home.social

#pqc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.

fetched live
  1. CW: llm producing genuinely impressive cryptographic result

    I was looking at the NIST-competition for further signatures at work today and noticed that HAWK has been withdrawn...

    (Context: NIST wasn't exactly enthusiastic about any signature scheme in the previous pqc competition and started a new one that is now in round three with only a few schemes left. HAWK was the only remaining lattice based scheme with the claim to fame being that it is basically FALCON (in standardization by NIST as FN-DSA) without the need for floating point arithmetic.)

    Now it turns out that Anthropic has an LLM that managed to find a severe enough attack to require enough of an adjustment to the parameters, that HAWK would become noncompetitive.

    This was genuinely new, clearly found by AI, on a very high profile target that lots of humans actively tried to break unsuccessfully, and clearly important that it was found...

    They also managed to improve the cryptanalysis on a round reduced version of AES, another VERY impressive feat!

    There is a genuine argument now that AI is competitive with the best human cryptanalysts and I am not yet sure what to make of that...
    😐

    #crypto #cryptography #pqc

  2. CW: llm producing genuinely impressive cryptographic result

    I was looking at the NIST-competition for further signatures at work today and noticed that HAWK has been withdrawn...

    (Context: NIST wasn't exactly enthusiastic about any signature scheme in the previous pqc competition and started a new one that is now in round three with only a few schemes left. HAWK was the only remaining lattice based scheme with the claim to fame being that it is basically FALCON (in standardization by NIST as FN-DSA) without the need for floating point arithmetic.)

    Now it turns out that Anthropic has an LLM that managed to find a severe enough attack to require enough of an adjustment to the parameters, that HAWK would become noncompetitive.

    This was genuinely new, clearly found by AI, on a very high profile target that lots of humans actively tried to break unsuccessfully, and clearly important that it was found...

    They also managed to improve the cryptanalysis on a round reduced version of AES, another VERY impressive feat!

    There is a genuine argument now that AI is competitive with the best human cryptanalysts and I am not yet sure what to make of that...
    😐

    #crypto #cryptography #pqc

  3. Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.

    Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.

    Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.

    So I try to explain the change.

    postquantum.com/security-pqc/g

    #PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity

  4. Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.

    Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.

    Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.

    So I try to explain the change.

    postquantum.com/security-pqc/g

    #PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity

  5. Oracle's plans for backporting PQC algorithms (ML-DSA and ML-KEM) and TLS 1.3 Post-Quantum Hybrid Key Exchange to current LTS JDK releases:

    blogs.oracle.com/java/post-qua

    #java #security #crypto #tls #pqc

  6. Oracle's plans for backporting PQC algorithms (ML-DSA and ML-KEM) and TLS 1.3 Post-Quantum Hybrid Key Exchange to current LTS JDK releases:

    blogs.oracle.com/java/post-qua

    #java #security #crypto #tls #pqc

  7. We published our #PQC roadmap for #GoogleCloud aiming for an ambitious 2029 completion timeline. It’s been quite a ride to get commitments from product teams all over the organization to become quantum safe by 2029. cloud.google.com/blog/products

  8. We published our #PQC roadmap for #GoogleCloud aiming for an ambitious 2029 completion timeline. It’s been quite a ride to get commitments from product teams all over the organization to become quantum safe by 2029. cloud.google.com/blog/products

  9. Sí señor!

    Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!

    Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!

    Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu

    Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)

    #UbuConLA #pqc #postquantum #cybersecurity #infosec

  10. Sí señor!

    Desde #JuncoTIC somos patrocinadores de la #UbuConLA2026 que se realizará en Chile el próximo 29 y 30 de setiembre!

    Estaremos sorteando accesos gratuitos a nuestros cursos, así que los que vayan a ir estén atentos a los sorteos!

    Por mi parte, daré una charla sobre Criptografía Post-cuántica en #Ubuntu

    Acá seguimos, apoyando eventos de #softwarelibre y #opensource, y las comunidades abiertas, que compartiendo se aprende más :-)

    #UbuConLA #pqc #postquantum #cybersecurity #infosec

  11. Viele Unternehmen unterschätzen #PQC. Die EU erwartet bis 2026 Migrationspläne – Umsetzung bis 2030/2035. Das ist kein Forschungsthema mehr, sondern Governance.

    Sebastian Hempel analysiert, was konkret zu tun ist: javapro.io/de/pqc-es-ist-zeit-

    #Compliance #CyberSecurity @Cloudflare

  12. Viele Unternehmen unterschätzen #PQC. Die EU erwartet bis 2026 Migrationspläne – Umsetzung bis 2030/2035. Das ist kein Forschungsthema mehr, sondern Governance.

    Sebastian Hempel analysiert, was konkret zu tun ist: javapro.io/de/pqc-es-ist-zeit-

    #Compliance #CyberSecurity @Cloudflare

  13. Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.

    Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.

    Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.

    But this is the third event this summer hitting PQC from a different angle.

    Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.

    Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.

    And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.

    Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.

    If the lesson were just "lattice math is fragile," one event would suffice.

    The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.

    SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.

    Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:

    postquantum.com/security-pqc/s

    #infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility

  14. Daniel Simon, creator of the algorithm that catalyzed Shor's, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). If correct, the asymptotic security assumptions behind ML-KEM and ML-DSA would need reassessment.

    Related interesting part: Wen and Zheng at Télécom Paris (ePrint 2026/155, accepted to CRYPTO 2026 and therefore peer-reviewed) prove that Module-LWE is quantum-polynomially equivalent to a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank that ML-KEM actually uses in production. They also reduce that structured variant to plain EDCP. The reduction chain between Simon's claim and the algorithms in your TLS stack has fewer unproven joints than it did a week ago, and half of that chain is now peer-reviewed.

    Simon's paper is preliminary, several proofs are sketches, and the final SVP/LWE corollary rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am not a theoretical cryptographer and I am not declaring this proven. I am waiting for people like Micciancio, Peikert, Regev, Ducas to review it.

    But this is the third event this summer hitting PQC from a different angle.

    Bernstein demonstrated ML-DSA signing-key recovery in under one second by exploiting implementation flaws. The algorithm itself is fine; what organizations actually deploy is not. The attack surface is the gap between a correct specification and a correct implementation, and that gap exists in every deployment.

    Anthropic's AI model autonomously recovered signing keys from HAWK-256 challenge instances. HAWK is a NIST Round 3 signature candidate, not a deployed standard, so nothing in production was touched. But the result showed that AI systems are now producing original cryptanalysis, not just assisting human researchers. Every deprecated or candidate algorithm still running in your estate became easier to attack the moment that capability crossed the line.

    And now Simon's claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM's specific hardness assumption.

    Three different attack classes: implementation bugs found by a human, a PQC candidate broken autonomously by AI, and a theoretical quantum algorithm targeting foundational lattice assumptions.

    If the lesson were just "lattice math is fragile," one event would suffice.

    The lesson is that your cryptographic attack surface is wider than any single threat model covers, and the only architecture that absorbs all three is one built to replace algorithms without rebuilding infrastructure. I.e. crypto-agility.

    SLH-DSA, LMS/XMSS, HQC, and everything hash-based or code-based is untouched by all of this.

    Full analysis of the Simon paper, including where the proof is most vulnerable and what it means for migration planning:

    postquantum.com/security-pqc/s

    #infosec #cybersecurity #PQC #postquantum #cryptography #quantum #MLKEM #latticecrypto #cryptoagility

  15. How to read a quantum vendor's fidelity claim: demand the protocol (RB, XEB, and GST measure different things), the median rather than the hero pair, simultaneous operation, the readout/SPAM/leakage figures alongside the gate number, and the duration it held. Five answers is engineering; one is a press release. Full methodology plus mid-2026 numbers for every modality: postquantum.com/quantum-comput #infosec #quantum #PQC #benchmarking

  16. How to read a quantum vendor's fidelity claim: demand the protocol (RB, XEB, and GST measure different things), the median rather than the hero pair, simultaneous operation, the readout/SPAM/leakage figures alongside the gate number, and the duration it held. Five answers is engineering; one is a press release. Full methodology plus mid-2026 numbers for every modality: postquantum.com/quantum-comput #infosec #quantum #PQC #benchmarking

  17. Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.

    postquantum.com/security-pqc/m

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore

  18. Singapore's MAS will issue supervisory expectations for FIs' quantum-safe migration. Target: quantum resilience before end of decade. Three-phase approach: cryptographic asset inventory, prioritized migration of vulnerable systems, then technical capabilities + governance.

    postquantum.com/security-pqc/m

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #MAS #Singapore

  19. For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.

    TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.

    The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.

    TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.

    Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.

    My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:

    postquantum.com/security-pqc/t

    #infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum

  20. For the PKI/TLS people here: Chrome's MTC test-operator program is now receiving external applications.

    TrustAsia filed Chromium Issue 538260165 ("Test MTC CA Operator: [TrustAsia]") on July 24. Geomys followed on July 31. PKI standards expert Corey Bonnell surfaced the TrustAsia filing publicly and identified it as the first such application he could find in the tracker.

    The technical details: TrustAsia's filing uses unsigned CA trust-anchor certificates per RFC 9925 (the general-purpose profile for X.509 certificates without cryptographic signatures, finalized Feb 2026) and the critical id-pe-mtcCertificationAuthority extension from draft-ietf-plants-merkle-tree-certs-05. The extension carries four fields — log hash algorithm, cosigner signature algorithm, and separate min/max serial number bounds. The critical marking prevents conventional path validators from misinterpreting the certificate as an ordinary intermediate.

    TrustAsia qualifies for Chrome's Phase 2 (Q1 2027) through its CT log history — Chrome-qualified since 2021, with current log2026a/b shards carrying usable status, clearing the "usable log before Feb 1, 2026" threshold.

    Chrome's quantum-resistant root store (CQRS) is targeted for Q3 2027. The current Chrome-Cloudflare experiment covers ~1,000 domains with classical signatures and X.509 failsafe. Production post-quantum authentication via MTC is still a 2027 target, not current reality.

    My full analysis covers the web PKI fork implications for PQC migration, the RFC 9925 mechanics, Chrome's three-phase plan, and what DigiCert, Let's Encrypt, and now TrustAsia/Geomys activity means for the MTC deployment timeline:

    postquantum.com/security-pqc/t

    #infosec #cybersecurity #cryptography #PQC #postquantum #TLS #PKI #quantum

  21. Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.

    Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.

    Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.

    postquantum.com/industry-news/

    #infosec #PQC #postquantum #cryptography #NIST #cybersecurity

  22. Fact-checked the quantum sections of WEF's Top 10 Emerging Technologies 2026.

    Three errors: NIST PQC took 8 years, not 2. IBM/Moderna was mRNA structure prediction, not protein folding. "Hybrid classical-quantum cryptography" is wrong terminology.

    Also missing: TNFL, key-establishment/signature distinction, all NIST algorithm names.

    postquantum.com/industry-news/

    #infosec #PQC #postquantum #cryptography #NIST #cybersecurity

  23. IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.

    UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.

    IBM packaged three evidence levels as one.

    postquantum.com/industry-news/

    #infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM

  24. IBM declared a "quantum advantage era." Three preprints make different claims, but don't confirm the declaration.

    UChicago: explicit advantage claim, device-dependent fidelity certificate. Qedma: no formal advantage proof; late-time results use a heuristic. Algorithmiq: no exhaustive classical separation; accuracy bound missing.

    IBM packaged three evidence levels as one.

    postquantum.com/industry-news/

    #infosec #cybersecurity #quantum #PQC #postquantum #cryptography #IBM

  25. A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).

    The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.

    Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.

    The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.

    For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.

    The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.

    Full analysis: postquantum.com/industry-news/

    #quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological

  26. A Harvard-Quantinuum-Stony Brook-UChicago collaboration published what the paper describes as the first experimental demonstration of a universal topological gate set built from braiding and fusing non-Abelian anyons, in Nature (vol. 655, pp. 591-597, July 15).

    The experiment: 54 physical qubits encoding 18 six-level qudits (each qudit is a qutrit-qubit pair, three physical qubits per site) on the H2-1 trapped-ion processor. The team prepared the ground state of the quantum double of S3 (the smallest non-Abelian group), encoded logical qutrits in the fusion space of spatially separated anyons, and demonstrated three primitives: a pull-through entangling gate via coherent braiding, and logical X- and Z-basis measurements via fusion and topological-charge readout. Braiding alone is provably not universal for these simple anyons; treating fusion as a computational primitive completes the gate set, an idea from Mochon's 2004 paper. The current demonstrations use linear-depth circuits, but the paper notes all three primitives can be scalably implemented with constant-depth adaptive circuits.

    Universality was illustrated by topologically preparing a magic state, the non-Clifford resource that most fault-tolerant architectures plan to build through distillation factories. The cyclic-fusion evidence from trapping a single non-Abelian anyon on the torus provides a separate diagnostic of the S3 encoding's computational power.

    The caveats are in the paper's own language: stabilizing the topological phase requires active error correction, "which is beyond the scope of the present work," though a finite decoding threshold for quantum doubles with solvable groups has recently been proven. No distance-scaling result shows that a larger lattice improves logical performance. Ground-state preparation discards about 24% of shots under heralding; the most selective calibration protocol (bureau of standards) accepted 11.5% against an ideal 12.5%, with about 6% after all heralding; the magic-state protocol's acceptance was 26.52%. The pull-through gate compiled to 845 native two-qubit gates at depth 307, about 5.9s per shot.

    For the CRQC picture: the magic-state result maps onto the magic-state capability in my framework at proof-of-principle level. It shows the anyonic primitives can create a non-Clifford resource but nothing yet about fault-tolerant production, injection, or logical fidelity at scale. The result widens the credible architecture set without shortening the calendar, and it raises the bar for Microsoft's materials-first Majorana approach, which pursues native topological protection in semiconductor-superconductor devices via parity measurements and measurement-based braiding.

    The deeper trade this paper forces: fusion-space computing may swap the magic-state-factory overhead for a more complex preparation, measurement, and decoding stack, and this paper makes that comparison an engineering question rather than a theoretical one. Twenty-two years from Mochon's recipe to hardware. Protection is next.

    Full analysis: postquantum.com/industry-news/

    #quantumcomputing #physics #faulttolerance #infosec #PQC #postquantum #topological

  27. DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.

    Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.

    Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.

    postquantum.com/security-pqc/d

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography

  28. DigiCert Quantum Readiness Outlook 2026: 87% pursuing PQC, 7% deployed quantum-safe certs at scale. <2 points of progress in a year.

    Barriers: legacy complexity 26%, performance 19%, budget 19%, exec buy-in 8%, where to start 3%.

    Report ignores TNFL entirely. No key-establishment vs. signature distinction. EO 14412 splits these for a reason.

    postquantum.com/security-pqc/d

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography

  29. Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ?

    Until now, I haven’t.

    #pqc #crypto #cryptography #dfir

  30. Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ?

    Until now, I haven’t.

    #pqc #crypto #cryptography #dfir

  31. HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.

    The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.

    The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.

    FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.

    What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.

    Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.

    Full analysis: postquantum.com/security-pqc/h

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA

  32. HKMA just published the most granular regulator-led PQC readiness assessment I've seen from any financial authority: a 56-page whitepaper with sector-wide survey data, a four-dimensional readiness index (12 sub-indices), barrier rankings, and five completed pilot descriptions.

    The headline number: Hong Kong's banking sector scores 2.3/10 on post-quantum cryptography readiness. Pilots score 1.8/10 — the weakest dimension. 71% of respondents have never conducted or planned any PoC or live testing of PQC algorithms.

    The barrier data is more interesting than the score. 87% ranked third-party dependencies as a top-three obstacle. 85% said their vendors lack clear PQC roadmaps. 79% cited technical complexity of cryptographic asset discovery across legacy IT environments. Banks can't migrate what they don't control, and the vendor ecosystem hasn't given them enough to plan against.

    FINMA published similar findings from Switzerland two weeks earlier: 72% of 60 surveyed institutions hadn't planned or implemented quantum-safe measures, only 8% had a roadmap. Two jurisdictions, same picture.

    What the HKMA report misses: no treatment of signature forgery (Trust Now, Forge Later) as a distinct threat track alongside HNDL. For banking, this matters — a CRQC that can break ECC forges transaction authorizations on the day the capability arrives. The report also never names ML-KEM, ML-DSA, or SLH-DSA in its body (they appear only in the abbreviations appendix), and barely addresses China's divergent PQC standards program despite Hong Kong straddling both cryptographic ecosystems.

    Carmen Chu (HKMA Banking Supervision) noted that banks with existing transition plans estimate 5.6 years on average to complete migration. The HKMA targets full readiness by 2030. The contradiction speaks for itself.

    Full analysis: postquantum.com/security-pqc/h

    #infosec #cybersecurity #PQC #postquantum #quantum #cryptography #banking #HKMA

  33. Best quantum computing meta-analysis of the year: Jurczak's PFYT framework explains why quantum engineering horizons keep resetting. Backed by Riverlane QEC data and OpenAlex bibliometrics.

    Where it breaks: conflating unsettled architecture with undefined targets. For CRQC and simulation workloads, the acceptance test is concrete.

    postquantum.com/quantum-comput

    #quantum #PQC #infosec #cryptography #postquantum

  34. Best quantum computing meta-analysis of the year: Jurczak's PFYT framework explains why quantum engineering horizons keep resetting. Backed by Riverlane QEC data and OpenAlex bibliometrics.

    Where it breaks: conflating unsettled architecture with undefined targets. For CRQC and simulation workloads, the acceptance test is concrete.

    postquantum.com/quantum-comput

    #quantum #PQC #infosec #cryptography #postquantum

  35. Every technique used in the various July AI hacking incidents has a known defense. Weak passwords. Unauthenticated endpoints. SQL injection. Unmonitored east-west traffic. Two of three organizations Anthropic's models compromised didn't even detect it.

    This is not an AI problem. It is a cybersecurity basics problem exposed at machine speed.

    Vendors are already starting to market "AI-resilient" infrastructure and "Mythos-resistant" cryptography. Do not buy the label. The correct response to faster attacks is faster defense, not a different kind of defense. Shorter patching windows. Better credential rotation. Tighter segmentation. Automated rollout.

    The one actually new investment: crypto-agility. In the same week OpenAI and Anthropic disclosed their hacking incidents, Anthropic's AI killed a PQC candidate that had survived years of NIST evaluation. 60 hours. $100K. HAWK was withdrawn the next day.

    AI is now also attacking mathematical layer of your defenses. And the upcoming quantum threat is defeating the mathematical layer. The shared defense is the ability to swap cryptographic algorithms without rebuilding your stack.

    Do good cybersecurity. Do it better. Do it faster. Build crypto-agility into the architecture.

    postquantum.com/ai-security/ai

    #cybersecurity #CISO #AIhacking #cryptoagility #PQC #postquantum #infosec #AI #quantumsecurity

  36. Every technique used in the various July AI hacking incidents has a known defense. Weak passwords. Unauthenticated endpoints. SQL injection. Unmonitored east-west traffic. Two of three organizations Anthropic's models compromised didn't even detect it.

    This is not an AI problem. It is a cybersecurity basics problem exposed at machine speed.

    Vendors are already starting to market "AI-resilient" infrastructure and "Mythos-resistant" cryptography. Do not buy the label. The correct response to faster attacks is faster defense, not a different kind of defense. Shorter patching windows. Better credential rotation. Tighter segmentation. Automated rollout.

    The one actually new investment: crypto-agility. In the same week OpenAI and Anthropic disclosed their hacking incidents, Anthropic's AI killed a PQC candidate that had survived years of NIST evaluation. 60 hours. $100K. HAWK was withdrawn the next day.

    AI is now also attacking mathematical layer of your defenses. And the upcoming quantum threat is defeating the mathematical layer. The shared defense is the ability to swap cryptographic algorithms without rebuilding your stack.

    Do good cybersecurity. Do it better. Do it faster. Build crypto-agility into the architecture.

    postquantum.com/ai-security/ai

    #cybersecurity #CISO #AIhacking #cryptoagility #PQC #postquantum #infosec #AI #quantumsecurity

  37. The quantum industry has a credibility problem, and announcements like this one from EY make it worse. EY says it installed a quantum computer in Toronto for "optimization, fraud detection, data protection and large-scale risk management." No vendor named. No qubit count. No specifications. I reached out to EY's media contact and CTO - no response.

    One journalist got them to confirm it's photonic.

    Here's the problem: no photonic quantum computer on Earth can do optimization, fraud detection, or risk management. Not Xanadu's. Not ORCA's. Not anyone's. The photonic modality has the largest gap to useful computation of any quantum platform I track in my CRQC Scorecard.

    Buying a quantum computer before they're useful? Actually smart. I wrote many posts defending exactly that logic. Procurement cycles are long. Talent is scarce. Institutional learning takes time.

    But describing a research-grade photonic prototype as a machine for "processing highly sensitive workloads" in fraud detection and risk management? That's the kind of claim that makes tech execs roll their eyes at the entire quantum industry.

    Joe Depa told Accounting Today the real focus is readiness and PQC. That's honest and a praiseworthy initiative. If that's what EY said, I'd congratulate them. The press release says something else. The gap between the two is the problem.

    My full analysis, including two plausible vendors, what they can actually build, and what to watch for on August 5: postquantum.com/industry-news/

    #QuantumComputing #PostQuantum #PQC #PhotonicQuantum #QuantumSecurity #CyberSecurity #BigFour #EY #CISO

  38. The quantum industry has a credibility problem, and announcements like this one from EY make it worse. EY says it installed a quantum computer in Toronto for "optimization, fraud detection, data protection and large-scale risk management." No vendor named. No qubit count. No specifications. I reached out to EY's media contact and CTO - no response.

    One journalist got them to confirm it's photonic.

    Here's the problem: no photonic quantum computer on Earth can do optimization, fraud detection, or risk management. Not Xanadu's. Not ORCA's. Not anyone's. The photonic modality has the largest gap to useful computation of any quantum platform I track in my CRQC Scorecard.

    Buying a quantum computer before they're useful? Actually smart. I wrote many posts defending exactly that logic. Procurement cycles are long. Talent is scarce. Institutional learning takes time.

    But describing a research-grade photonic prototype as a machine for "processing highly sensitive workloads" in fraud detection and risk management? That's the kind of claim that makes tech execs roll their eyes at the entire quantum industry.

    Joe Depa told Accounting Today the real focus is readiness and PQC. That's honest and a praiseworthy initiative. If that's what EY said, I'd congratulate them. The press release says something else. The gap between the two is the problem.

    My full analysis, including two plausible vendors, what they can actually build, and what to watch for on August 5: postquantum.com/industry-news/

    #QuantumComputing #PostQuantum #PQC #PhotonicQuantum #QuantumSecurity #CyberSecurity #BigFour #EY #CISO

  39. Claude Mythos demonstrates that LLMs can find new, working attacks on cryptographic algorithms. Cryptographers and security experts have welcomed the LLM-driven results as a fresh set of eyes, especially as the world moves toward quantum-safe cryptography.
    databreachtoday.com/claude-myt #PQC