#pqc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.
-
New paper: Hidden-Radix Cryptography vs Post-Quantum Cryptography.
Traces hidden-radix from naive base-change ciphers through SRE to p-adic completions and the idelic ring. Compares against all five PQC families: lattice, code, hash, multivariate, and isogeny-based.
https://doi.org/10.5281/zenodo.21609391
https://papers.qnfo.org/papers/hidden-radix-pqc/ -
New paper: Hidden-Radix Cryptography vs Post-Quantum Cryptography.
Traces hidden-radix from naive base-change ciphers through SRE to p-adic completions and the idelic ring. Compares against all five PQC families: lattice, code, hash, multivariate, and isogeny-based.
https://doi.org/10.5281/zenodo.21609391
https://papers.qnfo.org/papers/hidden-radix-pqc/ -
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.
For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.
https://postquantum.com/post-quantum/pqc-standards-fragmentation-multinationals/
-
US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.
For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.
https://postquantum.com/post-quantum/pqc-standards-fragmentation-multinationals/
-
Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.
Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.
https://postquantum.com/post-quantum/crypto-agility-architecture/
-
Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.
Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.
https://postquantum.com/post-quantum/crypto-agility-architecture/
-
PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.
Largest Shor's factoring demo on real hardware: the number 21.
The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.
https://postquantum.com/post-quantum/no-broken-rsa-2048-4096/
-
PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.
Largest Shor's factoring demo on real hardware: the number 21.
The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.
https://postquantum.com/post-quantum/no-broken-rsa-2048-4096/
-
CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.
If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:
-
CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.
If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
Q-FUD (Quantum Fear, Uncertainty, and Doubt) is an industry. Inflated timelines to sell products. Repackaged NIST guidelines as proprietary frameworks. "Quantum apocalypse" headlines for clicks. CISOs left making decisions with information designed to prevent rational decisions.
The field guide to manufactured urgency:
https://postquantum.com/post-quantum/q-fud-the-quantum-panic-industry/
-
Q-FUD (Quantum Fear, Uncertainty, and Doubt) is an industry. Inflated timelines to sell products. Repackaged NIST guidelines as proprietary frameworks. "Quantum apocalypse" headlines for clicks. CISOs left making decisions with information designed to prevent rational decisions.
The field guide to manufactured urgency:
https://postquantum.com/post-quantum/q-fud-the-quantum-panic-industry/
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
"Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.
EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.
Europe didn't pick a protocol winner. It's building a portfolio.
So why does CV-QKD get disproportionate strategic attention? Supply chain.
DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.
Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).
CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.
QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.
Now here's what makes it more complicated than a clean sovereignty narrative.
China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.
Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.
The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.
This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.
For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.
Full analysis: https://postquantum.com/post-quantum/europe-cv-qkd-industrialisation/
#infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI
-
"Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.
EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.
Europe didn't pick a protocol winner. It's building a portfolio.
So why does CV-QKD get disproportionate strategic attention? Supply chain.
DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.
Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).
CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.
QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.
Now here's what makes it more complicated than a clean sovereignty narrative.
China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.
Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.
The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.
This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.
For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.
Full analysis: https://postquantum.com/post-quantum/europe-cv-qkd-industrialisation/
#infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
Google: 2029. Microsoft: 2029. ANSSI: 2027 cert gate. US federal: 2030/2031. FINMA: mid-2027.
If your PQC migration plan targets 2035, it's outdated. The comfortable planning horizon contracted 3-5 years in 90 days.
Every deadline that moved:
https://postquantum.com/post-quantum/pqc-timeline-compression/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.
Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.
https://postquantum.com/post-quantum/us-federal-pqc-mandate-2026/
-
The U.S. federal PQC mandate consolidation: what applies to whom, by when, under which authority, and with what enforcement.
Five documents from three agencies, in one reference. If you sell to the federal government or hold contracts, this is your compliance calendar.
https://postquantum.com/post-quantum/us-federal-pqc-mandate-2026/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
Hybrid or just stick to ECC (25519).
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
PQC signature migration isn't a cert swap. Signatures are embedded in every stage of the software supply chain:
Code signing. Firmware validation. Container verification. Package authentication. Boot chains. UEFI.
Each with different key management, tooling, and upgrade paths. Full scope:
https://postquantum.com/post-quantum/signature-supply-chain/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
If a vendor says their proprietary algorithm is stronger than ML-KEM because "it hasn't been broken," they've confused "not attacked" with "unbreakable."
Cryptography's graveyard is full of unbroken algorithms. They were unbroken because nobody looked. One-minute checklist:
https://postquantum.com/post-quantum/proprietary-pqc-algorithms/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
The biggest near-term PQC risk isn't quantum. It's classical implementation bugs in brand-new cryptographic code deployed under deadline pressure across critical systems.
Hybrid ECC+PQ deployment isn't hedging quantum uncertainty. It's hedging classical software engineering reality.
https://postquantum.com/post-quantum/pqc-migration-risk-hybrid/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
An open competition has driven the logical qubit cost for one secp256k1 point addition into the high 1,100s. I traced where circuit optimization hits its hard floor - the arithmetic bound beyond which no algorithmic trick can reduce the cost further.
That floor is lower than most threat assessments assume.
https://postquantum.com/post-quantum/quantum-attack-ecc-circuit-floor/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
-
El lado del mal - Blind Quantum Computing (3) https://elladodelmal.com/2026/07/blind-quantum-computing-3.html #BQC #Quantum #Privacidad #Algoritmo #PQC #QCaaS
-
El lado del mal - Blind Quantum Computing (3) https://elladodelmal.com/2026/07/blind-quantum-computing-3.html #BQC #Quantum #Privacidad #Algoritmo #PQC #QCaaS
-
The largest line in McKinsey's $400-600B quantum-finance projection is risk and cybersecurity at $95-155B, and the arithmetic is: a 3–5% revenue increase applied to $3.1T of security spend.
Whose revenue? A bank books no revenue on its own security budget; its vendors do. The report never says.
The companion slide lists PQC and QKD as a "new business opportunity" on the grounds that they will be mandatory. Mandatory defensive migration is a cost center for every bank; folding it into quantum's value is creative accounting.
That is one of five problems. The others: the slide's arithmetic cannot be reproduced from its own printed assumptions (apply the affected-share labels and $600B becomes $270B at most); quantum and AI impacts are merged with no allocation; the classical baseline is frozen at 2026 for the one line where it is disclosed at all; and nothing engages the published resource estimates, including Goldman Sachs' own 4,700 logical qubits at a sustained 45 MHz, against McKinsey's own hardware survey showing 100–200 logical qubits by 2030.
McKinsey's top number of $600B value of quantum to finance has been circulating for a year. And it seems to be based on a number of basic mistakes.
https://postquantum.com/quantum-computing/mckinsey-quantum-finance-600b/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #fintech
-
The largest line in McKinsey's $400-600B quantum-finance projection is risk and cybersecurity at $95-155B, and the arithmetic is: a 3–5% revenue increase applied to $3.1T of security spend.
Whose revenue? A bank books no revenue on its own security budget; its vendors do. The report never says.
The companion slide lists PQC and QKD as a "new business opportunity" on the grounds that they will be mandatory. Mandatory defensive migration is a cost center for every bank; folding it into quantum's value is creative accounting.
That is one of five problems. The others: the slide's arithmetic cannot be reproduced from its own printed assumptions (apply the affected-share labels and $600B becomes $270B at most); quantum and AI impacts are merged with no allocation; the classical baseline is frozen at 2026 for the one line where it is disclosed at all; and nothing engages the published resource estimates, including Goldman Sachs' own 4,700 logical qubits at a sustained 45 MHz, against McKinsey's own hardware survey showing 100–200 logical qubits by 2030.
McKinsey's top number of $600B value of quantum to finance has been circulating for a year. And it seems to be based on a number of basic mistakes.
https://postquantum.com/quantum-computing/mckinsey-quantum-finance-600b/
#infosec #cybersecurity #quantum #PQC #postquantum #cryptography #fintech
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
-
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration