#pqc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.
-
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
El lado del mal - Blind Quantum Computing (3) https://elladodelmal.com/2026/07/blind-quantum-computing-3.html #BQC #Quantum #Privacidad #Algoritmo #PQC #QCaaS
-
El lado del mal - Blind Quantum Computing (3) https://elladodelmal.com/2026/07/blind-quantum-computing-3.html #BQC #Quantum #Privacidad #Algoritmo #PQC #QCaaS
-
The largest line in McKinsey's $400-600B quantum-finance projection is risk and cybersecurity at $95-155B, and the arithmetic is: a 3–5% revenue increase applied to $3.1T of security spend.
Whose revenue? A bank books no revenue on its own security budget; its vendors do. The report never says.
The companion slide lists PQC and QKD as a "new business opportunity" on the grounds that they will be mandatory. Mandatory defensive migration is a cost center for every bank; folding it into quantum's value is creative accounting.
That is one of five problems. The others: the slide's arithmetic cannot be reproduced from its own printed assumptions (apply the affected-share labels and $600B becomes $270B at most); quantum and AI impacts are merged with no allocation; the classical baseline is frozen at 2026 for the one line where it is disclosed at all; and nothing engages the published resource estimates, including Goldman Sachs' own 4,700 logical qubits at a sustained 45 MHz, against McKinsey's own hardware survey showing 100–200 logical qubits by 2030.
McKinsey's top number of $600B value of quantum to finance has been circulating for a year. And it seems to be based on a number of basic mistakes.
https://postquantum.com/quantum-computing/mckinsey-quantum-finance-600b/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #fintech
-
The largest line in McKinsey's $400-600B quantum-finance projection is risk and cybersecurity at $95-155B, and the arithmetic is: a 3–5% revenue increase applied to $3.1T of security spend.
Whose revenue? A bank books no revenue on its own security budget; its vendors do. The report never says.
The companion slide lists PQC and QKD as a "new business opportunity" on the grounds that they will be mandatory. Mandatory defensive migration is a cost center for every bank; folding it into quantum's value is creative accounting.
That is one of five problems. The others: the slide's arithmetic cannot be reproduced from its own printed assumptions (apply the affected-share labels and $600B becomes $270B at most); quantum and AI impacts are merged with no allocation; the classical baseline is frozen at 2026 for the one line where it is disclosed at all; and nothing engages the published resource estimates, including Goldman Sachs' own 4,700 logical qubits at a sustained 45 MHz, against McKinsey's own hardware survey showing 100–200 logical qubits by 2030.
McKinsey's top number of $600B value of quantum to finance has been circulating for a year. And it seems to be based on a number of basic mistakes.
https://postquantum.com/quantum-computing/mckinsey-quantum-finance-600b/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #fintech
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
After the White House quantum summit, I tested the claim that America built "every layer of the quantum stack." Eight layers. Named researchers. Primary sources.
Quick scorecard:
The PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) that NIST standardized and that EO 14412 mandates for federal systems? Designed almost entirely by Europeans and Canadians. CWI (Netherlands), Bochum (Germany), IBM Zurich (Switzerland), ENS Lyon (France), Waterloo (Canada). NIST ran the process — that's a real institutional win. But the algorithmic content is international.
The enabling infrastructure is even more striking.
Dilution refrigerators from Finland (Bluefors) and UK (Oxford Instruments) dominate the market that cools US superconducting quantum computers. Domestic manufacturing exists (Maybell in Denver, Bluefors's Syracuse operation) but the US remains substantially dependent on European-headquartered suppliers.
Control electronics from Switzerland (Zurich Instruments), Israel (Quantum Machines), Germany (Rohde & Schwarz).
The CHIPS Act quantum investments are partly a response to these dependencies.
On the science side: Josephson junction predicted at Cambridge (1962). First superconducting qubit demonstrated at NEC Japan (1999). Surface code traces to Kitaev (Russia). Steane code from Oxford. qLDPC codes from French and Russian mathematicians.
The US built the strongest commercial integration and scaling layer. That is a real and hard-won capability. It is not the same as sole authorship of the entire stack.
Policy implication: "we built everything" leads to different supply chain decisions than "we built the best integration layer, and it depends on allied supply chains." The second framing is more accurate and produces better policy.
Full article with every claim sourced:
https://postquantum.com/quantum-sovereignty/who-built-the-quantum-stack/#quantum #PQC #infosec #cryptography #postquantum #supplysecurity #quantumcomputing #cybersecurity
-
After the White House quantum summit, I tested the claim that America built "every layer of the quantum stack." Eight layers. Named researchers. Primary sources.
Quick scorecard:
The PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) that NIST standardized and that EO 14412 mandates for federal systems? Designed almost entirely by Europeans and Canadians. CWI (Netherlands), Bochum (Germany), IBM Zurich (Switzerland), ENS Lyon (France), Waterloo (Canada). NIST ran the process — that's a real institutional win. But the algorithmic content is international.
The enabling infrastructure is even more striking.
Dilution refrigerators from Finland (Bluefors) and UK (Oxford Instruments) dominate the market that cools US superconducting quantum computers. Domestic manufacturing exists (Maybell in Denver, Bluefors's Syracuse operation) but the US remains substantially dependent on European-headquartered suppliers.
Control electronics from Switzerland (Zurich Instruments), Israel (Quantum Machines), Germany (Rohde & Schwarz).
The CHIPS Act quantum investments are partly a response to these dependencies.
On the science side: Josephson junction predicted at Cambridge (1962). First superconducting qubit demonstrated at NEC Japan (1999). Surface code traces to Kitaev (Russia). Steane code from Oxford. qLDPC codes from French and Russian mathematicians.
The US built the strongest commercial integration and scaling layer. That is a real and hard-won capability. It is not the same as sole authorship of the entire stack.
Policy implication: "we built everything" leads to different supply chain decisions than "we built the best integration layer, and it depends on allied supply chains." The second framing is more accurate and produces better policy.
Full article with every claim sourced:
https://postquantum.com/quantum-sovereignty/who-built-the-quantum-stack/#quantum #PQC #infosec #cryptography #postquantum #supplysecurity #quantumcomputing #cybersecurity
-
New quantum snake oil just dropped: "HNDL detection" products and services.
In my new piece I call out "HNDL detection" market for what it is: exfiltration detection rebranded with a quantum label.
The core physics, passive collection (fiber splitter, receive-only RF, satellite dish) generates no observable event inside the victim's network. Zero. Your firewall, IDS, EDR, SIEM, NDR, and ML behavioral analytics all operate inside a boundary the collection never crosses. There is no packet to inspect because no packet was generated. There is no behavioral anomaly because the victim's traffic is identical whether or not a copy was made.
Every "HNDL detection" solution I've examined monitors NetFlow telemetry for outbound volume anomalies, unusual destinations, off-hours transfers, and encrypted tunnels to unexpected endpoints. That detects breaches and exfiltration. Useful, not new, and not what HNDL means.
The article covers the physics in depth: fiber tap insertion loss (0.002 dB per tap, per US Patent 4,802,723, below OTDR noise floor), the detection boundary problem (even where physical-layer detection is theoretically possible, the entity that can detect is the infra owner, not the data owner), LO leakage as the one genuine RF edge case (Ghostbuster, MobiCom 2018: 5m reliable, 14m best case, defeated by Phantom Eavesdropping LO whitening), and the historical record (Ivy Bells, Room 641A, Tempora: every major passive tap exposed by a human, never a detector).
Also covers the intent gap: even after a confirmed breach, no technical control can tell you the adversary plans to store data for future quantum decryption. You can confirm a theft. You cannot confirm a timeline.
The defense is ML-KEM (FIPS 203) on your long-lived confidentiality flows. Not a dashboard.
https://postquantum.com/post-quantum/cannot-detect-harvest-now-decrypt-later/
#infosec #cybersecurity #cryptography #PQC #postquantum #quantum #SIGINT #snakeoil
-
New quantum snake oil just dropped: "HNDL detection" products and services.
In my new piece I call out "HNDL detection" market for what it is: exfiltration detection rebranded with a quantum label.
The core physics, passive collection (fiber splitter, receive-only RF, satellite dish) generates no observable event inside the victim's network. Zero. Your firewall, IDS, EDR, SIEM, NDR, and ML behavioral analytics all operate inside a boundary the collection never crosses. There is no packet to inspect because no packet was generated. There is no behavioral anomaly because the victim's traffic is identical whether or not a copy was made.
Every "HNDL detection" solution I've examined monitors NetFlow telemetry for outbound volume anomalies, unusual destinations, off-hours transfers, and encrypted tunnels to unexpected endpoints. That detects breaches and exfiltration. Useful, not new, and not what HNDL means.
The article covers the physics in depth: fiber tap insertion loss (0.002 dB per tap, per US Patent 4,802,723, below OTDR noise floor), the detection boundary problem (even where physical-layer detection is theoretically possible, the entity that can detect is the infra owner, not the data owner), LO leakage as the one genuine RF edge case (Ghostbuster, MobiCom 2018: 5m reliable, 14m best case, defeated by Phantom Eavesdropping LO whitening), and the historical record (Ivy Bells, Room 641A, Tempora: every major passive tap exposed by a human, never a detector).
Also covers the intent gap: even after a confirmed breach, no technical control can tell you the adversary plans to store data for future quantum decryption. You can confirm a theft. You cannot confirm a timeline.
The defense is ML-KEM (FIPS 203) on your long-lived confidentiality flows. Not a dashboard.
https://postquantum.com/post-quantum/cannot-detect-harvest-now-decrypt-later/
#infosec #cybersecurity #cryptography #PQC #postquantum #quantum #SIGINT #snakeoil
-
New quantum snake oil just dropped: "HNDL detection" products and services.
In my new piece I call out "HNDL detection" market for what it is: exfiltration detection rebranded with a quantum label.
The core physics, passive collection (fiber splitter, receive-only RF, satellite dish) generates no observable event inside the victim's network. Zero. Your firewall, IDS, EDR, SIEM, NDR, and ML behavioral analytics all operate inside a boundary the collection never crosses. There is no packet to inspect because no packet was generated. There is no behavioral anomaly because the victim's traffic is identical whether or not a copy was made.
Every "HNDL detection" solution I've examined monitors NetFlow telemetry for outbound volume anomalies, unusual destinations, off-hours transfers, and encrypted tunnels to unexpected endpoints. That detects breaches and exfiltration. Useful, not new, and not what HNDL means.
The article covers the physics in depth: fiber tap insertion loss (0.002 dB per tap, per US Patent 4,802,723, below OTDR noise floor), the detection boundary problem (even where physical-layer detection is theoretically possible, the entity that can detect is the infra owner, not the data owner), LO leakage as the one genuine RF edge case (Ghostbuster, MobiCom 2018: 5m reliable, 14m best case, defeated by Phantom Eavesdropping LO whitening), and the historical record (Ivy Bells, Room 641A, Tempora: every major passive tap exposed by a human, never a detector).
Also covers the intent gap: even after a confirmed breach, no technical control can tell you the adversary plans to store data for future quantum decryption. You can confirm a theft. You cannot confirm a timeline.
The defense is ML-KEM (FIPS 203) on your long-lived confidentiality flows. Not a dashboard.
https://postquantum.com/post-quantum/cannot-detect-harvest-now-decrypt-later/
#infosec #cybersecurity #cryptography #PQC #postquantum #quantum #SIGINT #snakeoil
-
New quantum snake oil just dropped: "HNDL detection" products and services.
In my new piece I call out "HNDL detection" market for what it is: exfiltration detection rebranded with a quantum label.
The core physics, passive collection (fiber splitter, receive-only RF, satellite dish) generates no observable event inside the victim's network. Zero. Your firewall, IDS, EDR, SIEM, NDR, and ML behavioral analytics all operate inside a boundary the collection never crosses. There is no packet to inspect because no packet was generated. There is no behavioral anomaly because the victim's traffic is identical whether or not a copy was made.
Every "HNDL detection" solution I've examined monitors NetFlow telemetry for outbound volume anomalies, unusual destinations, off-hours transfers, and encrypted tunnels to unexpected endpoints. That detects breaches and exfiltration. Useful, not new, and not what HNDL means.
The article covers the physics in depth: fiber tap insertion loss (0.002 dB per tap, per US Patent 4,802,723, below OTDR noise floor), the detection boundary problem (even where physical-layer detection is theoretically possible, the entity that can detect is the infra owner, not the data owner), LO leakage as the one genuine RF edge case (Ghostbuster, MobiCom 2018: 5m reliable, 14m best case, defeated by Phantom Eavesdropping LO whitening), and the historical record (Ivy Bells, Room 641A, Tempora: every major passive tap exposed by a human, never a detector).
Also covers the intent gap: even after a confirmed breach, no technical control can tell you the adversary plans to store data for future quantum decryption. You can confirm a theft. You cannot confirm a timeline.
The defense is ML-KEM (FIPS 203) on your long-lived confidentiality flows. Not a dashboard.
https://postquantum.com/post-quantum/cannot-detect-harvest-now-decrypt-later/
#infosec #cybersecurity #cryptography #PQC #postquantum #quantum #SIGINT #snakeoil
-
New quantum snake oil just dropped: "HNDL detection" products and services.
In my new piece I call out "HNDL detection" market for what it is: exfiltration detection rebranded with a quantum label.
The core physics, passive collection (fiber splitter, receive-only RF, satellite dish) generates no observable event inside the victim's network. Zero. Your firewall, IDS, EDR, SIEM, NDR, and ML behavioral analytics all operate inside a boundary the collection never crosses. There is no packet to inspect because no packet was generated. There is no behavioral anomaly because the victim's traffic is identical whether or not a copy was made.
Every "HNDL detection" solution I've examined monitors NetFlow telemetry for outbound volume anomalies, unusual destinations, off-hours transfers, and encrypted tunnels to unexpected endpoints. That detects breaches and exfiltration. Useful, not new, and not what HNDL means.
The article covers the physics in depth: fiber tap insertion loss (0.002 dB per tap, per US Patent 4,802,723, below OTDR noise floor), the detection boundary problem (even where physical-layer detection is theoretically possible, the entity that can detect is the infra owner, not the data owner), LO leakage as the one genuine RF edge case (Ghostbuster, MobiCom 2018: 5m reliable, 14m best case, defeated by Phantom Eavesdropping LO whitening), and the historical record (Ivy Bells, Room 641A, Tempora: every major passive tap exposed by a human, never a detector).
Also covers the intent gap: even after a confirmed breach, no technical control can tell you the adversary plans to store data for future quantum decryption. You can confirm a theft. You cannot confirm a timeline.
The defense is ML-KEM (FIPS 203) on your long-lived confidentiality flows. Not a dashboard.
https://postquantum.com/post-quantum/cannot-detect-harvest-now-decrypt-later/
#infosec #cybersecurity #cryptography #PQC #postquantum #quantum #SIGINT #snakeoil
-
The minipgp6-sop ("msop") CLI tool can now be seen interoperating with other v6 #OpenPGP implementations, including using #PQC hybrid keys from the new #RFC9980:
In particular, the rPGP-based "rsop" CLI tool already features PQC support in its latest stable version.
Other #SOP implementations don't include PQC support in their default builds yet, but selecting any of the "+pqc" implementations (at the top of the test suite page) shows a lot more interop.
-
The minipgp6-sop ("msop") CLI tool can now be seen interoperating with other v6 #OpenPGP implementations, including using #PQC hybrid keys from the new #RFC9980:
In particular, the rPGP-based "rsop" CLI tool already features PQC support in its latest stable version.
Other #SOP implementations don't include PQC support in their default builds yet, but selecting any of the "+pqc" implementations (at the top of the test suite page) shows a lot more interop.
-
RE: https://social.linux.pizza/@AthanSpod/116883671948561062
I'm an idiot who forgot to load this post with relevant hash tags, so now I'll do that whilst quoting it.
-
Aceptaron mi charla en la #UbuConLa 2026!!
A investigar y preparar las diapos y ... estaré hablando sobre Criptografía Post-Cuántica en Ubuntu 26.04 LTS, y jugando con algunas herramientas 😜
Si van a andar por Chile a fines de setiembre, no olviden pasarse por la Facultad de Ingeniería U. Central.
Mi charla será virtual, así que supongo que habrá stream, les aviso!
#gnu #linux #ubuntu #ubucon #ubuconla #pqc #pqcrypto #postquantum #cryptography #criptografía #cripto
-
Aceptaron mi charla en la #UbuConLa 2026!!
A investigar y preparar las diapos y ... estaré hablando sobre Criptografía Post-Cuántica en Ubuntu 26.04 LTS, y jugando con algunas herramientas 😜
Si van a andar por Chile a fines de setiembre, no olviden pasarse por la Facultad de Ingeniería U. Central.
Mi charla será virtual, así que supongo que habrá stream, les aviso!
#gnu #linux #ubuntu #ubucon #ubuconla #pqc #pqcrypto #postquantum #cryptography #criptografía #cripto