home.social

#quantumsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #quantumsecurity, aggregated by home.social.

fetched live
  1. It is often said in quantum security discussions that Grover's algorithm attacks symmetric-key cryptography by halving the effective keysize of symmetric ciphers, or halving the length of hashes in terms of security. This claim is wrong, but it's so rooted in common discourse that it has become extremely difficult to disentangle from reality. Details:

    gagliardoni.net/#20260820_grov

    AES-128 and 256-bit hashes are totally fine against quantum attacks. Here is a quick smell test to evaluate the maturity of your commercial quantum migration / CBOM scanner solution: does it flag AES-128 as a risk finding? If so, the vendor is not well-informed about quantum risk.

    #cryptography #pqc #quantum #crypto #security #infosec #quantumsecurity

  2. @filippo I cannot believe I missed this beautiful quote of yours, THANKS for this. From your blog post at words.filippo.io/crqc-timeline/

    I also complained similarly before: gagliardoni.net/#20250714_ludd

    Subscribed to your RSS feed ❤️

    #cryptography #quantum #pqc #quantumsecurity #luddism #crypto #security #infosec

  3. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity

  4. Every technique used in the various July AI hacking incidents has a known defense. Weak passwords. Unauthenticated endpoints. SQL injection. Unmonitored east-west traffic. Two of three organizations Anthropic's models compromised didn't even detect it.

    This is not an AI problem. It is a cybersecurity basics problem exposed at machine speed.

    Vendors are already starting to market "AI-resilient" infrastructure and "Mythos-resistant" cryptography. Do not buy the label. The correct response to faster attacks is faster defense, not a different kind of defense. Shorter patching windows. Better credential rotation. Tighter segmentation. Automated rollout.

    The one actually new investment: crypto-agility. In the same week OpenAI and Anthropic disclosed their hacking incidents, Anthropic's AI killed a PQC candidate that had survived years of NIST evaluation. 60 hours. $100K. HAWK was withdrawn the next day.

    AI is now also attacking mathematical layer of your defenses. And the upcoming quantum threat is defeating the mathematical layer. The shared defense is the ability to swap cryptographic algorithms without rebuilding your stack.

    Do good cybersecurity. Do it better. Do it faster. Build crypto-agility into the architecture.

    postquantum.com/ai-security/ai

    #cybersecurity #CISO #AIhacking #cryptoagility #PQC #postquantum #infosec #AI #quantumsecurity

  5. The quantum industry has a credibility problem, and announcements like this one from EY make it worse. EY says it installed a quantum computer in Toronto for "optimization, fraud detection, data protection and large-scale risk management." No vendor named. No qubit count. No specifications. I reached out to EY's media contact and CTO - no response.

    One journalist got them to confirm it's photonic.

    Here's the problem: no photonic quantum computer on Earth can do optimization, fraud detection, or risk management. Not Xanadu's. Not ORCA's. Not anyone's. The photonic modality has the largest gap to useful computation of any quantum platform I track in my CRQC Scorecard.

    Buying a quantum computer before they're useful? Actually smart. I wrote many posts defending exactly that logic. Procurement cycles are long. Talent is scarce. Institutional learning takes time.

    But describing a research-grade photonic prototype as a machine for "processing highly sensitive workloads" in fraud detection and risk management? That's the kind of claim that makes tech execs roll their eyes at the entire quantum industry.

    Joe Depa told Accounting Today the real focus is readiness and PQC. That's honest and a praiseworthy initiative. If that's what EY said, I'd congratulate them. The press release says something else. The gap between the two is the problem.

    My full analysis, including two plausible vendors, what they can actually build, and what to watch for on August 5: postquantum.com/industry-news/

    #QuantumComputing #PostQuantum #PQC #PhotonicQuantum #QuantumSecurity #CyberSecurity #BigFour #EY #CISO

  6. Today Letsencrypt announced their plans for PQC migration and, oh boy, it's refreshing! TL;DR, Letsencrypt considers migration to quantum-resistant certificates a priority, and lays down a reasonable path to migrate. In so doing, they take the time to explain how, so far, the security community has been mainly focused on the problem of quantum-resistant secrecy (encryption) rather than authentication (signatures/certificates), and they explain why the sentiment is changing now, and why it is particularly relevant for Letsencrypt.

    letsencrypt.org/2026/06/03/pq-

    Not wanting to be the "told you so" guy, I've been saying this for at least 2 years now:

    gagliardoni.net/#20260603_hndl

    This is not to say that Harvest-Now-Decrypt-Later is a less urgent threat, but it's not as asymmetric as people have been believing so far. Glad to see things are changing!

    #cryptography #crypto #security #quantum #pqc #postquantum #quantumsecurity #letsencrypt #ai

  7. Написал с соавтором статью в РБК про квантовую криптографию: «Зачем нам сегодня квантово-устойчивая кибербезопасность»

    Квантовые компьютеры меняют картину киберрисков: алгоритмы шифрования теряют запас прочности, а значит, готовить IT-инфраструктуру к постквантовому переходу нужно уже сейчаc
    trends.rbc.ru/trends/innovatio

    @rf
    @rur
    @russian_mastodon
    @Russia

    #cryptography #encryption #quantumsecurity #postquantum

  8. Google set a hard 2029 target for PQC migration — a year ahead of NIST deprecation, while simultaneously targeting a million-qubit machine on the same timeline.

    Buried in the post: they "adjusted" their threat model to prioritize signatures over key exchange. Something I argued for since 2018.

    Full write up: postquantum.com/security-pqc/g

    #infosec #pqc #quantum #cryptography #postquantum #quantumsecurity

  9. New PNAS paper claims quantum computers max out at ~1,000 qubits. It's already being used to delay PQC migration.

    Problem: the latest ECC attack estimate needs just 1,193 qubits. RSA-2048 needs 1,399. Both falling fast.

    Even if the ceiling is real, it doesn't save you.

    #PQC #QuantumSecurity #QuantumReady

    postquantum.com/quantum-resear

  10. PQC migration is a program, not a patch. I just updated my quantum readiness starting list - curated for security people who need actionable info.

    Takes you from threat understanding → prioritization → running a real migration program with owners, milestones, dependencies, and vendor timelines.

    postquantum.com/quantum-readin

    #PQC #PostQuantumCryptography #InfoSec #CryptoAgility #QuantumSecurity

  11. “Cybersecurity Apocalypse in 2026” is back - now tied to the Jesse–Victor–Gharabaghi (JVG) algorithm preprint.

    I published a technical reality check: postquantum.com/security-pqc/c

    My take: another day, another (very) unfounded quantum cyber‑apocalypse claim.

    #quantum #quantumsecurity #pqc

  12. Google is fixing a big problem that most people don't realize we have. Our current encryption relies on math that quantum computers will eventually break, very easily. To prevent future hackers from reading today's data, Google is deploying post-quantum cryptography within HTTPS certificates.

    This change uses the ML-KEM algorithm to protect connections. By changing how keys work, Google protects your private information before quantum computers can access it. Security is about winning the race against a threat that does not exist yet. 🔐

    🧠 Google is using ML-KEM to protect HTTPS certificates from future quantum attacks.
    ⚡ Engineers use hybrid key exchanges to maintain compatibility with older systems.
    🎓 Post-quantum cryptography protects data stolen today from being read in a decade.
    🔍 The shift helps define new global standards for internet privacy.

    arstechnica.com/security/2026/
    #QuantumSecurity #Google #Encryption #security #privacy #cloud #infosec #cybersecurity

  13. Citi Institute warns quantum computers could break public-key crypto within a decade - a trillion-dollar, national-security risk. Q-Day is real: boards must prioritize quantum-safe defenses. Read: postquantum.com/security-pqc/c #QuantumSecurity

  14. New peer‑reviewed study (Computers, MDPI) by Robert Campbell finds enterprise migration to post‑quantum cryptography will take years — ~5–7y (small), 8–12y (medium), 12–15+y (large). It’s an ecosystem-wide transformation. Start preparing: postquantum.com/security-pqc/e #PQC #QuantumSecurity

  15. USTC (Lu, Yang, Wang, Bao & Jian‑Wei Pan) publish in Science: device‑independent QKD over 11 km of fiber with full finite‑key security, and positive asymptotic key rates to 100 km — a ~3,000× range jump since 2022. DI‑QKD at metropolitan scales. Read: postquantum.com/security-pqc/c #QuantumSecurity #QKD

  16. No — Pinnacle Architecture doesn’t make Q‑Day imminent. It’s a credible design that could factor RSA‑2048 with <100k physical qubits, but only under tight assumptions (p_err=1e‑3, 1µs code cycle, 10µs reaction). If those hold, it could shave years off forecasts. Read: postquantum.com/security-pqc/p #PQC #QuantumSecurity

  17. Too many Q-Day predictions are “by vibes.” I’ve updated my CRQC Capability Framework - the evidence-based method used by national security analysts for years.

    If you want to track Q-Day properly - QEC, connectivity, magic states, decoders, manufacturability - not hype, start here: postquantum.com/post-quantum/c

    #QDay #Y2Q #QuantumSecurity #PQC #CRQC

  18. My blog PostQuantum.com just went over 1M unique visitors in 30 days. 37K in the last day.

    The message is clear: Quantum security is no longer niche - and people are trying to cut through the hype, confusion, and pseudo-expert noise.

    If you need well-researched, cited guidance: postquantum.com

    #QuantumSecurity #PQC #PostQuantum #QuantumReadiness

  19. U.S. advisory panel urges a “Quantum First” national goal by 2030 — accelerate quantum computing, communications and post-quantum security to secure advantage in cryptography, drug discovery and materials science. Read more: postquantum.com/quantum-policy #Quantum #QuantumSecurity

  20. China's 'photonic quantum chip' is impressive - but it's not a general-purpose quantum computer. Media hype fuels "quantum-washing" and public confusion. Read why this matters for tech and security: postquantum.com/industry-news/ #QuantumSecurity #QuantumComputing

  21. 2030 is closer than you think – some experts predict that could be Q-Day (quantum code-breaking day). The EU, US, and others are already moving target dates up to around 2030 for critical systems to be quantum-safe. Meanwhile, an ISACA poll found only 5% of orgs have a quantum plan. Time to kick procrastination to the curb and treat this with urgency! #QuantumSecurity postquantum.com/post-quantum/q

  22. Quantum computing is being called the “skeleton key” of the digital world – a master key that could unlock nearly all of today’s encrypted data. In other words, a sufficiently powerful quantum computer poses a universal cyber threat more serious than anything before. Boards and CEOs can’t afford to ignore this. #QuantumSecurity #PQC postquantum.com/post-quantum/q

  23. Quantum computing is being called the “skeleton key” of the digital world – a master key that could unlock nearly all of today’s encrypted data. In other words, a sufficiently powerful quantum computer poses a universal cyber threat more serious than anything before. Boards and CEOs can’t afford to ignore this. #QuantumSecurity #PQC postquantum.com/post-quantum/q

  24. Unlike Y2K, Q-Day (the day quantum computers break our crypto) won’t be a dramatic midnight event. On Q-Day, everything will appear normal – websites still load, transactions still go through – but the invisible security layer will have crumbled. This article paints the scenario: the morning after Q-Day. It’s a quiet crisis: no immediate crashes, but a fundamental pillar of digital trust is gone. #QuantumSecurity postquantum.com/post-quantum/q

  25. “Whoever develops quantum computing first will have palpable military advantages”  – that quote sums it up. The allure of being able to crack any encryption (think reading adversaries’ secret comms) has nations racing to both build quantum computers and also upgrade their own crypto (#PQC) before someone else’s quantum machine can undermine their security. It’s an arms race where qubits are the warheads... #QuantumSecurity postquantum.com/quantum-comput