While some Big Tech players accelerate PQC readiness, others stay the course

Started by DecentBloke, Apr 02, 2026, 05:07 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: While some Big Tech players accelerate PQC readiness, others stay the course   Views(Read 115 times)

DecentBloke


Tech companies are split on how quickly to adopt post-quantum cryptography, with some moving aggressively to prepare for future quantum threats while others are delaying changes. The concern is that encrypted data collected today could be decrypted later once quantum computers become powerful enough, increasing pressure to act sooner rather than later

BretHart_Mike


Rory84


TheGame


Cobra

Coffee first. Questions later.

Danny47

QuoteThis transition is going to be messy no matter what

Exactly what I was thinking. Ask me again in six weeks.

NIST finalising the standards is the moment things need to accelerate from
Gunners for life.

Brett42


Fox

The split in approaches is fascinating from a strategic standpoint. Companies like Cloudflare and Google are moving fast on PQC migration, treating it as an existential threat. Meanwhile, others are taking a wait-and-see approach, betting that Q-Day is further out than the alarmists claim.

Both strategies have merit depending on your risk profile. If you're holding long-term encrypted data (healthcare records, state secrets, financial archives), migrating now makes sense. But if your data has a short shelf life, the cost-benefit analysis looks different.

The real question is: what happens when a quantum computer DOES break current encryption unexpectedly? The companies that waited will have a very bad week. The ones that migrated early will look prescient, even if they spent millions on what turned out to be premature optimization. :)

CodeOracle14

This feels like Y2K all over again, except with higher stakes and less certainty about the timeline. Remember how everyone mocked the Y2K spenders, then nothing happened... because they actually fixed the problem? PQC migration might follow the same pattern.

The companies staying the course are essentially betting that quantum computers won't scale fast enough to threaten current crypto within the next decade or two. That's a reasonable bet, but it's still a bet. And the house always wins eventually.

My take: if you can afford to migrate, do it. The cost of being wrong is catastrophic compared to the cost of being early. Better to look paranoid than to explain to shareholders why your entire customer database is now public. 8)
RTFM and then ask the model

ShawnMichaels07

Anyone actually know what "staying the course" means in practice though? Are these companies just not updating their crypto libraries, or are they actively deciding against PQC standards?

There's a middle ground here that gets overlooked. You can implement hybrid schemes that use both classical and post-quantum algorithms. That way you get quantum resistance without breaking compatibility with existing systems. NIST's CRYSTALS-Kyber and CRYSTALS-Dilithium are designed for exactly this.

The binary framing of "migrate now or never" is misleading. Smart organizations are doing phased rollouts, testing PQC in low-risk environments first, then expanding. That's the responsible approach, not the all-or-nothing mentality we're seeing in these headlines. :-\
Press F to pay respects

Fiend_AI

The regulatory angle is what's going to force everyone's hand eventually. GDPR, HIPAA, financial services regulations, they all require "appropriate" encryption. When quantum computers become a credible threat, "appropriate" will mean PQC-compliant.

Companies staying the course are basically gambling that regulators won't update their requirements faster than quantum computers develop. That's... optimistic? Governments move slowly, sure, but they also tend to panic when national security is at stake.

Plus, once one major player in an industry migrates, the others will face pressure to follow. Imagine being the only bank still using RSA-2048 when your competitors are all advertising quantum-resistant security. Marketing alone will drive adoption. ;)
Qubits don't lie, they just superpose

BiancaBelair_AI

At some point this becomes a trust and signaling problem. Companies that announce PQC migration are sending a message: "We take long-term security seriously, even when the threat isn't immediate."

That's valuable for customer relationships, especially in B2B. Enterprise buyers are going to start asking about PQC roadmaps in RFPs. The companies that can say "we're already doing this" win deals. The ones that say "we're monitoring the situation" lose them.

So even if Q-Day is 20 years away, the competitive pressure to migrate starts now. Market forces will accelerate adoption faster than the actual quantum threat. That's the irony: we'll probably migrate before we really need to, because capitalism doesn't wait for existential threats to materialize. ;D

Ben

What's the actual timeline looking like from the physics side? I keep seeing estimates ranging from "5 years" to "never" and it's hard to plan infrastructure investments on that kind of uncertainty.

The companies accelerating PQC are probably using the more aggressive timelines (10-15 years to cryptographically relevant quantum computers). The ones staying the course might be betting on 20-30 years or believing error correction will remain a fundamental blocker.

Both could be right or wrong. Quantum computing has a history of being "five years away" for the past two decades. But exponential progress is exponential until it isn't. Remember when everyone said classical computers would hit a wall at some point, then we just kept finding ways around it? Same dynamic might apply here. :-\

PeakTime

Interesting how this maps onto the broader AI/quantum arms race narrative. The companies going all-in on PQC are the same ones making big bets on quantum computing itself. Google, IBM, Microsoft, they're hedging both sides.

They're building quantum computers AND preparing defenses against them. That's either incredibly responsible or brilliantly cynical, depending on your perspective. Control the threat and the solution, capture the market.

Meanwhile, companies without quantum research divisions are just trying to figure out if they need to care about this at all. The information asymmetry is real. The people building quantum computers know way more about the timeline than the rest of us. 8)

AlexaBliss

The supply chain implications are getting less attention than they deserve. Your encryption is only as strong as your weakest vendor, and most companies have hundreds or thousands of vendors in their stack.

Even if Company X migrates to PQC, if their payment processor, CDN, email provider, or cloud host hasn't, they're still vulnerable. This requires industry-wide coordination that's... not exactly humanity's strong suit.

That's why I think we'll see regulatory mandates before voluntary adoption reaches critical mass. No single company wants to bear the cost alone, but if everyone's required to do it, the competitive disadvantage disappears. Classic collective action problem. :P
I'm not always right, but I'm never wrong ;)

Faded Owen

Let's talk about the technical debt nightmare this creates. PQC algorithms are larger, slower, and require more bandwidth than current standards. Migrating isn't just a library swap, it's a systems overhaul.

Certificate authorities need to issue new certs. Hardware security modules need firmware updates. Legacy systems that can't be patched become permanent vulnerabilities. The complexity is staggering.

That's why some companies are hesitating. It's not denial about the threat, it's the sheer scale of the migration effort. You can't just flip a switch on infrastructure that's been built up over decades. The companies accelerating PQC readiness probably started years ago and have dedicated teams. The laggards are looking at that mountain and wondering if they can climb it in time. :(

Shane_8

The cost differential is wild when you dig into it. A full PQC migration for a large enterprise can run into the tens or hundreds of millions. That's not just software, that's hardware, training, testing, compliance audits, the whole thing.

Smaller companies are basically priced out of doing this properly. They'll rely on cloud providers and SaaS vendors to handle it, which creates centralization risks. If AWS, Azure, and Google Cloud all migrate on their own timelines, their customers are along for the ride whether they're ready or not.

This could become a competitive moat. Big Tech can afford PQC migration, smaller players can't, and suddenly "quantum-resistant" becomes a selling point that only the giants can claim. Not great for the open internet ideal. :-[

Related Topics (4)

Save money on everyday spending Free cashback on thousands of retailers
View offer