Post-quantum migration gets harder when every user holds a key
Overview
Christopher Smith, CEO of Quantus, discusses the challenges of migrating to post-quantum cryptography, particularly in sectors like banking and healthcare. He reveals that many institutions still hold outdated cryptographic inventories, including default passwords and admin keys from former employees, which complicates the upgrade process. Smith explains that the larger key sizes required for post-quantum systems break previous assumptions about encryption protocols like IPsec, SSH, and TLS. This places a significant burden on organizations looking to upgrade their security measures, as user-held keys in blockchains create additional hurdles. The conversation raises awareness of the potential risks associated with a 'silent quantum break,' where vulnerabilities could be exploited without immediate detection. This situation emphasizes the urgent need for funding and resources to address these cryptographic challenges.
Key Takeaways
- Affected Systems: IPsec, SSH, TLS, libp2p, banking systems, healthcare systems
- Action Required: Organizations should assess their cryptographic inventories, update default passwords, and consider transitioning to post-quantum cryptography as key sizes change.
- Timeline: Newly disclosed
Original Article Summary
In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assumptions in IPsec, SSH, TLS and libp2p, why migrating user keys makes blockchains hard to upgrade, and what a silent quantum break would look like from outside. He also gives the argument for funding … More → The post Post-quantum migration gets harder when every user holds a key appeared first on Help Net Security.
Impact
IPsec, SSH, TLS, libp2p, banking systems, healthcare systems
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Organizations should assess their cryptographic inventories, update default passwords, and consider transitioning to post-quantum cryptography as key sizes change.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.