home.social

#pqc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.

fetched live
  1. New paper: Hidden-Radix Cryptography vs Post-Quantum Cryptography.

    Traces hidden-radix from naive base-change ciphers through SRE to p-adic completions and the idelic ring. Compares against all five PQC families: lattice, code, hash, multivariate, and isogeny-based.

    doi.org/10.5281/zenodo.21609391
    papers.qnfo.org/papers/hidden-

    #QNFO #Cryptography #PQC #pAdic #HiddenRadix

  2. New paper: Hidden-Radix Cryptography vs Post-Quantum Cryptography.

    Traces hidden-radix from naive base-change ciphers through SRE to p-adic completions and the idelic ring. Compares against all five PQC families: lattice, code, hash, multivariate, and isogeny-based.

    doi.org/10.5281/zenodo.21609391
    papers.qnfo.org/papers/hidden-

    #QNFO #Cryptography #PQC #pAdic #HiddenRadix

  3. "AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.

    postquantum.com/post-quantum/a

    #PQC #AI #infosec #cryptography

  4. "AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.

    postquantum.com/post-quantum/a

    #PQC #AI #infosec #cryptography

  5. Can't migrate everything to PQC at once. Which layer first?

    TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.

    postquantum.com/post-quantum/p

    #PQC #TLS #IPsec #infosec #cryptography

  6. Can't migrate everything to PQC at once. Which layer first?

    TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.

    postquantum.com/post-quantum/p

    #PQC #TLS #IPsec #infosec #cryptography

  7. US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.

    For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.

    postquantum.com/post-quantum/p

    #PQC #compliance #infosec #cryptography

  8. US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.

    For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.

    postquantum.com/post-quantum/p

    #PQC #compliance #infosec #cryptography

  9. Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.

    Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.

    postquantum.com/post-quantum/c

    #cryptoagility #PQC #infosec #cryptography

  10. Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.

    Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.

    postquantum.com/post-quantum/c

    #cryptoagility #PQC #infosec #cryptography

  11. PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.

    Largest Shor's factoring demo on real hardware: the number 21.

    The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.

    postquantum.com/post-quantum/n

    #RSA #PQC #infosec #cryptography

  12. PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.

    Largest Shor's factoring demo on real hardware: the number 21.

    The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.

    postquantum.com/post-quantum/n

    #RSA #PQC #infosec #cryptography

  13. CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.

    If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:

    postquantum.com/cnsa-2-0/compl

    #CNSA #PQC #infosec #NSA #cryptography

  14. CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.

    If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:

    postquantum.com/cnsa-2-0/compl

    #CNSA #PQC #infosec #NSA #cryptography

  15. My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:

    redhat.wd5.myworkdayjobs.com/J

    #Crypto #cryptography #GetFediHired #FediHire

    Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.

  16. My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:

    redhat.wd5.myworkdayjobs.com/J

    #Crypto #cryptography #GetFediHired #FediHire

    Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.

  17. Q-FUD (Quantum Fear, Uncertainty, and Doubt) is an industry. Inflated timelines to sell products. Repackaged NIST guidelines as proprietary frameworks. "Quantum apocalypse" headlines for clicks. CISOs left making decisions with information designed to prevent rational decisions.

    The field guide to manufactured urgency:

    postquantum.com/post-quantum/q

    #QFUD #PQC #infosec #cryptography

  18. Q-FUD (Quantum Fear, Uncertainty, and Doubt) is an industry. Inflated timelines to sell products. Repackaged NIST guidelines as proprietary frameworks. "Quantum apocalypse" headlines for clicks. CISOs left making decisions with information designed to prevent rational decisions.

    The field guide to manufactured urgency:

    postquantum.com/post-quantum/q

    #QFUD #PQC #infosec #cryptography

  19. "Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.

    EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.

    Europe didn't pick a protocol winner. It's building a portfolio.

    So why does CV-QKD get disproportionate strategic attention? Supply chain.

    DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.

    Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).

    CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.

    QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.

    Now here's what makes it more complicated than a clean sovereignty narrative.

    China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.

    Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.

    The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.

    This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.

    For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.

    Full analysis: postquantum.com/post-quantum/e

    #infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI

  20. "Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.

    EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.

    Europe didn't pick a protocol winner. It's building a portfolio.

    So why does CV-QKD get disproportionate strategic attention? Supply chain.

    DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.

    Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).

    CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.

    QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.

    Now here's what makes it more complicated than a clean sovereignty narrative.

    China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.

    Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.

    The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.

    This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.

    For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.

    Full analysis: postquantum.com/post-quantum/e

    #infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI

  21. New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.

    The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.

    Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.

    For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.

    Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): postquantum.com/security-pqc/e

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin

  22. New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.

    The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.

    Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.

    For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.

    Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): postquantum.com/security-pqc/e

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin

  23. Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.

    postquantum.com/post-quantum/g

    #AES #Grover #PQC #cryptography

  24. Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.

    postquantum.com/post-quantum/g

    #AES #Grover #PQC #cryptography

  25. Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.

    If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.

    Every deadline that moved:

    postquantum.com/post-quantum/p

    #PQC #infosec #cryptography #compliance

  26. Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.

    If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.

    Every deadline that moved:

    postquantum.com/post-quantum/p

    #PQC #infosec #cryptography #compliance

  27. PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.

    The operational playbook for SOC teams told "prepare for quantum":

    postquantum.com/post-quantum/s

    #SOC #PQC #infosec #blueteam

  28. PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.

    The operational playbook for SOC teams told "prepare for quantum":

    postquantum.com/post-quantum/s

    #SOC #PQC #infosec #blueteam

  29. The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.

    Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.

    postquantum.com/post-quantum/u

    #PQC #CISA #FedCyber #infosec

  30. The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.

    Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.

    postquantum.com/post-quantum/u

    #PQC #CISA #FedCyber #infosec

  31. PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:

    Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.

    Each with different key management, tooling, and upgrade paths. Full scope:

    postquantum.com/post-quantum/s

    #PQC #supplychain #infosec #cryptography

  32. PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:

    Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.

    Each with different key management, tooling, and upgrade paths. Full scope:

    postquantum.com/post-quantum/s

    #PQC #supplychain #infosec #cryptography

  33. If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."

    Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:

    postquantum.com/post-quantum/p

    #PQC #cryptography #infosec

  34. If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."

    Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:

    postquantum.com/post-quantum/p

    #PQC #cryptography #infosec

  35. Internet-wide PQC measurement: 160M SSH hosts scanned.

    IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.

    The OT gap should alarm anyone in ICS/SCADA.

    postquantum.com/security-pqc/f

    #PQC #OTsecurity #ICS #infosec

  36. Internet-wide PQC measurement: 160M SSH hosts scanned.

    IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.

    The OT gap should alarm anyone in ICS/SCADA.

    postquantum.com/security-pqc/f

    #PQC #OTsecurity #ICS #infosec

  37. "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

    CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

    postquantum.com/post-quantum/c

    #threatmodeling #CRQC #infosec #PQC

  38. "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

    CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

    postquantum.com/post-quantum/c

    #threatmodeling #CRQC #infosec #PQC

  39. The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.

    Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.

    postquantum.com/post-quantum/p

    #PQC #cryptography #infosec #cryptoagility

  40. The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.

    Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.

    postquantum.com/post-quantum/p

    #PQC #cryptography #infosec #cryptoagility

  41. An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.

    That floor is lower than most threat assessments assume.

    postquantum.com/post-quantum/q

    #ECC #cryptography #PQC #infosec #Bitcoin

  42. An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.

    That floor is lower than most threat assessments assume.

    postquantum.com/post-quantum/q

    #ECC #cryptography #PQC #infosec #Bitcoin

  43. If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.

    He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.

    postquantum.com/security-pqc/a

    #PQC #CRQC #infosec #cryptography

  44. If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.

    He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.

    postquantum.com/security-pqc/a

    #PQC #CRQC #infosec #cryptography

  45. The largest line in McKinsey's $400-600B quantum-finance projection is risk and cybersecurity at $95-155B, and the arithmetic is: a 3–5% revenue increase applied to $3.1T of security spend.

    Whose revenue? A bank books no revenue on its own security budget; its vendors do. The report never says.

    The companion slide lists PQC and QKD as a "new business opportunity" on the grounds that they will be mandatory. Mandatory defensive migration is a cost center for every bank; folding it into quantum's value is creative accounting.

    That is one of five problems. The others: the slide's arithmetic cannot be reproduced from its own printed assumptions (apply the affected-share labels and $600B becomes $270B at most); quantum and AI impacts are merged with no allocation; the classical baseline is frozen at 2026 for the one line where it is disclosed at all; and nothing engages the published resource estimates, including Goldman Sachs' own 4,700 logical qubits at a sustained 45 MHz, against McKinsey's own hardware survey showing 100–200 logical qubits by 2030.

    McKinsey's top number of $600B value of quantum to finance has been circulating for a year. And it seems to be based on a number of basic mistakes.

    postquantum.com/quantum-comput

    #infosec #cybersecurity #quantum #PQC #postquantum #cryptography #fintech

  46. The largest line in McKinsey's $400-600B quantum-finance projection is risk and cybersecurity at $95-155B, and the arithmetic is: a 3–5% revenue increase applied to $3.1T of security spend.

    Whose revenue? A bank books no revenue on its own security budget; its vendors do. The report never says.

    The companion slide lists PQC and QKD as a "new business opportunity" on the grounds that they will be mandatory. Mandatory defensive migration is a cost center for every bank; folding it into quantum's value is creative accounting.

    That is one of five problems. The others: the slide's arithmetic cannot be reproduced from its own printed assumptions (apply the affected-share labels and $600B becomes $270B at most); quantum and AI impacts are merged with no allocation; the classical baseline is frozen at 2026 for the one line where it is disclosed at all; and nothing engages the published resource estimates, including Goldman Sachs' own 4,700 logical qubits at a sustained 45 MHz, against McKinsey's own hardware survey showing 100–200 logical qubits by 2030.

    McKinsey's top number of $600B value of quantum to finance has been circulating for a year. And it seems to be based on a number of basic mistakes.

    postquantum.com/quantum-comput

    #infosec #cybersecurity #quantum #PQC #postquantum #cryptography #fintech

  47. New analysis: How Much Can AI Actually Help With PQC Migration?

    A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.

    The timeline estimate is not.

    I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.

    That accounts for maybe 15-20% of total program effort.

    The other 80%:

    - Getting executive mandate and multi-year budget (3-12 months)

    - Standing up program governance (3-6 months)

    - Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)

    - Change advisory board approvals for every production change

    - Vendor firmware/certification timelines entirely outside your control

    - Interoperability testing with real counterparties on their schedules

    - FIPS 140-3 module validation cycles

    - CBOM and crypto-agility as organizational transformations, not technology deployments

    Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.

    The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.

    EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.

    The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.

    postquantum.com/post-quantum/a

    #infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration

  48. New analysis: How Much Can AI Actually Help With PQC Migration?

    A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.

    The timeline estimate is not.

    I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.

    That accounts for maybe 15-20% of total program effort.

    The other 80%:

    - Getting executive mandate and multi-year budget (3-12 months)

    - Standing up program governance (3-6 months)

    - Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)

    - Change advisory board approvals for every production change

    - Vendor firmware/certification timelines entirely outside your control

    - Interoperability testing with real counterparties on their schedules

    - FIPS 140-3 module validation cycles

    - CBOM and crypto-agility as organizational transformations, not technology deployments

    Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.

    The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.

    EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.

    The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.

    postquantum.com/post-quantum/a

    #infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration