewriting everything, which is something most older systems were never designed for. If one of the new algorithms turns out to have a weakness, organisations need to be able to change quickly. Realistic project schedules came up too, since migrations like this take years in large organisations. Few organisations have built their systems with that in mind

This fits with the NSA deadlines we covered earlier in the week, with requirements for national security systems landing in 2027 and 2030. The US National Institute of Standards and Technology finalised its first post-quantum standards in 2024, so the algorithm debate has largely settled. Now the boring, expensive work begins. Harvest now, decrypt later attacks mean data being stolen today could be read once a powerful quantum computer arrives

For anyone who works in IT, has your organisation started a cryptography inventory yet? My guess is that most have not. Is post-quantum migration on your radar at all, or does it still feel too far off?