29. You Don’t Need Post-Quantum Crypto Yet – Tech Field Day Podcast
With the advent of quantum computers, the likelihood that modern encryption is going to be invalidated is a possibility. New standards from NIST have arrived that have ushered in the post-quantum era. You don’t need to implement them yet but you need to be familiar with them. Tom Hollingsworth is joined by Jennifer Minella, Andrew Conry-Murray, and Alastair Cooke in this episode to discuss why post-quantum algorithms are needed, why you should be readying your enterprise to use them, and how best to plan your implementation strategy.
Transcript
Encryption is something that everyone knows they need, and it's only a matter of time before someone figures out how to crack it. And the coming wave of quantum computing means that we could face an Armageddon when it comes to all of the encrypted data that we've been using for the last decades. However, a new algorithm is on the horizon that would allow us to live in a post quantum world.
But is it something you need to worry about today? In this episode of the Tech Field Day podcast, we postulate that post quantum and crypto is not something you need right now. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry.
This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded and associated with, with one of our events. Tech Field Day is a part of the Futurum Group, and this podcast is also published on our sister company Site Techstrong tv. On this episode, we're headed into security field Day, and I'd like to take a moment for our delegates to introduce themselves before we jump into the topic starting with jj.
Hey everybody, it's Jennifer Manila, jj, um, security and Infrastructure specialist. I Analyst Cook. I'm a data center infrastructure and cloud guy, and now a part of the Tick Field Day team.
Hi, I am Drew Connery Murray. Uh, I'm with the packet pushers. I've been covering the IT and security spaces for a long time as a, as an analyst and reporter.
Well, thank you all very much for joining us. Of course. I am Tom Hollingsworth.
I'm a practice lead and event lead here at Tech Field Day, part of the Futurum Group. Let's jump into the premise for today's episode. If you are a huge fan like I am of the Seminole 1990s work sneakers, you've probably seen what happens whenever encryption is no longer valid for anybody.
Maybe it's a little black box and an answering machine. An answering machine, of course, was a thing that we used to answer the phone before voicemail happened, and it can immediately decrypt everything. Well, how likely is this science fiction concept?
It turns out it's actually more common than you might think, to the point where the United States government has actually introduced legislation recently to force our National Institute of Standards and Technology, NIST, to adopt post quantum crypto. But the premise for this episode is you don't need post quantum crypto yet. All right, I'm gonna open up by kind of throwing this out to the floor.
What is it about current encryption? That means we need to have some kind of a post encryption in order to avoid having Robert Redford to read my emails. So my understanding is that, uh, with the rise of, um, quantum computers, uh, they are very good at, um, attacking the mechanisms we currently use today to develop our, the, the underlying mathematics of cryptography, which is basically multiplying two primes.
Um, quantum computers are very good at that. It's not a hard problem for them, uh, which is hard for more traditional, uh, computing. So the fact that quantum computers are, you know, still on the horizon becoming, uh, the encryption community and industry realized they needed to get out ahead of this, uh, so that, uh, when quantum computers are actually up and functioning, everything wasn't immediately able to be decrypted A plus.
Drew, you must have watched my episode of conversations about quantum computers as well as quantum resistant encryption, because I, that's exactly how I phrased it, is, uh, quantum computers are actually really awesome at solving and factoring prime numbers. And that's basically how RSA encryption works, right? Is that we have this huge product of two primes and we don't know how to get that product.
We, we get the, the factors of it easily, and that's why modern encryption works. That's why Bob and Alice can talk to each other. The problem is, is that when you have a computer that's strong enough and error corrected enough, you can solve that equation instantaneously and then immediately decrypt things.
Granted, there was a little Hollywood magic and like, you know, putting a little probe on the, the chip and all of a sudden everything just kind of floats down like the matrix. But, um, you know, that that's actually a pretty good way to put it. And NIST actually had to come up with ways to defeat that, that didn't use traditional encryption methodology.
Um, so I, I kinda wondered, does this mean that the sky is falling now and that we we have to switch everything tomorrow? So as I, uh, ha having a physics degree myself and having actually taken some quantum computing classes a very, very long time ago, um, it, it's interesting to me that, that what we see in quantum computing now is the ability to have a, a single qubit, the thing that does the actual math, um, take a set of inputs, generate a vast amount of possible answers, and then return the, the correct answer. Uh, the thing is though that qubits are really hard to build.
Uh, they require sort of super cooling, uh, situation and, uh, getting a computer with enough of them to do real work is the challenge at the moment. So it's that scalability of getting to the thousands of qubits that we're going to need if we want to break encryption. Hang on, I didn't want to break, but maybe if I'm a government agency, I do want to break encryption.
Um, to be clear, that's not what these computer systems, these quantum computers are being built for. They're being built because the same kind of math is great for doing things like, uh, forecasting financials and doing some material science working out which alloys of what metal to put together. So it's not that these things were designed for breaking crypto, they're just extremely good at it.
However, at this, this time, they're not sufficiently large in size to immediately break these, uh, these large key sizes that we're using in, in crypto at the moment. But of course, everything gets easier to build as you build more of them. And the size of these quantum computers has been growing over time.
The challenge is when they're widespread enough and sufficiently powerful to deal with the encryption keys that we can generate now, now we can always generate larger and larger encryption keys, but the rate at which the quantum computers grow, it's gonna be faster than we can handle those larger keys. So this is the, the driver for the, the post quantum encryption ideas. I, I love, I'm gonna give the flip side of this because Alistair's coming in with this lovely accent and the academic approach, and you've got the lovely mustache, the little handlebar thing going on there, you look so sophisticated.
Um, so I'm gonna lay on its credence to everything he says it does. I and I, and it's so true, but I'm gonna lay on like rural North Carolina on you for a second. And, uh, you know, the quantums, they just math real good and really all of our cryptography throughout all of time is just different math problems.
Anytime we break encryption, it's a math problem. So the more speed and intelligence we have in the platforms, the quicker we break it. And this is just an extreme case of a, a big jump in technology in that processing power.
But is this really any different than when Des was supposedly an uncrackable encryption protocol? And now I can basically reverse it in minutes because the, the math factoring works out for even 56 bit keys quickly. And, and, you know, technology is always gonna march on.
Like I can remember, you know, thinking about what it would take to brute force a password back in the day, and it's like, oh yeah, this could take years for you to factor it out. Well, at a big enough scale, cloud computing, for example, I can factor that password very quickly because I have what amounts to unlimited resources for a short period of time. How is using cloud computing to, you know, basically run John the ripper to get into my email different than the kind of math that we would do to get, you know, an RSA private key?
I'm looking, I'm looking at the academic down here waiting for something cool. Uh, yeah, the speed at which we've seen growth in compute power has followed Moore's law, right? So we're, we're looking at roughly doubling compute power over 18 months.
I think we might've seen a bit of a slowdown that's out to a whole two years for doubling. And that's what's killed the, the short key lengths and meant that if we doubled the key length, we can actually still do the encryption, right? We use shorter keys early on because it took a lot of compute power to do the encryption.
Uh, as we start needing longer keys, then we have to spend more compute time producing those longer keys and the cipher text from them. And so there's this arms race between the ability to attack the keys using large amounts of the same compute power that we are using to generate the keys. Uh, we're quantum comes in, is that we sidestep that whole arms race, that quantum functions in a completely different way and scales in a completely different way.
So if we're not using quantum to generate our keys, and I don't think anybody's talking about that yet, because you can't have quantum in your laptop yet in order to handle quantum keys. So quantum is that, that quantum leap, uh, and the ability to decrypt, to attack these, these keys that's not matched with an increasing ability to generate keys. So if we went to encryption keys that were a million bits long, we'd have longer before quantum could attack them, but not as much longer as quantum will will the, the rate at which quantum is gonna grow in its ability to attack.
Uh, but you run into a problem there, Mr. Cook, and that is physics, because if you make an encryption key, a million bits long, I still have to calculate that key. I still have to do the math on a modern computer.
And anyone who has ever accidentally typed in the wrong RSA key link on a Cisco router and watched it grind to a halt for 10 minutes because it's trying to calculate this is a hu you, you know exactly what that is. Like it, there's a math problem that even the best CPUs today have a hard time calculating through shortcuts. Now granted, once you've created that key, everything is, is copacetic, but like, that's like my, my fancy MacBook over here, right?
What happens when I try to do that on an IOT device? Like, like this is one of the problems that a lot of IOT manufacturers are starting to face, and it's actually something that I talked to, uh, Mike Nelson at DigiCert about several years ago. Your thermostat does not have enough horsepower to calculate a reasonable encryption key.
And, and that's with modern solved problems in this technology. Like once we get to p qc, like or post yeah, postcard crypto, that's, that's a bigger problem, right? Like I've seen the technical specs behind this.
There's like 3D latticework and like multi-stage equations and like, I can already see the smoke coming out of my machine trying to, trying to do this. Well, I mean, in the iot world, we have ECC, so we've got elliptic curve crypto, which is much shorter keys, it's a much lower, um, it's just less intense from a processing, um, perspective. So iot devices can do that.
But I think the other thing we're talking about like puke pu puke, puke, puke, p qc, uh, post quantum crypto, yep. Ian slip there. Um, you, it really, it's not something we're worried about with every type of device and every type of data, right?
You, we don't care if your thermostat data gets decrypted 10 years from now. But at the same time, I mean, we, we kind of face this problem now. We are there certain things that are okay to encrypt at a lower confidence level if you want to call it that.
Whereas there are certain things that you want to have, like when do I use triple dev versus AE 56 a ES 56, 2 56 Ev every, every algorithm paired with key link and all of the other things you go with crypto stuff has a certain shelf life, right? It's like a, it's like a rating on a, a safe for or, or a firewall or something like how long will this last? Because hopefully organizations that are, you know, mature and responsible and security conscious have, um, data retention policies and that data will have been destroyed digitally or physically before the shelf life of that encryption is met.
So yes, there's certain types of data that we worry about for longer periods of time. Things like financial data, government records, intellectual property, health, health records, things that people are keeping for a long period of time and need to stay private. I think, um, that echoes my feeling on it, jj, is that the cost of quantum attack against your cryptography is going to be very high for a long period of time.
And so the value of the data that I'm going to be able to retrieve through this quantum attack has to be very high. And it's that high value data that you have to protect more. And as you say, we've always been doing this, we've always chosen the level of, uh, effort for encryption that is gonna return us some value.
It's been really helpful to have offloads. So having the hardware based, uh, encryption in modern CPUs makes a huge difference to what we can encrypt and what we will see over time, and I'm talking quite a long time possibly my children's time, uh, is where the, the offloads are actually quantum offloads inside these, um, commodity equipment. That is definitely not a near future, that's a further out future, but it's, it's continuing that trend of we're gonna see more and more advanced technology available in smaller and smaller and more power efficient pack, uh, packaging.
It's one of the standard parts of, of the IT industry and particularly the, the hardware side of it that we see more capability. And, um, again, we'll, we'll go back to having an arms race where both sides are equal. Uh, when quantum, uh, attacks become practical, the arms race is gonna be unequal because the attacks are going to be much more, uh, rapidly scalable than our ability to protect scales.
So we're going to need to adopt something that is going to allow us to continue to compete with the, uh, the attack, uh, capabilities. Well, I think that's why it's important to note that I think NIST has released specifications for, uh, encryption algorithms that are resistant to the use of quantum computers, and they can be operated on the existing hardware that we have today. It doesn't require a quantum computer to use these algorithms.
And so we're getting an initial level of protection against attacks using a quantum computer to decrypt, uh, encrypted information by using these new algorithms. And one thing I wanna bring up here, uh, talking about NIST and this whole process to come up with, um, these now poorly named algorithms because they all got a, a government number instead of something cool like, you know, being named after crystals or something, was that they actually started this process fairly wide. I think they were, they started off doing something like 60 some different algorithms, and over the course of the last couple of years, they've actually narrowed them down quite a bit.
And one of the things that I thought was really fascinating was that one of the finalists that actually made it all the way through almost to the end, um, once people actually got a chance to test it and really dig into it, they found out that there was a shortcut that could have allowed it to basically be very insecure if it had been put into production because basically there was a mathematical shortcut that allowed people to kind of dump the key. And I think that this whole process of putting these things out there for people to test has really helped us understand how difficult of a problem this is to solve when you're trying to make something that's resistant to what is effectively a magical computer. So I mean, is this open sourcing, uh, testing of these things?
Is this the way that we should do it in the future? That's always how we do it. I mean, when, when we've had any type of, you know, cryptographic, crip, cryptographic algorithms like this, they are created and tested and peer reviewed by the community that that's how they get developed.
And, um, it, it's a lot of, you know, smart people and interesting work around that space. I mean, one of the things at the RSA conference they did, you know, 'cause it was really centered around cryptography for so long, um, you know, watching that process a little bit play out on stage, you know, probably, you know, back when it was much smaller more than 10 years ago. Um, but no, I mean that's how, that's how these things get developed.
So yeah, they start with a super wide funnel. I don't remember when they started this, but I'm guessing it's, you know, like probably at least eight years ago. And they just keep narrowing down and whittling it.
Um, and then, you know, as you narrow down, you have less of a pool for all of the rest, right? Every, the whole population is, is split when you have a funnel of let's call it a hundred or 200, but then when you get down to the final 10 or 20, all eyes are on those 10 or 20 and you get just a lot more rigidity in the testing. Putting my tinfoil hat on, I could, I, I assume that, you know, big governments around the world would love to have, um, you know, private development of, uh, encryption and decryption tools, uh, that they just keep to themselves.
But as, you know, a consumer or a user or an advisor or a buyer, I would put more trust in models that I know have been released to the public and looked at by the public and looked at by various groups as opposed to just, well, the NSA says it's fine, so it must be fine. You mean like the news story from last year where, uh, certain government agencies forced a backdoor into an ECC encryption algorithm and then forced a whole bunch of network companies to use it so that they could decrypt traffic. And then it turns out the people they were decrypting the traffic from turned it around and started decrypting their own traffic.
Not that that's happened before. Hopefully we've, we've learned, but you know, I, I think we won't, and we'll have to go through it again and again, but, uh, my money for the best security is the one that has the most eyes on it publicly. And and I, I do wanna bring up the fact for anybody watching this podcast who's rushing out to go download di lithium or, or kyber or whatever, whatever they call it now, um, we still have a a point that we need to hit in quantum computing where this becomes feasible.
Because one of the problems we have right now, um, you, you've probably seen some of the headlines, you know, of how many qubits Google has managed to, to ring out of a computer, which is impressive, right? But it's not just the throughput, it's the error correction because quantum computing produces a lot of noise. And until we're capable of creating error corrected findings, a lot of what we get back is just noise.
And so this whole completely invalidating RSA based encryption won't happen until the computers are, I think, what did I see, north of 50 qubits. But they have to have like a really amazing amount of error correction. And what that means effectively is money.
Like, like you're gonna have to invest millions upon millions of dollars into these things to be able to get them to the point where this can happen. Now, the flip side of that is, is that once that toothpaste is out of the tube, from that point forward, it's a problem. Uh, uh, you know, I I say that if, if you are a company that owns a quantum computer or a nation state that has a quantum computer with appropriate precision, then yes, you could probably decrypt all the things that other people are running.
But like, you know, when do you think that that's going to happen? Because, you know, as, as Al pointed out, this is a physics problem right now, eventually it'll become a money problem. Well, I, I mean, I think right now the, the focus isn't, or for most of us, right on, on enterprise organizations and architects who are worried about security, we're not focused on post, we're not fo focused on quantum computing.
We're thinking about post quantum crypto, which is how do we go ahead? 'cause we, these algorithms are available to us now. Products are starting to ship with them.
We've already seen 'em in browsers, we're seeing them in switch route firewalls, all of the network infrastructure things. I'm sure they're into the, you know, the clouds as well. And when we're talking about equipment and licensing that has sometimes 3, 5, 7, 10 year life cycles, we need to be asking our vendors at this point, what they're doing for PQC and going, going ahead and implementing that because it doesn't hurt anything.
It's available to us. It's not, it shouldn't be an added cost or added work. We need to just go ahead and do it, and then we don't have to worry about what happens in five, 10 years.
Yeah, there's, you know, a lot of mathematical rigor that goes into the development of these encryption algorithms. But often where you get strung up is, uh, on implementation. And so we wanna start getting, you know, doing those implementation reps now before it really matters and before it's high stakes, uh, so that we don't, we implement it correctly and learn how to do the key exchanges correctly and the negotiation correctly, and write the software around it correctly.
So that's not an emergency. When suddenly we find out, oh wait, X country has had a quantum computer for three years and they're shovel grabbing everything and decrypting it. We've got, it's an emergency.
Let's make our mistakes now while it's not an emergency, let's start getting familiar with these, uh, algorithms, figuring out how they work with everything else that we're doing, get them into our firewalls, our browsers, and so on. Now before it's an emergency, And I have to imagine all the various, you know, compliance regulations are gonna be mandating this anyway. So, you know, there's, there's P-C-I-D-S-S for payment card, there's HIPAA for certain types of health records.
Um, and then we have all, all of the different layers of things for other personal identifiable information and, and financial transactions. Um, you know, even just down to like the NIST suite, the NIST 800 suite that we use, you know, the federal government uses here in the us, you know, the 853, the civilians and all like universities like this is seeping down into our everyday lives in local municipal governments education of using these nist, you know, frameworks that are, that are starting to steer towards, right, the, the NIST standards for cryptography. So that's going to be coming, that will probably come sooner than the actual qu quantum computing in a lot of hands.
I think it is important to recognize though, that the quantum computing, uh, capability growth has been huge. And we've known that this was coming for some time. I think it was about six years ago I interviewed somebody who'd been working in quantum research, uh, at an event.
And at the time that we were talking about having, uh, the largest, uh, quantum computers having between five and 10 qubits available. Now we are seeing, uh, IBM last year had a, a quantum computer with a thousand qubits. So we're getting to the point where there's enough qubits there to start doing that error correction and handle that noise.
Um, uh, you do a triply redundant check of the math and you discard the one that doesn't agree with the other two. Uh, this, we are getting towards the point where the leading edge science can do, uh, can attack reasonably large keys and, um, and get good answers out. So we definitely need to be making these moves now.
We need to be getting these, uh, experiences. Drew says, you, you need to learn the stuff. You need to start implementing it before it becomes the, the big crisis.
Uh, but we are getting closer and closer to that big crisis crisis. Now, it may be a, a year or two before we see commercial organizations able to do this, but I have this sneaking suspicion that there are, uh, government agencies and particularly the unspeakable government agencies, both, uh, within the powers that we work for, but also, uh, the adversary powers who probably have capabilities they're not talking about. And, uh, those are the ones that are most concerning as, uh, And are happy to rent that out to help cover the cost.
I'm sure. Yeah. My, my concern is some of the, the long-term intrusions, I mean, we saw conventional long-term intrusions into a power company and telcos, um, not too long ago.
Well, well, I'm concerned that there's, there's more going on in the crypto side through, through undisclosed quantum in innovation. And I think that one of the kind of hit hitting on some of the points that you brought up here, the value in this is not that we've created a quantum resistant encryption algorithm. 'cause there's hundreds of them out there.
The value is that somewhere someone who set standards says, this is the one we're gonna use because this means that everybody can kind of say, we're gonna use this, we're gonna implement this. Regulations can be rewritten to allow this in addition to other things. And, and yes, your regulation needs to be specific.
It should not state like military grade encryption or something dumb like that because first of all, that's, that's not a thing. But more importantly, when you specify that, you know, you can either use something like a ES 2 56 or, um, whatever the NIST number is for, for kyber, that will give you the capability to say, you know, I know that these workloads are protected at this time, and once we've started implementing this, we can iterate on it. And if we're iterating on this while quantum is still trying to break the stuff that we put in place, now that means that three years from now when we finally get to a point where this is a problem, we are hopefully a generation or two removed from this.
And whatever we have is even gonna be more impressive, uh, as far as security and things like that. Because this is always evolving situation. You know, like, like Alistair brought up, we, we saw a news story recently where, you know, a nation state actor used some pretty, uh, interesting ways to just basically slip into a telco and start siphoning data.
And I believe al in our conversation, our first thought was, you're encrypting data in flight, right? Like, if you're encrypting data in flight, this isn't a problem, right? You're doing this.
And and I think a lot of people aren't doing that right now, and they need to, they need to address that. Like, like, I don't care which one you pick, but pick something. Because once all the data that was flying across the internet is encrypted in flight and it's very temporally sequenced, a lot of this doesn't matter.
The value in using quantum computer to crack encryption is not that it will take, you know, you'll be able to look at data from 10 years ago and get it. That's not very valuable. It's that you can decrypt in real time on the fly and, and basically intercept point in time communications.
Yeah, JJ and I did a podcast with DigiCert and I feel bad about repeating, uh, vendor lines, but they, I think they did bring up an important point is that what we should be thinking about is agility, meaning we're, we're never gonna be sort of one and done with a, the perfect encryption algorithm. So you're going to need to be comfortable with rotating in and out of encryption algorithms, making sure your systems and your processes are able to roll with the punches essentially as new algorithms roll out and new attacks roll out to be able to swap in and out as needed. Uh, so I think that's what we should be thinking about when we're thinking about post quantum encryption, is that the ability to adapt on the fly as needed, as new technologies and new attacks emerge.
Yep. And you know, there's not air quote military grade encryption. I mean, that's not, like you said, it's not really a thing.
But we do have guidance from the federal government by way of like the CNSA suite, which is the commercial national Security algorithm suite. So that's what the federal government uses and recommends for security conscious organizations. And that encompasses a breadth of different types of, you know, algorithms and families including PQC, including E-C-C-R-S-A, et cetera.
Um, so we, I think we have good guidance in this space, but it does make sense for us to start thinking about it now, not during our next refresh cycle. These are all very valid reasons why you shouldn't be rushing out to implement post quantum crypto algorithms today. However, tomorrow would be a really good time for you to take a look at it, because the more familiar you are with it and the way that it's being implemented in the various different areas inside of your software or inside of your data or whatever is more valuable to you, so that when you are ready to make that move, when you're ready to flip that switch, you are not struggling with implementation details and, and kudos to the NIST for getting it right, like they didn't spend a whole lot of time going into the math behind it.
There's papers if you wanna read that. It's just like, Hey, this will protect you a lot better in the future from the specific kind of attack that we know is coming, but we need to get a handle on it before it becomes an issue. And of course, if you want to learn more about things like post quantum crypto, the best place to do that is during our security field day events.
We have one coming up October 16th and 17th, and I know for a fact that post quantum crypto is gonna be something that gets discussed during that event. com, you can see more information about that and you can follow along with all the live streaming video. We'll, in fact be joined by all of our guests here at Security Field Day.
So we can't wait to hear what they have to say and during both, during the event and afterwards. And we would love to hear what you have to say. So thank you very much for being a part of the Tech Field Day podcast.
If you wanna leave a comment on this video on your perspectives or your questions, uh, please do so. You can also follow us on all of our social media platforms. We're at Tech Field Day almost everywhere.
We'd also love it if you would subscribe to our YouTube channel and follow along with all the great events that we do at Tech Field Day. com/podcast for the latest episode, as well as our upcoming field day event schedule. com.
You can also follow Textron TV for more episodes of content like this through all of those sister sites. We hope that you'll join us for Security Field Day, or at least watch the replay of the videos if you're watching this after October 16th through 17th. And we'll be in touch with more great information and more great podcast episodes very soon.