#pqc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pqc, aggregated by home.social.
-
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
"AI compresses PQC migration from 15 years to four." This is being repeated these days. I disagree. AI accelerates the analysis phase. The deployment phase :vendor schedules, HSM procurement, firmware upgrades, certificate rotation in production; is organizational, not computational.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
-
US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.
For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.
https://postquantum.com/post-quantum/pqc-standards-fragmentation-multinationals/
-
US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.
For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.
https://postquantum.com/post-quantum/pqc-standards-fragmentation-multinationals/
-
US mandates ML-KEM/ML-DSA. China building its own suite. France requires hybrid. India adds Preferential Market Access gates.
For any org operating cross-border, PQC compliance is a matrix: diverging algorithms, conflicting hybrid requirements, incompatible certification regimes. One config won't cover it.
https://postquantum.com/post-quantum/pqc-standards-fragmentation-multinationals/
-
Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.
Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.
https://postquantum.com/post-quantum/crypto-agility-architecture/
-
Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.
Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.
https://postquantum.com/post-quantum/crypto-agility-architecture/
-
Every PQC guide says "be crypto-agile." After leading Fortune Global 500 migrations: HSMs can't upgrade, protocols hard-code ciphers, cert chains assume fixed key sizes.
Real crypto-agility needs abstraction layers, algorithm negotiation, and swappable primitives. Most stacks have none.
https://postquantum.com/post-quantum/crypto-agility-architecture/
-
PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.
Largest Shor's factoring demo on real hardware: the number 21.
The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.
https://postquantum.com/post-quantum/no-broken-rsa-2048-4096/
-
PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.
Largest Shor's factoring demo on real hardware: the number 21.
The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.
https://postquantum.com/post-quantum/no-broken-rsa-2048-4096/
-
PQC vendors are telling CISOs that RSA-2048 has been secretly broken. It hasn't.
Largest Shor's factoring demo on real hardware: the number 21.
The PQC case is strong without fabricated claims. Vendors who lie erode the credibility everyone depends on.
https://postquantum.com/post-quantum/no-broken-rsa-2048-4096/
-
CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.
If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:
-
CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.
If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:
-
CNSA 2.0 is the most operationally specific PQC mandate in the world: algorithm selections, timelines, and enforcement for National Security Systems.
If you sell into classified environments or your supply chain does, this applies to you. The vendor-neutral reference:
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
My team is looking for a US-based person to work on making #PQC #SmartCards work with open source software. Says Raleigh, but remote will be considered when nobody can be found locally, which is likely:
#Crypto #cryptography #GetFediHired #FediHire
Note: don't complain to me if company decides to cancel the position in three days for reasons I don't understand.
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments: https://news.ycombinator.com/item?id=48994116
#HackerNews #France #Anssi #PQC #Cybersecurity #Certification #2027 #PostQuantum
-
Q-FUD (Quantum Fear, Uncertainty, and Doubt) is an industry. Inflated timelines to sell products. Repackaged NIST guidelines as proprietary frameworks. "Quantum apocalypse" headlines for clicks. CISOs left making decisions with information designed to prevent rational decisions.
The field guide to manufactured urgency:
https://postquantum.com/post-quantum/q-fud-the-quantum-panic-industry/
-
Q-FUD (Quantum Fear, Uncertainty, and Doubt) is an industry. Inflated timelines to sell products. Repackaged NIST guidelines as proprietary frameworks. "Quantum apocalypse" headlines for clicks. CISOs left making decisions with information designed to prevent rational decisions.
The field guide to manufactured urgency:
https://postquantum.com/post-quantum/q-fud-the-quantum-panic-industry/
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
El lado del mal - III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026 https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html #Quantum #PostQuantum #Criptografia #Seguridad #PQC #QKD #Cuántica
-
"Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.
EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.
Europe didn't pick a protocol winner. It's building a portfolio.
So why does CV-QKD get disproportionate strategic attention? Supply chain.
DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.
Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).
CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.
QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.
Now here's what makes it more complicated than a clean sovereignty narrative.
China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.
Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.
The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.
This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.
For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.
Full analysis: https://postquantum.com/post-quantum/europe-cv-qkd-industrialisation/
#infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI
-
"Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.
EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.
Europe didn't pick a protocol winner. It's building a portfolio.
So why does CV-QKD get disproportionate strategic attention? Supply chain.
DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.
Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).
CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.
QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.
Now here's what makes it more complicated than a clean sovereignty narrative.
China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.
Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.
The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.
This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.
For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.
Full analysis: https://postquantum.com/post-quantum/europe-cv-qkd-industrialisation/
#infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI
-
"Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.
EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.
Europe didn't pick a protocol winner. It's building a portfolio.
So why does CV-QKD get disproportionate strategic attention? Supply chain.
DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.
Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).
CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.
QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.
Now here's what makes it more complicated than a clean sovereignty narrative.
China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.
Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.
The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.
This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.
For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.
Full analysis: https://postquantum.com/post-quantum/europe-cv-qkd-industrialisation/
#infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
New ECDLP resource estimate: 835 logical qubits for secp256k1, the lowest published figure for a 256-bit ECC curve. The paper (arXiv:2607.13816) supersedes the same team's April preprint at 1,333.
The tradeoff matters for threat modeling: this circuit uses ~20x more Toffoli gates than the Babbush (Google) and Schrottenloher alternatives. Fewer qubits = narrower machine. More gates = longer computation = harder to keep fault-tolerant. The paper provides no depth analysis and lists it as an open question. Whether 835 qubits with 1.7B Toffoli gates is cheaper to build and operate than 1,175 qubits with 80M gates is not answered.
Craig Gidney (Google) noted the gate count was ~100x better than he expected, and that the authors used exact (non-approximate) circuits. Approximate arithmetic would likely compress the gates further.
For PQC migration planning: this confirms the algorithmic track for ECDLP-256 is maturing. The uncertainty in when ECC breaks sits on the hardware/QEC side. Your migration schedule should be set by CNSA 2.0 deadlines and data lifetimes, not by these estimates.
Corrected comparison table and full analysis (the paper's abstract carries a stale Chevignard number): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
#infosec #cybersecurity #PQC #postquantum #quantum #cryptography #ECC #Bitcoin
-
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
The transition to #PQC must become a top priority on IT infrastructure roadmaps.
https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge -
Is AES safe from Grover's? Yes, for now. Resource requirements are astronomical under current architectures. But "Grover is dead" overstates it. The three pillars (surface-code overhead, slow logical gates, current QEC) are all under assault by qLDPC codes and photonic architectures. So don't prioritize it, but monitor it over coming years.
https://postquantum.com/post-quantum/grover-algorithm-aes-dead/