#pqc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.
Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.
https://postquantum.com/post-quantum/us-federal-pqc-mandate-2026/
-
The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.
Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.
https://postquantum.com/post-quantum/us-federal-pqc-mandate-2026/
-
The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.
Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.
https://postquantum.com/post-quantum/us-federal-pqc-mandate-2026/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/