The Clock is Ticking on Quantum Resilience: Dr. Michele Mosca from evolutionQ on Navigating the Post-Quantum Horizon
Transcript
Hey everyone. Welcome back here to Techstrong tv. You know, last week we, we had a, a moment here at Techstrong where in partnership with our good friends at DigiCert, we released the initial Quantum Security 25 list.
And we hope to make this a, a, uh, annual list over the next years. And it, it really was aimed at, at two things as I was telling my next guest off, off camera number one, to shine a light on the whole quantum quantum security field right now, right? For too long, we, we have kind of been kicking the can down the road when it comes to covering quantum saying, yeah, it's three to five years out.
It's three. Oh, yeah. Won't it be great when it finally comes, it's three to five years out.
Well, my friends, I'm here to tell you the good news. You know, I don't know if it's three to five years out anymore. I think it's a lot more on the horizon and there's real quantum or post quantum security work being done now, as I think you're going to hear number two, you know, every movement needs its leaders.
And we, and we wanted to identify, some may say it's early, some not, but we wanted to identify 25 individuals who are, um, have established themselves as leaders in this quantum security space. With that, let me introduce you to my next guest. He is one of these 25 established leaders in this space.
His name is Dr. Kel Kelley Moscow. I hope I got it right.
It's Italian from Michael. Dr. Mosco, welcome to Text Drunk tv.
It's great to have you on here. Thanks, Alan. It's great to be here.
Alright, so obviously it's doctor you, I assume it's PhD. Um, you are the co-founder, president and CEO of a company called Evolution Q. But beyond, beyond the headline right?
Give people a little bit of your backstory. My backstory, I mean, we can go way back, you know, grew up on a farm, but I, you know, I was good at mathematics and so when I, I Would imagine that helped. Yeah, yeah, yeah.
Um, when I was studying mathematics at Waterloo in the, in the nineties, some of my, uh, mentors and academic advisors, they happened to be taking, uh, public key cryptography from an idea on a blackboard into a globally deployed standard. I really had no understanding what that really meant, but the math was fun, and I got to work with them on really testing the assumptions of our cryptography, how we were gonna secure the internet. 'cause it's secure as long as certain math problems are hard.
So, of course, we're like, well, let's break these math problems. Right? So I started off sort of as a code breaker, and that was fun.
And then I, I got into Oxford to do some more, you know, the mathematical studies underlying information security. And then I met, I kept hearing about this quantum computing thing, and I thought it was dumb. And then I thought it was like ridiculous and I really didn't wanna waste my time on it, but my advisor forced me to meet one of the pioneers of quantum information, actually.
Then I realized, okay, they're not completely crazy. You know, this will eventually work, and I like how you're describing it's three to five years away. 'cause a good lead metric, I think is, we used to talk about quantum computing as being 20 to 50 years away, and then it's always 10 to 20 years away.
Well, which one is it? You know? And now it's three to five years away, so obviously, you know, things are heating up.
But I, so by serendipity in the nineties, I found myself at the interface of, you know, cryptography, which is part of cybersecurity, a fundamental pillar of securing the digital economy and this new quantum computing thing. And I was one of the few translators between those two communities. And I was studying the power of quantum computing.
So I had a lot of fun doing the fundamental mathematics underlying enabling quantum computers using them and protecting against them. Uh, and then I was recruited, uh, back to Canada to help start a quantum center within a cryptography, uh, group, and grew that into one of the largest, but a flagship quantum computing institutes that does foundations, applications and implementations of quantum information processing. But always kind of true to my roots in cryptography and cybersecurity, which in the nineties was really honestly a niche.
Like who cared about code, you know, breaking in the nineties. Mm-hmm. But, you know, over the next 30 years, it's now a fundamental pillar of the global economy.
Uh, so I found myself constantly, you know, translating between these communities and telling people you need, you know, what I knew is it takes decades, two to three decades to prepare new cryptography to be ready for showtime. So even 20 years away was not, was barely, it was cutting it close, right? But now, indeed, I think we're five to 10 years away with high likelihood.
So fortunately there's many people who, uh, you know, it was part of a rogue effort really to get ready for this guera at a time when nobody really, everyone thought it was ridiculous waste of time. Uh, and fortunately we spent a few decades preparing so that by 2015 when the NSA and the United States and others said, no, we really gotta get ready for this as soon as possible. Fortunately, we had a couple decades or more of hard thankless work to build on.
Uh, and we're still working hard to get ready in time. Uh, but fortunately we had those, you know, extra years of, of preparation, uh, in advance. I love it.
You know, uh, the good folks at IBM are basically on a quantum by 28 or 29 or bus kind of thing. Right. They, they've committed to delivering.
Yeah. By that, I see you are being conservative, let's say. Um, well, I think I, being realistic, right?
And you have to manage the tail distributions, right? And in cybersecurity mm-hmm. It's the one tail.
Like what if there are, what if, what if they are cryptographically relevant by 2031 or whatever? Uh, and, and you know, you still have to, some people have to manage the other tail. And because you're betting on these computers, you know, creating extra value for your company by a certain date, well, what if the, what if it's five years later?
Right? That's actually an easier tail to manage. Whereas if you're not ready for a cryptographic zero day, you have a business continuity problem, right.
Let alone all the old secrets. Um, and that's sort of part of the core of the so-called musket equation that tried to remind people you can't wait till the threat is at the doorstep if it takes you two years to prepare. If it takes 10 years to prepare, you better start 10 years before good luck.
'cause we don't know when that day is. So I really create a lot of uncertainty. So you have to also factor in your risk tolerance.
And if, if you have long-term secrets, you gotta start even earlier. So, you know, and, and I certainly, I have no doubt, might colleagues at IBM will deliver on, on continue to deliver on these amazing platforms. I don't think they're promising cryptographic relevance in three years, but I think they're promising, you know, something far beyond what we currently have and, and, and, uh, potentially business useful in, in a small number of years.
And cryptographic relevance, well, code breaking relevance will come in under 10 years is, is I think what they're very confident in. And there's a number of other players who are similarly confident. Hmm.
Let's, let's segue going into evolution Q, what's that about? Yeah, so, you know, with my academic career and so on, I was really good at telling other people what they had to do. And, and they, you know, and they usually ignored it, but occasionally you'd get people saying, you know what?
You, I think you have a point. We need to, we need to do something. And it was all prepara.
Oh, like all about risk management, ultimately. Like, don't stop everything else you're doing, but you gotta invest a little bit. End up being ready, right?
You can't only do firefighting. There has to be a little bit of fire prevention, but the fires will become unmanageable. And occasionally I'd get some people saying, you know what?
You're right. What should I do? Uh, and you know, that prompted me, for example, 15 years ago to start an open source platform for post quantum algorithms.
'cause I had the first company saying, you know, you're right. Our clients do want their information to be secure long term. What should I do?
And I hadn't, I wasn't ready for somebody to actually believe me and want to act on it. Uh, yeah, I was mentally ready. But I realized, well, you know what?
You don't have the platforms, uh, for, for doing that. So I started an open source platform. Um, another, you know what happened?
Probably what drove me to start the company is I've been doing consulting for industry and government since the nineties, is the CIO of Canada asked to meet her in Ottawa. So I went, I didn't really know what she was gonna ask me. And she said, look, I know who you are.
I know what you've done. What should I do? I was like, well, well, I start asking her some questions and I said, okay, so my team is gonna come together with your team and we're gonna do this, this, uh, pilot.
We just discussed a, a short term thing. 'cause I wasn't looking for some never ending consulting gig. I really wanted to get to the point, to the heart of the matter and be able to, you know, create resilience for the Canadian government.
So then I had to, when I left her office, I said, now I have to build that team. So I started going to a meeting. I've been engaging in the industry for decades.
So I had friends and started putting together a team to offer professional services, tell people understand, but what does this quantum threat mean to me? What should I do about it? What's my roadmap?
And it was about, we wanted to build products, but we needed to know what products people really needed, right? And a lot of things they needed, there's other people better suited to deliver, right? So we wanted to get the ecosystem moving in that direction early, while there's still time before it's a panic.
And about 2020, we realized the product gap, which is really about enabling scalable cryptographic resilience. And that was really exciting. And so we, we've been developing the software frameworks, not just the framework, the actual tools which are deployed all around the world to enable scalable cryptographic resilience.
That's really what evolution Q's all about. You know, very pragmatically managing your cyber, your cryptographic risk, bringing it down to an acceptable level by enabling scalable software solutions. I love it.
Yeah. You know, In in, in this field, you know, security's usually a laggard, right? Not, not in in this field, or I mean in general, right?
Security even like in AI right now, right? We're seeing security usual, and it's usual place in the caboose of the train, right? We're running as fast as we can.
And then someone says, oh, what about, what about securing it? Is this secure? Yeah.
Um, with Quantum. And one of the things that I think I like about what's going on there is security seems to be out front and center, right? Some of the biggest breakthroughs, some of the most real technology that we're seeing right now is around quantum cryptography, or let's call it post quantum cryptography, around quantum proof algorithms, right?
As you mentioned, they didn't say NIST Mitre, they got out ahead, they partnered with, with industry. And we've had post quantum algorithms available for, you know, some of our digital certificates and stuff now for a little while. And, and by the time Q day does come, you know, we, we, we, there's no excuse why we shouldn't be prepared from a security point of view.
That's, that's refreshing, right? I mean, that, that's not the usual, as you probably know. Yeah.
So there's hope for humanity, right? Uh, yeah. And I think maybe, I think, you know, this is, you know, we shouldn't be bitter about this fact 'cause it's been like that for millennia.
It's part of human nature. Uh, but we do need to get smarter about how we subvert the usual market forces. How we internalize, 'cause this is real, like these, these expected losses due to not being ready for emerging threats.
That's real economically real. But it's not in our short term calculus in most cases. So how do you internalize that?
So we properly manage those risks. We don't over invest. 'cause we have a lot of other things we need to be protecting against and, and seizing opportunities.
But if we underinvest, then obviously it could be an unrecoverable event. So what's different over the last many millennia is the hyper concentration and this hyperscale when weaponized means, you know, a hyper problem, right? And you have to, you can't wait for the problems to start and say, oh, this is bad.
'cause they're not gonna be slow and incremental. It could be a rapid game over event. So you do have to architect for resilience versus just security gets what, you know, and we've been doing it like MFA, that's essentially a defense in depth approach, realizing we're not gonna make passwords perfect.
We're not gonna make humans smarter. Like, we're not gonna get, you know, one layer of defense isn't gonna be enough. We have to be ready for an unexpected break.
It'll be bad, but we'll detect, recover, and move on. So we've done this like we know how to create resilience, right? Through diversity, you know, defense in depth and agility even in non-technical domains.
But obviously in cryptography it's the same thing, right? So how do you create that market pull for what we know we need? Well, step one is awareness, right?
And that's what a few souls and then, and many of them are on your, your, uh, our D list. So it's been a pleasure to, to work with them over the last few decades and to create the awareness. That's what the whole mosque inequ is about, is a really simple way of articulating this risk and then making it easier.
How do you, how, how do I make it easier for people to take actions, uh, both in terms of knowing what actions to take and then technologically making it easier. That's why we did the open source, which is now part of this effort involving Mitre and others that you mentioned. Um, and now, you know, slowly the, the, the, the incentives are, are occurring with, uh, the guidance.
You know, the NSA announcements and the crypto logic authorities standards bodies, that further reduces the friction and increases the impetus. 'cause of course, people don't change their behavior 'cause they see the light, they change their behavior 'cause they feel the heat. So, you know, the regulatory framework's either here or coming.
Now, this is a board level issue, right? So maybe we do need to get ahead of it. So I'm hoping, so first of all, this is a blessing in disguise.
This quantum threat is not a bad thing. It would, it was without it, we, we could be, we'd be in a much more precarious situation because normally zero days don't get announced 30, 40 years in advance, right? So it really shined a light on this fragility in our digital economy that there have been people like me saying, Hey, there's this fragility and nobody would've cared.
But because quantum is a real thing, slow moving, but real, it forced us to address this agil fragility, and we have a fighting chance to create, you know, a resilient cryptographic foundation. Uh, if again, if it weren't for the quantum threat announced decades in advance, this fragility would be baked in even deeper and deeper and deeper to the point where we really have no chance of recovering from it. So I think it's a blessing and disguise in terms of enabling cryptographic resilience.
But it's also a wake up call. Where are the other fragilities like this one where we're kind of all letting the short term market forces get the better of us, right? And we're seeing it obviously with supply chains, with critical minerals.
Like that was an own goal, right? And there's other own goals like that. What are the other ones where, you know, can we, can we borrow from the quantum safe playbook?
Like how did these quantum safe people get ahead of this? Right? And, and have some other, you know, examples where we can create resilience where we currently are living with fragility.
Agreed. Excellent. Excellent.
Dr. Mosco, as I said, it's a 15 minute interview. We're, we're probably a little overtime already, but let me ask for people who maybe wanna follow you, follow what's going on at Evolution q follow this space, right?
Yeah. Because the, the space is still new enough where, you know, when I first got on the web, you were in school, you know, Yahoo was a gray page. I never view it was gray and it had Yahoo and purple and, and it was a couple of pages.
There wasn't that, there weren't that many websites, you know what I mean? And, uh, I I we're almost at that stage here, when we look at Quantum, we could still keep a, you could still keep your thumb on the pulse. How would you recommend people do that though?
Well, there's obviously you can follow Evolution Q on LinkedIn, uh, and so on. Uh, and the other, you know, there's a few fora where I think there's really credible, uh, authoritative guidance at different technical levels. There's the, the Canadian Forum for Digital Infrastructure Resilience, quantum Readiness Working Group.
Mm-hmm. It's a mouthful, but if you search it up, you'll see every year we've been for the last five, six years publishing best practices. FS IAC does nice work, uh, publishing best practices, uh, and, and the Canadian, uh, sorry, the, the Quantum Safe Financial Forum led by Europol, uh, and Pro provides some, this is, these are many different stakeholders coming together and articulating some useful new guidance and, and findings.
So there's like, there's examples like that, which I think can provide a different array, uh, of trusted guidance. And they're not trying to sell you anything. You do need to buy stuff, but I mean, so, but so there's many other, you know, credible vendors out there as well.
But the three examples I just gave are, are sort, kind of team efforts across the globe. Um, so those are some examples of where to get some good, trusted guidance. I love it.
Listen, congratulations on being a member of the inaugural, uh, quantum 25 Quantum Security 25 list. Um, through the year, we're gonna tap back in and, and hear what's going on and kind of get your views. We're working on a, uh, a steady kind of updates here with the 25 people so that hopefully we can become a resource from a tech media perspective.
We're not a government agency or a vendor selling anything, quite frankly, but we, we do think as the audience and community for this to Dev develops, we'd like to be a, a place people can come and gather and, you know, read information from all across the world. So we'll be in touch with you again. Congratulations Dr.
Kel. Kel Mosca. Yes.
Did I say it right? Yeah. Perfect.
Yeah. Thanks Dr. Kel Mosca.
Thanks for doing this. 'cause that's, you know, like I said, awareness is really a critical piece and, and recognizing a lot people who've honestly done a lot of the thankless work is, is really, uh, valuable. So, uh, thanks for your important contribution here.
Thank, thank you. Alright, we're gonna take a break on text trunk ga uh, text trunk tv. We'll be back here in just a moment.
Bit.