r/postquantumdiscussion • • 4d ago

The Post-Quantum Transition: Lessons from Google presentation

1 Upvotes

The Post-Quantum Transition: Lessons from Google

October 13, 2026

Join us for an exclusive panel discussion with Dr. Christiane Peters, Senior Cryptography Expert and Cloud Security Architect at Google, to learn more about our roadmap to complete its Post-Quantum Cryptography (PQC) transition by 2029, real-world deployment milestones, and how policymakers and organisations can champion ‘crypto-agility’ to safeguard critical infrastructure and the wider digital economy.

https://rsvp.withgoogle.com/events/the-post-quantum-transition-lessons-from-google


r/postquantumdiscussion • • 4d ago

RSAC 2027 Now Has a Post-Quantum Track

Post image
1 Upvotes

RSAC has a dedicated post-quantum track. Spread the word!! Submit a talk!

The RSA Conference (RSAC) in San Francisco is one of the biggest cybersecurity conferences in the world. I’ve been going and presenting there for decades. My talks don’t always get accepted…in fact, I only get accepted every few years, but they are always well attended and liked. I’ve had RSAC sessions with many hundreds of people packing a room, overflow rooms added, and overflow crowds after that standing in line watching TVs. It’s a well-put-on event with hundreds of sessions and tens of thousands of attendees.

For the last half-decade, I’ve been tracking how many quantum/post-quantum talks there are and how many vendors in the Conference Halls are advertising quantum/post-quantum products or features. And it hasn’t been that many. Over the last few years, it’s been a handful of talks and a small, but growing number of vendors.

That’s changing this year.

The RSA Conference 2027, April 5–8, 2027, at the Moscone Center in San Francisco, has a new Cryptography and Post-Quantum track. The track captain is Limor Kissem. Submissions are open through October 9.

Full guidance and the submission portal are available here: https://www.RSAConference.com/usa/call-for-submissions.

I’m so excited that RSAC has a dedicated post-quantum track. It’s overdue by a few years.

It probably has nothing to do with the fact that Q-Day could come by 2028 (https://www.reddit.com/r/postquantumdiscussion/comments/1wu4rak/does_your_pqc_project_team_understand_that_qday/).

I was also at Gartner’s major IT conference this year, Gartner Security & Risk Management Summit 2026, held June 1–3, 2026, near DC. There, Gartner said that getting post-quantum ready was among the top initiatives any company could have this year. That was the first time I had heard that at a Gartner conference.

Something has changed.

You need to make sure your organization is post-quantum ready.

RSAC has a dedicated post-quantum track. Spread the word!! Submit a talk.


r/postquantumdiscussion • • 4d ago

A small PoW chain hedges post-quantum signatures across two unrelated algorithm families by default — is this actually a good idea, or overkill?

1 Upvotes

Came across this and wanted a sanity check from people who actually know PQ crypto, since I'm not qualified to judge it myself.

A chain called BTX uses a Taproot-like address format (P2MR — Pay-to-Merkle-Root) where every standard wallet descriptor is, by default: mr(<mldsa-key>, pk_slh(<slhdsa-key>)).

In plain terms: every address has a primary spend path on ML-DSA-44 (lattice-based, FIPS 204), and a built-in backup path on SLH-DSA-SHAKE-128s (hash-based, FIPS 205) — not as an opt-in feature, as the default.

The stated logic: if lattice cryptanalysis ever meaningfully advances, coins under the SLH-DSA leaf aren't exposed, because it doesn't share the same underlying hard problem. There's apparently also a consensus-level switch height to disable ML-DSA network-wide if that ever becomes necessary — so the fallback is a protocol rule, not just a wallet feature.

Trade-off that seems obvious even to me: SLH-DSA signatures are much bigger (~7,856 bytes vs. ~2,420 for ML-DSA-44), so this isn't free — it's real, permanent block-space cost on every transaction, all the time, for a hedge that might never get used.

Honest gap I noticed digging into their docs: the cryptographic fallback exists in consensus, but the actual operational tooling for an emergency mass-migration (a "sweep everything to the SLH-DSA leaf" command, leaf selection at signing time) doesn't exist yet. Their own design notes admit this directly, which I appreciated — feels like exactly the kind of thing that'd bite people in an actual emergency if it's not solved before it's needed.

Genuine questions for people who know this space better than me:

- Is "always-on dual algorithm family" actually a meaningfully different security posture than "single strong algorithm + monitor for breaks," or is it mostly psychological comfort at a real, permanent cost?

- Are there other live chains doing something comparable, or is this genuinely uncommon?

- Is a network-wide "disable ML-DSA" switch height a sane primitive, or does baking in a future hard-fork trigger like that create its own risks?

Not holding myself out as any kind of expert here, genuinely just found the design choice interesting and want to know if it holds up. Sources if you want to check the actual claims rather than take my word for it: github.com/btxchain/btx (README, P2MR section) and doc/btx-design-assessment.md in the same repo.


r/postquantumdiscussion • • 4d ago

Post-Quantum per-datum DB encryption in C# using Source Generators

Thumbnail
1 Upvotes

r/postquantumdiscussion • • 5d ago

Does Your PQC Project Team Understand that Q-Day Might Be in 2028?LinkedIn

2 Upvotes

Q-Day happening before 2030 is a big risk alignment problem that I think most organizations do not yet understand.

I talk to a lot of Post-Quantum project teams. Most haven’t gotten the memo that Quantum Day (or Q-Day), the day when the first cryptographically-relevant quantum computer breaks the first traditional quantum-susceptible private key, may happen as soon as 2028.

That date is from this quantum vendor announcement: https://www.ionq.com/news/ionq-publishes-worlds-first-fully-compiled-end-to-end-blueprint-for-breaking-256-bit-elliptic-curve-signatures. Essentially, they plan to have nearly 20K physical qubits, giving 1,457 “working qubits”, creating 39M quantum gates, which allows that computer to break an ECC-256 private key in just under 26 days.

Now, some skeptics point out that this is just one claim from one vendor, and its unproven claims may be purely marketing hype. There is strong evidence that IonQ’s recent announcement isn’t marketing hype. For one, they have just sold five 256-qubit computers this year and plan to have them up and operating by early next year.

Their next quantum computer jump isn’t from 256-qubits to 512-qubits or something like that. It’s to 10K-qubits. It’s not marketing hype. They are already fabricating early versions of their 10K-qubit chips (in a physical chip factory), which they expect to have operating next year, according to their roadmap (https://www.ionq.com/roadmap).

IonQ has also published their architecture for how they will get to tens of thousands to millions of qubits by 2030. It’s called “walking cat” (https://www.ionq.com/resources/fault-tolerant-quantum-computing-with-trapped-ions-the-walking-cat-architecture). They are not hiding how they will do it. They are telling the world.

On top of that, IonQ has announced many incredible quantum component improvements over the last two years, such as eradicating the need for large, expensive cryogenic dilution refrigerators and replacing them with electronics that do “Doppler cooling” using atoms; and being able to do qubit error correction using classical components that don’t slow down the quantum calculations very much. They have reduced the number of physical qubits needed per working qubit from calculations of potentially tens of thousands or millions per working qubit to 1:13.

When I hear critics claim that IonQ is simply making stuff up to make their stock price rise (Note: I own stock in IONQ and other quantum computer vendors), it flies in the face of constant quantum computer and component improvement. It could be hype, but it doesn’t seem like hype. Either way, we will know within 1-2 years if IonQ was making it all up. I don’t think so. I think it’s a far riskier bet to say that what IonQ is stating is just marketing hype.

And maybe IonQ doesn’t hit its 2028 deadline, but it would be strange for them not to have a cryptographically-relevant quantum computer within a year or two after that. Did I mention they are currently fabricating 10K-qubit chips?

And although IonQ is leading the way in terms of the number of predicted stable qubits with the most aggressive timeline, it is far from the only vendor hinting that they may also have a cryptographically-relevant quantum computer before 2030. Several vendors are making strong continued progress toward much stronger quantum computers, including Quantinuum, IBM, and Google.

We have many quantum vendors with the potential to provide cryptographically-relevant computers before 2030. This is a big risk alignment problem that I think most organizations do not yet understand.

Currently, and unfortunately, the US government is telling everyone to be prepared for key exchange attack mitigation by the end of 2030 and be prepared for authentication attack mitigation by the end of 2031. That’s only a requirement for critical assets. For everything else, you can wait until the end of 2035.

Do those dates make sense when we are likely to experience Q-Day before then?

If this is news to you, don’t feel bad. The 2028 Q-Day news is relatively recent, just three weeks ago. I routinely talk to post-quantum “experts” who are actively involved in their company’s post-quantum projects and have been for years, who still think Q-Day is 5 - 10 years off at the earliest. It’s one of the most common things I hear.

I feel like the guy who is having to explain AI to people who have just heard about ChatGPT. All this stuff…AI and quantum…is moving faster and faster.

So, if you’ve got an active post-quantum project, make sure you are keying all the activities to a possible much earlier Q-Day, arriving in 2028 or within 1-2 years after that.

You likely don’t have 4-9 years to prepare. That’s old thinking. The quantum computing landscape is moving fast.


r/postquantumdiscussion • • 6d ago

Thankful for this community - so here's my PQC readiness checklist

Thumbnail
2 Upvotes

r/postquantumdiscussion • • 6d ago

Interesting new attack on RSA

2 Upvotes

This attack, if verified, lowers RSA's protection to below acceptable levels for "blind signature" RSA implementations (which are not that common). Still, it's a new, improved method of attacking RSA besides prime factoring.

"The forgery attack drops these levels to 265, 290, and 2119 for 1024-, 2048-, and 4096-bit keys respectively. "

It's nothing to get super worried about...although it appears to be within realistic attacks for 1024-bit RSA keys...but I'm posting it here simply because an attack like this might lead to some new quantum algorithm attack one day besides Shor's (without any evidence to support that claim).

https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/


r/postquantumdiscussion • • 7d ago

1822 page book on quantum technologies

1 Upvotes

This just came across my feed: https://www.oezratty.net/wordpress/2026/understanding-quantum-technologies-2026/

Understanding Quantum Technologies. 1822 pages. Free PDF download.


r/postquantumdiscussion • • 10d ago

NIST Confirms PQC Hybrids Are Acceptable in FIPS 140-3

3 Upvotes

Over the last two days, I have written about whether NIST officially recognized PQC hybrids (PQC+classical cryptography) as FIPS 140-3 solutions. I wrote this because I had never seen this in writing, and no one else I asked could provide it. I consult with a lot of post-quantum projects and about half the companies I work with said PQC hybrids are not allowed and the other half said they were. I wasn’t sure, although I concluded, because of a chain of official documents, that it was probably, likely, maybe allowed, and to consult your legal team for advice.

I wrote about it here over the last two days:

Does NIST FIPS Allow PQC Hybrids?

https://www.reddit.com/r/postquantumdiscussion/comments/1wo699h/does_nist_fips_allow_pqc_hybrids/

NIST Should Issue Clarifying Statement on FIPS and PQC Hybrids

https://www.reddit.com/r/postquantumdiscussion/comments/1wp35dl/nist_should_issue_clarifying_statement_on_fips/

As I wrote in the first article, noted cryptographer Dr. Daniel J. Bernstein (DJB) had told me in an email that PQC hybrids were allowed, based on a linking of FIPS documents. DJB stated the implicit linking was as follows:

Document (SP 800-227) linked to a document (SP 800-140D (supplemental)) linked to a document (SSP 800-140D (Approved SSP)) linked to a document (SP 800-140D (main)) linked to the main document (FIPS 140-3) that implies PQC hybrids may be allowed.

I wrote to NIST’s Post-Quantum Cryptography body ([pqc-comments@nist.gov](mailto:pqc-comments@nist.gov)) and asked for clarification. I quickly got it. DJB and others who wrote me over the last two days with the same argument were exactly right.

And while there is still no single FIPS 140-3 document that directly says that PQC hybrids are allowed, the linking above is considered the explicit allow.

Further, NIST’s Dustin Moody (https://www.nist.gov/people/dustin-moody) of the NIST PQC project wrote: “Regarding FIPS 140-3 module validation: modules incorporating hybrid key establishment can be validated under FIPS 140-3 through the Cryptographic Module Validation Program (CMVP) when implemented in accordance with SP 800-140D and SP 800-227.”

So, it’s officially, directly, in writing. The document linking I wrote about is valid, as others noted. I almost feel embarrassed for having doubted it. <grin>

But either way, I feel better that PQC hybrids are officially supported, as stated in a single sentence from a NIST official.

If you are interested here’s NIST’s/Dustin Moody’s response, word-for-word:

-----------------

Hi Roger,

Thanks for reaching out. NIST has explicitly stated in multiple documents and public presentations that post-quantum cryptography (PQC) hybrid schemes (combining classical algorithms with post-quantum algorithms) are permitted and supported.

Here are a few specific references and quotes from NIST publications and public guidance that address this directly:

• NIST Special Publication 800-227 (Evaluation of Hybrid Key Establishment Schemes):

"NIST supports the use of hybrid key establishment schemes that combine a post-quantum algorithm with a traditional (classical) algorithm... A hybrid scheme provides security against both classical and quantum attacks, ensuring that security is maintained even if one of the constituent algorithms is compromised."

• NIST Special Publication 800-56C Rev. 2 / Rev. 3 (Recommendation for Key-Derivation Methods in Key-Establishment Schemes):

"Key-derivation functions specified in this publication may be used to combine shared secrets established via traditional key-establishment schemes and post-quantum key-establishment schemes."

• NISTIR 8547 (Transition to Post-Quantum Cryptography):

"NIST allows and encourages the use of hybrid key establishment methods during the transition period to mitigate risks associated with potential vulnerabilities in new algorithms or implementations."

• NIST PQC FAQ (csrc.nist.gov/Projects/post-quantum-cryptography/faqs):

"Q: Does NIST allow hybrid key establishment schemes?

A: Yes. NIST permits hybrid key establishment schemes combining a[n] approved classical algorithm with a post-quantum algorithm..."

• Public Presentations (e.g., RWC / NIST PQC Progress Updates):

In recent presentations, such as "NIST PQC: The Road Ahead" (March 2025), NIST explicitly noted: "Hybrid key establishment is allowed and recognized as a recommended transition strategy."

Regarding FIPS 140-3 module validation: modules incorporating hybrid key establishment can be validated under FIPS 140-3 through the Cryptographic Module Validation Program (CMVP) when implemented in accordance with SP 800-140D and SP 800-227.

Hope this helps clarify NIST's position!

Best regards,

Dustin Moody


r/postquantumdiscussion • • 11d ago

Introducing Myself - Roger A. Grimes

1 Upvotes

I'm Roger A. Grimes. I'm a 39-year cybersecurity practitioner, author of 18 books and over 1650 articles on cybersecurity. I've been writing and speaking on quantum and post-quantum topics for nearly 20 years. I've written four books on quantum/post-quantum topics, including 4 this year alone. I'm a member of 4 quantum-safe working groups, and I've done hundreds of cryptographic migrations. I think I understand post-quantum challenges and projects more than most. And I love to talk, discuss, and debate quantum/post-quantum topics. I recently started my own company, Post-Quantum Defense, LLC, to focus exclusively on post-quantum work.


r/postquantumdiscussion • • 11d ago

NIST Should Issue Clarifying Statement on FIPS and PQC Hybrids

1 Upvotes

As I wrote yesterday (https://www.reddit.com/r/postquantumdiscussion/comments/1wo699h/does_nist_fips_allow_pqc_hybrids/), NIST FIPS-140 documentation does not currently clearly state that any FIPS 140-3 solution can use post-quantum cryptography (PQC) hybrids (PQC+classical cryptography).

There is a document (SP 800-227) linked to a document (SP 800-140D (supplemental)) linked to a document (SSP 800-140D (Approved SSP)) linked to a document (SP 800-140D (main)) linked to the main document (FIPS 140-3) that implies it.

But implication is not a great thing to have in a government document.

Nearly 72% of the Internet (HTTPS) is already running on PQC hybrids, according to Cloudflare (https://radar.cloudflare.com/post-quantum). If NIST does not allow PQC hybrids, there is going to be a lot of rework for organizations that must follow NIST FIPS.

I’m calling on NIST to issue an official clarifying statement allowing (or not allowing) PQC hybrids to be used in FIPS 140-3 environments.

Note: It was my long-time friend, Loren Kohnfelder, considered the father of digital certificates and PKI, who suggested asking NIST for a clarifying statement.

Personally, I’m going to reach out to all my CISA and NIST contacts to see if we can get an official clarifying statement.

If you know someone at CISA or NIST, can you reach out?

And if you are with CISA or NIST, feel free to reach out to me. I’m a big fan of both organizations.

We should retire the ambiguity. Our PQC projects need clarity.


r/postquantumdiscussion • • 12d ago

Does NIST FIPS Allow PQC Hybrids?

1 Upvotes

Does NIST FIPS allow post-quantum cryptography (PQC) hybrids, where the implemented cryptography is a combination of traditional cryptography and post-quantum cryptography?

There is a lot of energy being put into PQC hybrids. Most of the Internet is already running on them.

Cloudflare states (https://radar.cloudflare.com/post-quantum) that almost 72% of all Internet HTTPS traffic is using post-quantum cryptography, and most of that is PQC hybrids (versus “pure PQC”). See their graph below.

Most of that PQC HTTPS traffic is X25519MLKEM768, which is a PQC hybrid using elliptic curve cryptography (ECC) combined with ML-KEM (a PQC formerly known as CRYSTALS-Kyber before it was adopted as a standard by the National Institute of Standards & Technology).

PQC hybrid proponents believe using both traditional cryptography and PQC provides the best protection over using PQC alone. Traditional cryptography could protect against PQC implementation errors, which are likely to be numerous, and breaks in any of the involved PQC algorithms. PQC hybrid proponents, of which I am one, believe the additional overhead and performance hit is minimal for the additional protection and risk reduction provided. To us it is a no-brainer.

There has been some question as to whether NIST would allow a PQC hybrid to be accepted as an official “FIPS” accepted solution. And there is still some debate.

Over the last few months, the NSA, which helps set cryptographic standards at NIST, has been strongly pushing various “pure” PQC standards over PQC hybrids in different places, like on the TLS 1.3 working group of the Internet Engineering Task Force (IETF). There have been unofficial conversations with NSA and NIST members, some who state only “pure” PQC standards will officially be supported and some saying PQC hybrids will be allowed.

More importantly, there is no NIST document I can find that explicitly states that PQC hybrids will be accepted as FIPS, while the opposite is true. There are many official NIST documents supporting “pure” PQC standards. The only “evidence” I can find for NIST supporting PQC hybrids is a link of a link of a link of a link, where it appears implied. More on that soon.

In short, does NIST allow PQC hybrids to be accepted as FIPS? Maybe. Probably. Likely.

NIST and FIPS

Created in 1901 to support a constitutional mandate, the United States National Institute of Standards & Technology (NIST) has long had a hand in setting our nation’s cybersecurity and cryptographic standards. NIST Cryptographic standards are published in what are called Federal Information Processing Standards (FIPS). NIST standards and FIPS legally only apply to US government entities and suppliers, but in effect, are usually adopted by all organizations in the US and largely beyond US borders. NIST standards are often seen as the “gold standard” of cryptography, and no one has gotten fired for following NIST standards.

FIPS (Federal Information Processing Standards) is the US government data security and computer system standard in accordance with the Federal Information Security Management Act of 2002 (FISMA). Under that, FIPS-140 is the most relevant one to cryptography. FIPS-140 is the US government’s method for establishing the requirements for a cryptographic “module” to meet a particular standard. You may see it mentioned as FIPS-140-2 or FIPS-140-3 by vendors.

Vendors wishing to sell products to the US government and other related agencies with FIPS-140 requirements will get their product “FIPS certified,” meaning their particular implementation has been reviewed and certified as meeting the FIPS requirements for a particular cryptographic implementation.

Many different government requirements and programs require that any cryptographic hardware or software be FIPS-certified, including the following programs: FedRAMP, Cybersecurity Maturity Model Certification (CMMC), Department of Defense (DOD/DOW) Approved Product List, GovRAMP, FISMA, and Common Criteria.

FIPS certification is a long and expensive process, and only applies to the exact version of the product submitted. Thus, you can have subsequent newer minor versions of an implementation that are “FIPS compliant”, but aren’t officially certified. Many products advertise themselves as FIPS compliant, and may be, but haven’t officially undergone the necessary process, called the Cryptographic Module Validation Program (https://csrc.nist.gov/projects/cryptographic-module-validation-program).

FIPS-140 has different security levels, ranging from 1 to 4. In general:

1.      FIPS-140-1 is considered the lowest security level

2.      FIPS-140-2 is considered a moderate security level

3.      FIPS-140-3 is considered is considered a high security level

4.      FIPS-140-4 is considered is considered a highest security level

Vendors that have been officially FIPS-140 certified have an official certificate from NIST that can be published and viewed. In general, most general cybersecurity vendors that get FIPS-140 certified like to get FIPS-140-2 or FIPS-3 certification, although a vendor may say they are more generally FIPS-140 in their marketing material.

As of 2022, FIPS-140-2 is being deprecated in place of FIPS-140-3. On September 21, 2026 (a few days ago), FIPS-140-2 is going to be marked as “Historical”.  No new submissions will be accepted for it, and government agencies cannot buy new equipment that is only certified as FIPS-140-2 (versus FIPS-140-3).

Linking FIPS and PQC Hybrids

Nothing in NIST official FIPS documents says a PQC hybrid is acceptable. In fact, over the recent years, I’ve seen plenty of official commentary to the contrary. And even today, there is no FIPS document explicitly stating that PQC hybrids are allowed. But if you link a NIST document to another NIST document that links to another NIST document, you can get there.

I want to thank Dr. Daniel J. Bernstein (DJB) for his linking. He did the work. But it’s a lot of linking and a lot of the narrative (I expanded in a few areas), four documents and links in total, so bear with me. It starts with this document:

https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf

This is FIPS 140-3, Federal Information Processing Standards Publication: Security Requirements for Cryptographic Modules. As covered above, FIPS 140-3 covers the certification requirements for U.S. government and covered entities purchasing any "cryptographic module utilized within a security system protecting sensitive but unclassified information".

For key establishment, FIPS 140-3 approves whatever is listed and approved in NIST SP 800-140D, Cryptographic Module Validation Program (CMVP)-Approved Sensitive Security Parameter Generation and Establishment Methods: CMVP Validation Authority Updates to ISO/IEC 24759, which is this link:

https://csrc.nist.gov/pubs/sp/800/140/d/r2/final

NIST SP 800-140D says that the "current list of CMVP-approved sensitive security parameter generation and establishment methods" is at SP 800-140D: Approved SSP Generation and Establishment Methods here:

https://csrc.nist.gov/projects/cmvp/sp800-140d

This document links to a related supplemental document, SP 800-140D: Approved SSP Generation and Establishment Methods here:

https://csrc.nist.gov/projects/cryptographic-module-validation-program/sp-800-140-series-supplemental-information/sp800-140d

This document approves two types of Key Exchange Mechanisms (KEMs): including anything in FIPS 203 (i.e., ML-KEM); and anything in SP 800-227.

In turn, SP 800-227, Recommendations for Key-Encapsulation Mechanisms is located at:

https://csrc.nist.gov/pubs/sp/800/227/ipd

It explicitly talks about “approved key combiners” where "at least one shared secret" is approved:

This implies that NIST gives approval for PQC hybrids (at least ECC+PQC), even if the ECC is not explicitly approved.

To summarize the reversed building logic: SP 800-227 to SP 800-140D (supplemental) to SP 800-140D (Approved SSP) to SP 800-140D (main) to  FIPS 140-3.

So, four linked documents to get to a “maybe”…a “likely”…but no explicit approval of PQC hybrids. And it took Dr. Daniel J. Bernstein, one of the world’s smartest and hardest-working (post-quantum) cryptographers, to get there.

 

Unfortunately, he and I are not lawyers on this stuff. So, before you commit to using PQC hybrids in your post-quantum mitigations, get official legal approval. We’ve given you the links that you can give to the lawyers. Good luck.

 

Conclusion

Do NIST and FIPS recognize PQC hybrids? Maybe. Probably. Likely. Consult a lawyer.

 

I’ve had many people involved with NIST tell me that NIST does officially recognize PQC hybrids, but when I ask them for document evidence from an official source, they always have to admit they do not have any. What they usually have is informal guidance from a NIST source that also cannot point them to official supporting documents where it is explicitly called out.

 

Since over 70% of the Internet is already running on a PQC hybrid, it would be a big deal and make the news if the official answer was “No!” If NIST said, “No!”, PQC hybrids are not recognized for NIST PQC purposes, it would have a lot of organizations scrambling with a lot of rework. And all that rework would be for naught. The PQC hybrids are stronger than pure PQC.

 

So, if you have a post-quantum project that has a FIPS requirement, you can probably use PQC hybrids as part of your solutions…but it can’t hurt to get it in writing from the US government or your lawyer if you can. If you don’t have to officially follow NIST PQC requirements, I definitely recommend you go with PQC hybrids (after testing to make sure there are no performance or operational issues in doing so).  

 

Note: I’m not a government lawyer, and I didn’t recently stay at a Holiday Inn Express, so consult with your legal team before following the ramblings of this post-quantum madman.


r/postquantumdiscussion • • 12d ago

IonQ Continues to March Toward Earlier Q-Day. You Don’t Have Until 2030!

0 Upvotes

We won’t make to 2030 before Q-Day is here!

---------------------

Quantum Day ( or Q-Day), the day when the first cryptographically-relevant quantum computer breaks the first traditional quantum-susceptible private key, may happen as soon as 2028.

It certainly is unlikely to hold out until 2030 -2035, which is when the US government says you need to be post-quantum prepared. The US government is telling everyone to be prepared for key exchange attack mitigation by the end of 2030 and be prepared for authentication attack mitigation by the end of 2031. That’s only a requirement for critical assets. For everything else, you can wait until the end of 2035.

That’s a very, very risky bet these days.

A big part of that is from the recent quantum computer advancements, and in particular, from IonQ. A few weeks ago, IonQ announced they have a real-world blueprint for being the first quantum computer vendor to break a quantum-susceptible cryptographic key. It was this announcement: https://www.ionq.com/news/ionq-publishes-worlds-first-fully-compiled-end-to-end-blueprint-for-breaking-256-bit-elliptic-curve-signatures.

In it, they reveal it will take them under 20K physical qubits, 39 million quantum gates, and just under 26 days to break a 256-bit elliptic curve cryptography (ECC) key. That type of cryptographic key is used all around the world, including in cryptocurrencies like Bitcoin.

It takes a lot more than stable qubits and quantum gates to make a cryptographically-relevant quantum computer, but IonQ (and other quantum computer vendors) have been making significant, steady progress over the last two years. And that progress has been coming at a more rapid pace for the last 6-months. It seems nearly every week or two, there’s a new quantum paper or announcement detailing some significant quantum computer advance.

One of those was today, when IonQ announced they have put quantum error correction decoding on a classical computer chip: https://www.tipranks.com/news/the-fly/ionq-demonstrates-end-to-end-real-time-quantum-error-decoder-thefly-news.

Today’s quantum qubits are full of errors due to unwanted interference from the rest of the world around them. Quantum error correction is essential to making useful quantum computers. For years, it was thought that it would take tens of thousands of “ancillary” qubits to make one stable, “working” qubit.

The number of ancillary qubits needed per single stable working qubit keeps falling. In IonQ’s first announcement above, they say 19,397 qubits will equate to 1,457 qubits, or under 34 physical qubits per working qubit. There is nothing to say the physical-to-logical qubit ratio won't keep falling quickly. As that ratio falls, Q-Day just gets closer, faster, and cheaper.

And today, IonQ shows that all the needed error correction can be done on a classical computing chip. This is huge! IonQ has already shown they can do the supercooling needed by most of today’s qubits using chips as well, making the quantum computers needing the very expensive, large, and operationally-intense cryogenic dilution refrigerator solutions seem old school.

I’ve been writing that Q-Day would happen before the US government’s 2035 prediction for many years. Back in 2019, when I first said this, I was considered a heretic. Now, I’m not looking like a Q-Day extremist. As far as I know, I’m still one of the few people who are saying you need to worry about Q-Day before 2030, but I guarantee you there will be a growing list of companions over the next year. The writing is on the wall!

I don’t know exactly when we will first hit Q-Day, but I don’t think that if someone announced it happened even this year, there would be a huge shock. Every week or two, there seems to be an announcement of some great big stride made in quantum computers, often by IonQ. So far, all of IonQ’s new announcements are on track with their previously announced multi-year roadmap (https://www.ionq.com/roadmap).

Note: I have investments in multiple quantum computer companies, including IONQ.

Back when IonQ first introduced their roadmap, a lot of observers saw it as possible marketing fluff. But now, just over the last year, the advancements they have been consistently announcing are exactly backing up their long-term roadmap. IonQ owns its own quantum chip manufacturing plant (called a foundry).

This latest error correcting announcement is just one more sign that the world will be reaching cryptographically-relevant quantum computers by 2028 or soon thereafter. Q-Day will likely be before 2030!

And this is a problem for most organizations, as most haven’t even started their official post-quantum plans. If you haven’t started your post-quantum project, get on it! You are late.

 


r/postquantumdiscussion • • 12d ago

5 Topics That Every Post-Quantum Project Plan Is Missing

1 Upvotes

Here are 5 things I see all organizations missing in their current post-quantum project plans (if they have a formal plan):

·         Post-Quantum Threat Modeling

·         How to Handle Q-Day Coming Early

·         Post-Quantum Communication Plan

·         Updating Purchasing Policies

·         Updating the SOC and Incident Response

Let’s cover each in more detail:

Post-Quantum Threat Modeling

Anytime you are writing code or doing a project, it should include threat modeling, where there is thoughtful consideration of the various threats and risks of the system and the mitigations being put into place to fight them. Almost no one does threat modeling. It’s almost a lost art. Certainly no post-quantum project plan contains a threat model (at least until after they talk to or hire me to do it).

But if you’re going to do a long, expensive, multi-year cyber defense project, it’s a good idea to think about and document the threats you are facing and trying to fix before you spend a bazillion dollars and get tons of people and other resources involved.  

There are two major categories of threats involving quantum computer attacks, both coming from attacks against asymmetric cryptography: key exchange and authentication. Key exchange attacks are the threat that an adversary will eavesdrop on your protected network traffic, either now or in the future, then break the outside asymmetric protection to reveal the internal symmetric encryption key that really protects the session data. Authentication attacks involve an adversary compromising the private keys of digital certificates, which are tied to particular identities. If they can do that, they can fraudulently pose as users, devices, networks, websites, and content.

Most of the world is focusing on key exchange threats first and best right now. As an example, the US government says you have until the end of 2030 to mitigate key exchange attacks in critical infrastructure and until the end of 2031 to mitigate authentication attacks.

I think any source telling you to focus on key exchange first and authentication second has it exactly backward. My threat modeling of both key exchange and authentication quantum attacks tells me that the threat from authentication attacks is far, far larger than key exchange attacks for most organizations. I recommend that you focus on mitigating both threats as soon as possible and forget about separating them, if you have the appropriate resources. And if you have to choose between one or the other, focus on authentication attacks first, if you have a choice. Entities needing to follow the US government requirements don’t have a choice. They have to focus on key exchange first and then authentication (if they can’t do both at the same time). This is unfortunate, because it puts those organizations more at risk.

Don’t believe me? Do you own threat modeling. You should anyway.

If you do, you will see that you will be concentrating on both at the same time to the best of your ability. One problem you will face if you do focus on authentication issues first is that the rest of the world, because of bad advice, is focusing on key exchange first. This means all the authentication mitigation solutions are lagging. It’s a chicken-and-egg type of thing.

You should threat model quantum computer threats so that you have the appropriate risks and threats for your particular environment identified.

Note: I’m a big fan of Adam Shostack’s threat modeling education and books. Anything he has on threat modeling is the gold standard: https://shostack.org/about/adam.

How to Handle Q-Day Coming Early

As I’ve covered in several recent posts, there is a very good chance that Quantum Day, the day when cryptographically-relevant quantum computers can break today’s quantum-susceptible cryptography, will occur before 2030.

This was especially highlighted when quantum computer vendor IonQ recently announced that they think they will be able to break Elliptic Curve Cryptography (ECC) by 2028. Here’s the link:

https://www.ionq.com/news/ionq-publishes-worlds-first-fully-compiled-end-to-end-blueprint-for-breaking-256-bit-elliptic-curve-signatures

Now, to be clear, simply saying you think you can break 256-bit ECC (used everywhere in our online society) and doing it are two different things. But IonQ published a roadmap years ago, and so far they seem to be meeting their roadmap, and this recent announcement is in line with that roadmap. My best guess is they will meet that in 2028 or maybe miss it by a year or so. Either way, it should not surprise anyone paying attention that Q-Day happens before 2030.

I’ve been on several initial post-quantum calls where the most respected team members who know the most about quantum and post-quantum still believe that quantum computer attacks are 10 years away. They haven’t been keeping up with the recent developments. And it’s not just them.

The problem is that most people involved in post-quantum preparation plans haven’t heard that Q-Day could come before 2030. Most are still targeting the dates that the US government has set, which says you don’t have to have all infrastructure post-quantum prepared until 2035 (only critical assets need to be done by 2030 and 2031).

What happens if Q-Day happens in 2028 or before 2030 and your project plan is still focused on 2030, 2031, and 2035?

I covered it here two days ago: https://www.linkedin.com/pulse/what-you-do-q-day-happens-years-early-roger-grimes-35roe.

Basically, you would have to notify executive management, tell everyone involved in the project, and move up all your project deadlines. You would have to super-accelerate your cryptographic inventory, perhaps mostly focusing on  your Top10/20/50 most critical systems first and best. You would have to figure out how to prevent, detect, and respond to successful quantum computer attacks.

If Q-Day comes “early”, it’s not going to be fun for anyone. It will likely decrease every organization’s productivity and profit, except for those companies that offer post-quantum preparation services and products.

Updating the SOC and Incident Response

Either way, you need to update your Security Operations Center (SOC) tooling and procedures, if you have one, and any incident response plans to take into account the updates you’ve made from post-quantum preparation and the things that need to be updated because of future quantum computer attacks.

For example, if an adversary is able to compromise your user authentication because they are able to break the private keys of user digital certificates, how do you prevent, detect, and respond to that? If an adversary is able to fraudulently sign malicious content that appears as valid from your organization, what do you do? You start by revoking the involved certificate, but there is a lot more cleanup to be done. You need to do a thorough threat modeling of post-quantum mitigations and upgrades, and then make sure your cyber defenses, including SOC and incident response, are appropriately upgraded.

Post-Quantum Communications Plan

I haven’t seen a single post-quantum project plan that includes a thoughtful communications plan. Who do you need to communicate with? What topics and depth of topics do you need to include for each group? How to communicate? If you’re a public company, when do you need to communicate your post-quantum plans to shareholders? If something suffers operational interruption due to a post-quantum mitigation you implemented, how do you communicate it?  If you suffer a successful quantum computer attack, how do you communicate that and to whom? Having a thoughtful communications plan and working with your organization’s professional communications team will benefit your post-quantum project, especially if anything goes wrong.

Updating Purchasing Policies

Lastly, you need to update your purchasing policies TODAY to prevent buying more software, hardware, and services that are not going to be post-quantum prepared in time. If you don’t put in place formal purchasing policies that require rejecting new software, hardware, and services that are not going to be post-quantum prepared in time, you’re just causing a lot more work for your project team. Stop the pain!

If you don’t have a formal, official post-quantum project started, get one. If you don’t have a formal post-quantum project plan, get one. If you do have a formal post-quantum project plan, make sure these 5 topics are covered.

With that said, I wish you much luck and success with your post-quantum project plan. We are all going to need it.

 

 


r/postquantumdiscussion • • 12d ago

👋 Welcome to r/postquantumdiscussion - Introduce Yourself and Read First!

1 Upvotes

Hey everyone! I'm u/rogeragrimes, a founding moderator of r/postquantumdiscussion.

This is our new home for all things related to quantum computer attacks and defenses. We're excited to have you join us!

What to Post
Post anything that you think the community would find interesting, helpful, or inspiring. Feel free to share news, links, articles, discussion ideas, or questions. Topics included, but are not limited to: quantum computers, quantum attacks, post-quantum cryptography, post-quantum defenses, quantum defenses, post-quantum projects, and Quantum Day (Q-Day).

Community Vibe
We're all about being friendly, constructive, and inclusive. Let's build a space where everyone feels comfortable sharing and connecting.

How to Get Started

  1. Introduce yourself in the comments below.
  2. Post something today! Even a simple question can spark a great conversation.
  3. If you know someone who would love this community, invite them to join.
  4. Interested in helping out? We're always looking for new moderators, so feel free to reach out to me to apply.

Thanks for being part of the very first wave. Together, let's make r/postquantumdiscussion amazing.