#postquantum — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #postquantum, aggregated by home.social.
-
BTQ Technologies Signs MOU with ITCENGLOBAL, a KRW 8.9 Trillion Korean IT Group, to Advance Post-Quantum Security Across Korea’s Financial, Public-Sector, and Enterprise Infrastructure https://www.byteseu.com/2271594/ #BiometricAuthentication #BTQ #DigitalIdentity #EnterpriseCustomers #FinancialInstitutions #ITCENPNS #Korea #KOSDAQ #PostQuantum #PublicSector #SecurityPlatform #Technology
-
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
Sí señor!
Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!
Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!
Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu
Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)
-
Sí señor!
Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!
Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!
Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu
Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)
-
Sí señor!
Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!
Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!
Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu
Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)
-
Sí señor!
Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!
Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!
Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu
Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)
-
La FINMA tire la sonnette d'alarme : la majorité des banques suisses n'ont pas de plan de migration post-quantique. Ce n'est pas un problème futur — les attaques "harvest now, decrypt later" collectent déjà des données chiffrées aujourd'hui. La fenêtre de préparation est là. Elle ne le restera pas. #infosec #PostQuantum #cryptographie
https://dcod.ch/2026/08/06/finma-banques-suisse-plan-quantique/ -
Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.
Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.
Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.
But this is the third event this summer hitting PQC from a different angle.
Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.
Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.
And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.
Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.
If the lesson were just "lattice math is fragile," one event would suffice.
The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.
SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.
Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:
https://postquantum.com/security-pqc/simon-quantum-algorithm-lattice-pqc/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility
-
Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.
Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.
Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.
But this is the third event this summer hitting PQC from a different angle.
Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.
Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.
And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.
Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.
If the lesson were just "lattice math is fragile," one event would suffice.
The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.
SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.
Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:
https://postquantum.com/security-pqc/simon-quantum-algorithm-lattice-pqc/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility
-
Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.
Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.
Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.
But this is the third event this summer hitting PQC from a different angle.
Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.
Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.
And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.
Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.
If the lesson were just "lattice math is fragile," one event would suffice.
The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.
SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.
Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:
https://postquantum.com/security-pqc/simon-quantum-algorithm-lattice-pqc/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility
-
Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.
Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.
Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.
But this is the third event this summer hitting PQC from a different angle.
Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.
Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.
And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.
Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.
If the lesson were just "lattice math is fragile," one event would suffice.
The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.
SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.
Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:
https://postquantum.com/security-pqc/simon-quantum-algorithm-lattice-pqc/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility
-
Uh-oh... https://eprint.iacr.org/2026/1591
Potentially worrying. Has anyone looked into it already?
#cryptography #pqc #crypto #quantum #quantsec #postquantum #lattice
-
Uh-oh... https://eprint.iacr.org/2026/1591
Potentially worrying. Has anyone looked into it already?
#cryptography #pqc #crypto #quantum #quantsec #postquantum #lattice
-
Uh-oh... https://eprint.iacr.org/2026/1591
Potentially worrying. Has anyone looked into it already?
#cryptography #pqc #crypto #quantum #quantsec #postquantum #lattice
-
Uh-oh... https://eprint.iacr.org/2026/1591
Potentially worrying. Has anyone looked into it already?
#cryptography #pqc #crypto #quantum #quantsec #postquantum #lattice
-
Uh-oh... https://eprint.iacr.org/2026/1591
Potentially worrying. Has anyone looked into it already?
#cryptography #pqc #crypto #quantum #quantsec #postquantum #lattice
-
Breaking Bitcoin's ECDSA in an hour needs roughly 317 million physical qubits. Today's best quantum machine runs around 100.
Meanwhile in 2025, crypto lost $3.4 billion to theft. Social engineering: 55%. Bridge exploits and insider access: most of the rest. Quantum attacks: zero dollars.
Post-quantum work is necessary long-term engineering. It's also step 10 on a security checklist where steps 1-5 remain undone.
https://roamingpigs.com/field-manual/quantum-crypto-threat-overblown/
-
Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.
https://postquantum.com/security-pqc/mas-quantum-resilience-supervisory-expectations/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore
-
Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.
https://postquantum.com/security-pqc/mas-quantum-resilience-supervisory-expectations/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore
-
Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.
https://postquantum.com/security-pqc/mas-quantum-resilience-supervisory-expectations/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore
-
Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.
https://postquantum.com/security-pqc/mas-quantum-resilience-supervisory-expectations/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore
-
Our August online training schedule:
1. Remaining Anonymous — free for Subscribers and Subscribers PRO
2. Post-Quantum — free for Subscribers PRO
#cybersecurity #infosec #postquantum #quantum #anonymous -
Our August online training schedule:
1. Remaining Anonymous — free for Subscribers and Subscribers PRO
2. Post-Quantum — free for Subscribers PRO
#cybersecurity #infosec #postquantum #quantum #anonymous -
Our August online training schedule:
1. Remaining Anonymous — free for Subscribers and Subscribers PRO
2. Post-Quantum — free for Subscribers PRO
#cybersecurity #infosec #postquantum #quantum #anonymous -
For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.
TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.
The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.
TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.
Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.
My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:
https://postquantum.com/security-pqc/trustasia-mtc-chrome-test-root/
#infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum
-
For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.
TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.
The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.
TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.
Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.
My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:
https://postquantum.com/security-pqc/trustasia-mtc-chrome-test-root/
#infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum
-
For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.
TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.
The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.
TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.
Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.
My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:
https://postquantum.com/security-pqc/trustasia-mtc-chrome-test-root/
#infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum
-
For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.
TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.
The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.
TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.
Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.
My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:
https://postquantum.com/security-pqc/trustasia-mtc-chrome-test-root/
#infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.
Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.
Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.
https://postquantum.com/industry-news/wef-top-10-emerging-technologies-2026-pqc-quantum/
#infosec #PQC #postquantum #cryptography #NIST #cybersecurity
-
IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.
UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.
IBM packaged three evidence levels as one.
https://postquantum.com/industry-news/ibm-three-quantum-advantage-papers/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM
-
IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.
UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.
IBM packaged three evidence levels as one.
https://postquantum.com/industry-news/ibm-three-quantum-advantage-papers/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM
-
IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.
UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.
IBM packaged three evidence levels as one.
https://postquantum.com/industry-news/ibm-three-quantum-advantage-papers/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM
-
IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.
UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.
IBM packaged three evidence levels as one.
https://postquantum.com/industry-news/ibm-three-quantum-advantage-papers/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM
-
A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).
The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.
Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.
The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.
For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.
The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.
Full analysis: https://postquantum.com/industry-news/universal-topological-gates-anyons/
#quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological
-
A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).
The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.
Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.
The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.
For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.
The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.
Full analysis: https://postquantum.com/industry-news/universal-topological-gates-anyons/
#quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological
-
A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).
The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.
Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.
The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.
For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.
The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.
Full analysis: https://postquantum.com/industry-news/universal-topological-gates-anyons/
#quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological
-
A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).
The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.
Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.
The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.
For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.
The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.
Full analysis: https://postquantum.com/industry-news/universal-topological-gates-anyons/
#quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological
-
A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).
The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.
Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.
The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.
For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.
The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.
Full analysis: https://postquantum.com/industry-news/universal-topological-gates-anyons/
#quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological
-
DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.
Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.
Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.
https://postquantum.com/security-pqc/digicert-quantum-readiness-outlook-2026/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography
-
DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.
Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.
Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.
https://postquantum.com/security-pqc/digicert-quantum-readiness-outlook-2026/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography
-
DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.
Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.
Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.
https://postquantum.com/security-pqc/digicert-quantum-readiness-outlook-2026/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography
-
DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.
Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.
Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.
https://postquantum.com/security-pqc/digicert-quantum-readiness-outlook-2026/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography
-
HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.
The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.
The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.
FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.
What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.
Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.
Full analysis: https://postquantum.com/security-pqc/hkma-banks-quantum-readiness-2-3/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA
-
HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.
The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.
The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.
FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.
What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.
Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.
Full analysis: https://postquantum.com/security-pqc/hkma-banks-quantum-readiness-2-3/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA
-
HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.
The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.
The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.
FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.
What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.
Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.
Full analysis: https://postquantum.com/security-pqc/hkma-banks-quantum-readiness-2-3/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA
-
HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.
The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.
The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.
FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.
What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.
Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.
Full analysis: https://postquantum.com/security-pqc/hkma-banks-quantum-readiness-2-3/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA
-
HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.
The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.
The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.
FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.
What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.
Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.
Full analysis: https://postquantum.com/security-pqc/hkma-banks-quantum-readiness-2-3/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA
-
Best quantum computing meta-analysis of the year: Jurczak's PFYT framework explains why quantum engineering horizons keep resetting. Backed by Riverlane QEC data and OpenAlex bibliometrics.
Where it breaks: conflating unsettled architecture with undefined targets. For CRQC and simulation workloads, the acceptance test is concrete.
https://postquantum.com/quantum-computing/perpetual-five-year-quantum-computers-pfyt/
-
Best quantum computing meta-analysis of the year: Jurczak's PFYT framework explains why quantum engineering horizons keep resetting. Backed by Riverlane QEC data and OpenAlex bibliometrics.
Where it breaks: conflating unsettled architecture with undefined targets. For CRQC and simulation workloads, the acceptance test is concrete.
https://postquantum.com/quantum-computing/perpetual-five-year-quantum-computers-pfyt/
-
Best quantum computing meta-analysis of the year: Jurczak's PFYT framework explains why quantum engineering horizons keep resetting. Backed by Riverlane QEC data and OpenAlex bibliometrics.
Where it breaks: conflating unsettled architecture with undefined targets. For CRQC and simulation workloads, the acceptance test is concrete.
https://postquantum.com/quantum-computing/perpetual-five-year-quantum-computers-pfyt/
-
I updated https://arewequantumyet.taffer.ca to include a link to IBM's new Quantum Advantage Tracker page.
Helpful 🤞 if you want to know whether to panic about classical private-key encryption being broken!
-
I updated https://arewequantumyet.taffer.ca to include a link to IBM's new Quantum Advantage Tracker page.
Helpful 🤞 if you want to know whether to panic about classical private-key encryption being broken!
-
I updated https://arewequantumyet.taffer.ca to include a link to IBM's new Quantum Advantage Tracker page.
Helpful 🤞 if you want to know whether to panic about classical private-key encryption being broken!
-
I updated https://arewequantumyet.taffer.ca to include a link to IBM's new Quantum Advantage Tracker page.
Helpful 🤞 if you want to know whether to panic about classical private-key encryption being broken!