6 ms·
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
- cold_pizz4 2mo agoRelated: https://news.ycombinator.com/item?id=48992806 https://news.ycombinator.com/item?id=48992806 (Are 128-bit symmetric keys really secure against quantum computers?)
- close04 2mo ago[dead]
- vaadu 2mo agoWill they decertify previously certified PQC-free products?
- roblabla 2mo agoQualification is time-constrained. You are qualified for two to three years. So by 2030, all qualified products will be PQC-free.
- u1hcw9nx 2mo ago[dead]
- tsimionescu 2mo agoI'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.
- exmadscientist 2mo agoAgreed. This looks from the outside like someone read a report, got unnecessarily spooked, and now the rest of the herd is following along. But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it. However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I don't have any particular recent expertise to support that, but I did used to share an office with some serious QC people and go to their talks so... make of my words what you will.
- exmadscientist 2mo agoWould anyone downvoting care to explain? I'm genuinely interested in seeing anything that suggests there's either some secret breakthrough (completely plausible, but there's no evidence that I've seen hint of) making quantum computers actually useful, or an argument that they'll be usable by (say) 2050? Because right now my attitudes are trained by things like this https://algassert.com/post/2500 https://algassert.com/post/2500 that explain just why 15 was factored in that famous run of Shor's algorithm and not, say, 21; and why 21 hasn't been factored yet and isn't likely to be any time soon....
- alphager 2mo agoI work as a security architect in a major European company. We're currently demanding a full cryptographic inventory of every new product purchased or service built in-house and will start demanding PQC in 2028. Not because we expect a workable quantum computer by 2030 (current estimates are around 2035-2040), but because stuff survives for decades in large enterprises (especially if it touches hardware in any way. Think OT, think controllers for all kinds of machines). Now that PQC is standardized, there's no gain not to demand it (it's basically a demand to use a current openSSL/libreSSL/$library), but not demanding it now will cause a major headache once/if quantum computers work. TLS connection speed matter only for a very tiny niche of applications; those will choose according to their needs. For the general case, it just doesn't matter. If your threat model includes store-now-decrypt-later, you should have been demanding PQC for years.
- colmmacc 2mo agoI was at ANSSI headquarters last year doing a technical presentation and several of their questions were about Post-Quantum Cryptography, "Q day" (when a practical Quantum Computer is expected) and other related things. They keep a close eye on this stuff and it's to their credit. Similarly the BSI in Germany have been promoting Post-Quantum security for some time now. I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!
- dredmorbius 2mo agoPQC: Post-Quantum Cryptography. The concern is systems which won't be resistant against quantum cryptographic attacks. The US's NIST has an explainer page, "Post-Quantum Cryptography PQC": <https://csrc.nist.gov/projects/post-quantum-cryptography https://csrc.nist.gov/projects/post-quantum-cryptography>.
- CurbStomper 2mo ago[dead]
- 6r17 2mo agoTBF it's the healtiest approach to it. It's just risk mitigation. Nobody cares about it - there are nice papers to implement it ; just freaking do it.
- dylan604 2mo agoFrom TFA: "The policy reflects growing concern about Harvest Now, Decrypt Later (HNDL) attacks, in which adversaries intercept and store encrypted communications today with the intention of decrypting them once a cryptographically relevant quantum computer (CRQC) becomes available." Once it gets to be "later" where the harvest data is able to be decrypted, I guess will have decent enough LLMs to summarize all of that data? Otherwise, there's going to be such a huge back log to make it not too useful
- pixl97 2mo agoI mean we have decent enough LLMs and algorithms to classify it pretty easily now, much less the future. Just getting context information on who or what the data is narrows down a lot of what you want to look at.
- dylan604 2mo agoIf that were true, they wouldn't need to store it for ever
- vitally3643 2mo agoThey need to store it because the technology to decrypt it does not yet exist.
- dylan604 2mo agoboy did you miss the point. I know that's what they say, but the GP comment said that pretty much everything you need to know can be found just from the metadata which diminishes the claims for needing to decrypt the data. It's trivializing the value of the decrypted data.
- pixl97 2mo agoEh, with the Metadata you can nearly instantly figure out what encrypted data you need to keep for long periods of time for later decryption. For monitoring the plebs metadata is fine, but when you get to things like political targets and the vastly wealthy it's a different story.
- d1ss0nanz 2mo ago[flagged]