home.social

#pqc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.

fetched live
  1. 📰 US Treasury Forms Task Force to Guard Finance Sector from Quantum Threats

    The U.S. Treasury has launched a Quantum-Readiness Task Force to help the financial sector transition to post-quantum cryptography (PQC) and defend against future quantum computing threats. #Quantum #PQC #Cybersecurity #Finance #Treasury

    🔗 cyber.netsecops.io/articles/us

  2. 📰 US Treasury Forms Task Force to Guard Finance Sector from Quantum Threats

    The U.S. Treasury has launched a Quantum-Readiness Task Force to help the financial sector transition to post-quantum cryptography (PQC) and defend against future quantum computing threats. #Quantum #PQC #Cybersecurity #Finance #Treasury

    🔗 cyber.netsecops.io/articles/us

  3. 📰 US Treasury Forms Task Force to Guard Finance Sector from Quantum Threats

    The U.S. Treasury has launched a Quantum-Readiness Task Force to help the financial sector transition to post-quantum cryptography (PQC) and defend against future quantum computing threats. #Quantum #PQC #Cybersecurity #Finance #Treasury

    🔗 cyber.netsecops.io/articles/us

  4. 📰 US Treasury Forms Task Force to Guard Finance Sector from Quantum Threats

    The U.S. Treasury has launched a Quantum-Readiness Task Force to help the financial sector transition to post-quantum cryptography (PQC) and defend against future quantum computing threats. #Quantum #PQC #Cybersecurity #Finance #Treasury

    🔗 cyber.netsecops.io/articles/us

  5. @bortzmeyer @shaft y'a déjà un numéro d'algo en tout cas (18) dans le registre de l'IANA.

    #dnssec #pqc

  6. @bortzmeyer @shaft y'a déjà un numéro d'algo en tout cas (18) dans le registre de l'IANA.

    #dnssec #pqc

  7. @bortzmeyer @shaft y'a déjà un numéro d'algo en tout cas (18) dans le registre de l'IANA.

    #dnssec #pqc

  8. @bortzmeyer @shaft y'a déjà un numéro d'algo en tout cas (18) dans le registre de l'IANA.

    #dnssec #pqc

  9. @bortzmeyer @shaft y'a déjà un numéro d'algo en tout cas (18) dans le registre de l'IANA.

    #dnssec #pqc

  10. @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

    #DNS #DNSSEC #PQC

  11. @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

    #DNS #DNSSEC #PQC

  12. @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

    #DNS #DNSSEC #PQC

  13. @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

    #DNS #DNSSEC #PQC

  14. @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

    #DNS #DNSSEC #PQC

  15. I released v1.7.1 of gonemaster that now can verify ML-DSA-44. Based on miekg/dns that also released support for it today. #DNS #dnssec #pqc

  16. I released v1.7.1 of gonemaster that now can verify ML-DSA-44. Based on miekg/dns that also released support for it today. #DNS #dnssec #pqc

  17. I released v1.7.1 of gonemaster that now can verify ML-DSA-44. Based on miekg/dns that also released support for it today. #DNS #dnssec #pqc

  18. I released v1.7.1 of gonemaster that now can verify ML-DSA-44. Based on miekg/dns that also released support for it today. #DNS #dnssec #pqc

  19. I released v1.7.1 of gonemaster that now can verify ML-DSA-44. Based on miekg/dns that also released support for it today. #DNS #dnssec #pqc

  20. 📰 Bipartisan 'Quantum-GUARD Act' Introduced to Protect US Electric Grid

    US Senators introduce the bipartisan Quantum-GUARD Act to protect the nation's electric grid from quantum computing threats. The bill directs the DOE and FERC to prepare for the transition to post-quantum cryptography. #QuantumComputing #PQC #Cyberse...

    🔗 cyber.netsecops.io/articles/us

  21. Registration is now open for the Post-Quantum Cryptography: State of the Art workshop, taking place in Bonn on 6 October 2026.

    This one-day training will provide an overview of the current state of post-quantum cryptography, with practical insights into NIST standards, cryptographic libraries and migration strategies.

    The workshop is co-located with ETSI’s CRA Standards Unlocked Event.

    esat.kuleuven.be/cosic/events/

    #PQC #PostQuantumCryptography #QuantumSafe

  22. Registration is now open for the Post-Quantum Cryptography: State of the Art workshop, taking place in Bonn on 6 October 2026.

    This one-day training will provide an overview of the current state of post-quantum cryptography, with practical insights into NIST standards, cryptographic libraries and migration strategies.

    The workshop is co-located with ETSI’s CRA Standards Unlocked Event.

    esat.kuleuven.be/cosic/events/

    #PQC #PostQuantumCryptography #QuantumSafe

  23. Registration is now open for the Post-Quantum Cryptography: State of the Art workshop, taking place in Bonn on 6 October 2026.

    This one-day training will provide an overview of the current state of post-quantum cryptography, with practical insights into NIST standards, cryptographic libraries and migration strategies.

    The workshop is co-located with ETSI’s CRA Standards Unlocked Event.

    esat.kuleuven.be/cosic/events/

    #PQC #PostQuantumCryptography #QuantumSafe

  24. Registration is now open for the Post-Quantum Cryptography: State of the Art workshop, taking place in Bonn on 6 October 2026.

    This one-day training will provide an overview of the current state of post-quantum cryptography, with practical insights into NIST standards, cryptographic libraries and migration strategies.

    The workshop is co-located with ETSI’s CRA Standards Unlocked Event.

    esat.kuleuven.be/cosic/events/

    #PQC #PostQuantumCryptography #QuantumSafe

  25. It is often said in quantum security discussions that Grover's algorithm attacks symmetric-key cryptography by halving the effective keysize of symmetric ciphers, or halving the length of hashes in terms of security. This claim is wrong, but it's so rooted in common discourse that it has become extremely difficult to disentangle from reality. Details:

    gagliardoni.net/#20260820_grov

    AES-128 and 256-bit hashes are totally fine against quantum attacks. Here is a quick smell test to evaluate the maturity of your commercial quantum migration / CBOM scanner solution: does it flag AES-128 as a risk finding? If so, the vendor is not well-informed about quantum risk.

    #cryptography #pqc #quantum #crypto #security #infosec #quantumsecurity

  26. It is often said in quantum security discussions that Grover's algorithm attacks symmetric-key cryptography by halving the effective keysize of symmetric ciphers, or halving the length of hashes in terms of security. This claim is wrong, but it's so rooted in common discourse that it has become extremely difficult to disentangle from reality. Details:

    gagliardoni.net/#20260820_grov

    AES-128 and 256-bit hashes are totally fine against quantum attacks. Here is a quick smell test to evaluate the maturity of your commercial quantum migration / CBOM scanner solution: does it flag AES-128 as a risk finding? If so, the vendor is not well-informed about quantum risk.

    #cryptography #pqc #quantum #crypto #security #infosec #quantumsecurity

  27. It is often said in quantum security discussions that Grover's algorithm attacks symmetric-key cryptography by halving the effective keysize of symmetric ciphers, or halving the length of hashes in terms of security. This claim is wrong, but it's so rooted in common discourse that it has become extremely difficult to disentangle from reality. Details:

    gagliardoni.net/#20260820_grov

    AES-128 and 256-bit hashes are totally fine against quantum attacks. Here is a quick smell test to evaluate the maturity of your commercial quantum migration / CBOM scanner solution: does it flag AES-128 as a risk finding? If so, the vendor is not well-informed about quantum risk.

    #cryptography #pqc #quantum #crypto #security #infosec #quantumsecurity

  28. It is often said in quantum security discussions that Grover's algorithm attacks symmetric-key cryptography by halving the effective keysize of symmetric ciphers, or halving the length of hashes in terms of security. This claim is wrong, but it's so rooted in common discourse that it has become extremely difficult to disentangle from reality. Details:

    gagliardoni.net/#20260820_grov

    AES-128 and 256-bit hashes are totally fine against quantum attacks. Here is a quick smell test to evaluate the maturity of your commercial quantum migration / CBOM scanner solution: does it flag AES-128 as a risk finding? If so, the vendor is not well-informed about quantum risk.

    #cryptography #pqc #quantum #crypto #security #infosec #quantumsecurity

  29. It is often said in quantum security discussions that Grover's algorithm attacks symmetric-key cryptography by halving the effective keysize of symmetric ciphers, or halving the length of hashes in terms of security. This claim is wrong, but it's so rooted in common discourse that it has become extremely difficult to disentangle from reality. Details:

    gagliardoni.net/#20260820_grov

    AES-128 and 256-bit hashes are totally fine against quantum attacks. Here is a quick smell test to evaluate the maturity of your commercial quantum migration / CBOM scanner solution: does it flag AES-128 as a risk finding? If so, the vendor is not well-informed about quantum risk.

    #cryptography #pqc #quantum #crypto #security #infosec #quantumsecurity

  30. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  31. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  32. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  33. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  34. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  35. I've used GSMA material in telco consulting for decades. And in my previous roles as telco CTO and CISO. So when the GSMA Foundry published a Quantum Computing Implementation Playbook for operators in July, I downloaded it the same day and expected to write a short, positive piece about it.

    Instead I spent three weeks deciding whether to take it apart in public, and then did.

    Here is the short version. Figure 2 stars telecom for highest near-term impact citing McKinsey. McKinsey puts it at lowest near-term value tier.

    Figure 14 is a vendor roadmap table with three consecutive rows labelled IBM. Row two describes Google's Willow and Quantum Echoes. Row three describes Rigetti's Ankaa-3.

    And so on.

    The security angle is footnote 7 on page 9, where PQC and the quantum threat go "not within the scope." GSMA Intelligence's own operator survey puts network security first among quantum priorities, ahead of network efficiency.

    On methodology, Section 5 is genuinely good, and it defines five evaluation dimensions, names scalability as the most informative signal in the NISQ era, and tells operators to benchmark against the strongest realistic classical alternative. Section 6 then presents four validated use cases and three of them without the classical alternative comparison.

    The document is vendor-contributed, vendor-evidenced, vendor-benchmarked, and commercially downstream of a 16-week programme the same vendor runs. That isn't the problem. The problem is the GSMA badge and the fact that operators will quote it in board papers because GSMA said so.

    Full review with page numbers for both PDFs, so you can check me. postquantum.com/quantum-comput

    #infosec #quantum #PQC #postquantum #telecom #cryptography #GSMA

  36. I've used GSMA material in telco consulting for decades. And in my previous roles as telco CTO and CISO. So when the GSMA Foundry published a Quantum Computing Implementation Playbook for operators in July, I downloaded it the same day and expected to write a short, positive piece about it.

    Instead I spent three weeks deciding whether to take it apart in public, and then did.

    Here is the short version. Figure 2 stars telecom for highest near-term impact citing McKinsey. McKinsey puts it at lowest near-term value tier.

    Figure 14 is a vendor roadmap table with three consecutive rows labelled IBM. Row two describes Google's Willow and Quantum Echoes. Row three describes Rigetti's Ankaa-3.

    And so on.

    The security angle is footnote 7 on page 9, where PQC and the quantum threat go "not within the scope." GSMA Intelligence's own operator survey puts network security first among quantum priorities, ahead of network efficiency.

    On methodology, Section 5 is genuinely good, and it defines five evaluation dimensions, names scalability as the most informative signal in the NISQ era, and tells operators to benchmark against the strongest realistic classical alternative. Section 6 then presents four validated use cases and three of them without the classical alternative comparison.

    The document is vendor-contributed, vendor-evidenced, vendor-benchmarked, and commercially downstream of a 16-week programme the same vendor runs. That isn't the problem. The problem is the GSMA badge and the fact that operators will quote it in board papers because GSMA said so.

    Full review with page numbers for both PDFs, so you can check me. postquantum.com/quantum-comput

    #infosec #quantum #PQC #postquantum #telecom #cryptography #GSMA

  37. I've used GSMA material in telco consulting for decades. And in my previous roles as telco CTO and CISO. So when the GSMA Foundry published a Quantum Computing Implementation Playbook for operators in July, I downloaded it the same day and expected to write a short, positive piece about it.

    Instead I spent three weeks deciding whether to take it apart in public, and then did.

    Here is the short version. Figure 2 stars telecom for highest near-term impact citing McKinsey. McKinsey puts it at lowest near-term value tier.

    Figure 14 is a vendor roadmap table with three consecutive rows labelled IBM. Row two describes Google's Willow and Quantum Echoes. Row three describes Rigetti's Ankaa-3.

    And so on.

    The security angle is footnote 7 on page 9, where PQC and the quantum threat go "not within the scope." GSMA Intelligence's own operator survey puts network security first among quantum priorities, ahead of network efficiency.

    On methodology, Section 5 is genuinely good, and it defines five evaluation dimensions, names scalability as the most informative signal in the NISQ era, and tells operators to benchmark against the strongest realistic classical alternative. Section 6 then presents four validated use cases and three of them without the classical alternative comparison.

    The document is vendor-contributed, vendor-evidenced, vendor-benchmarked, and commercially downstream of a 16-week programme the same vendor runs. That isn't the problem. The problem is the GSMA badge and the fact that operators will quote it in board papers because GSMA said so.

    Full review with page numbers for both PDFs, so you can check me. postquantum.com/quantum-comput

    #infosec #quantum #PQC #postquantum #telecom #cryptography #GSMA

  38. I've used GSMA material in telco consulting for decades. And in my previous roles as telco CTO and CISO. So when the GSMA Foundry published a Quantum Computing Implementation Playbook for operators in July, I downloaded it the same day and expected to write a short, positive piece about it.

    Instead I spent three weeks deciding whether to take it apart in public, and then did.

    Here is the short version. Figure 2 stars telecom for highest near-term impact citing McKinsey. McKinsey puts it at lowest near-term value tier.

    Figure 14 is a vendor roadmap table with three consecutive rows labelled IBM. Row two describes Google's Willow and Quantum Echoes. Row three describes Rigetti's Ankaa-3.

    And so on.

    The security angle is footnote 7 on page 9, where PQC and the quantum threat go "not within the scope." GSMA Intelligence's own operator survey puts network security first among quantum priorities, ahead of network efficiency.

    On methodology, Section 5 is genuinely good, and it defines five evaluation dimensions, names scalability as the most informative signal in the NISQ era, and tells operators to benchmark against the strongest realistic classical alternative. Section 6 then presents four validated use cases and three of them without the classical alternative comparison.

    The document is vendor-contributed, vendor-evidenced, vendor-benchmarked, and commercially downstream of a 16-week programme the same vendor runs. That isn't the problem. The problem is the GSMA badge and the fact that operators will quote it in board papers because GSMA said so.

    Full review with page numbers for both PDFs, so you can check me. postquantum.com/quantum-comput

    #infosec #quantum #PQC #postquantum #telecom #cryptography #GSMA

  39. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity

  40. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity

  41. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity

  42. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity