Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cryptographic Security And The Quantum Apocalypse
Articles

Cryptographic Security And The Quantum Apocalypse

Nick FranceBy Nick FranceDecember 23, 2021Updated:January 9, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cybercrime Economics of Malicious Macros
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With MI6’s recent admission that it needs to “tap into” the global technology industry to keep up with China’s quantum computing mastery, staying secure against this new computing paradigm is a top priority for world leaders.

While many still see quantum computing in the realm of sci-fi, practicable  quantum computing inches closer to becoming a reality every day. If an actor were to successfully harness quantum computing – such as China, the most advanced to date – the entire global digital infrastructure would be rendered obsolete overnight.

Quantum computing holds immense potential, but it also presents catastrophic cybersecurity risks. If sufficient quantum computing potential falls into the hands of a hostile power, the cryptographic basis that underpins every aspect of modern digital infrastructure could be rendered useless overnight. The moment this happens is known as the ‘Quantum Apocalypse’.

Quantum explained

Quantum computers take advantage of the nature of quantum physics to create an entirely new computing paradigm different from the traditional 0/1 binary-based, gated computers we have been using since the 1950s.

Instead, they run on quantum bits (known as qubits), which can superpose and entangle themselves in order to perform multiple processes simultaneously.  A qubit can represent one or zero, or also a third condition which represents a ‘coherent superposition’ of the two. Because qubits are not limited to two simple on/off states, each new stable qubit added to a quantum computing system increases its power much more quickly than for its traditional counterpart.

The nature of how they calculate gives quantum computers a vast advantage over traditional digital computers for some specific types of task. Two of these happen to be factoring large numbers down to their primes, and another is calculating elliptic curves. This is important because the cryptographic algorithms used to encrypt data throughout the world’s global digital infrastructure depend on these two mathematical functions, and should they break down, encryption as we know it will collapse.

Therefore, when these algorithms are compromised, the foundational security of all digital systems will be insecure. The modern systems of finance, commerce, communication, transportation, manufacturing, energy, government, and healthcare will, for all intents and purposes, cease to function, as the encryption they rely on crumbles. This is the nightmare scenario MI6 fears.

What next?

However, it’s not all doom and gloom. To protect from the Quantum Apocalypse, governments and organisations need to migrate the global public key infrastructure (PKI) away from existing algorithms to new quantum resistant cryptographic approaches. As of now, experts in the security industry, academia, and government are working on this problem, seeking to discover, define, and codify the best encryption algorithms to current standards. An international combined effort of academia, industry, and the US’ National Institute of Standards and Technology (NIST) has winnowed a list of more than eighty initial candidates down to slightly more than ten possible approaches today. While the final cryptographic approaches remain to be determined, the cryptographic community is highly confident that one or more of these ultimately will fit the bill.

A winning encryption algorithm must be:

  • Fast to encrypt for a traditional computer
  • Fast to decrypt for a traditional computer using the private key
  • Prohibitively difficult to decrypt in a brute force attack for either a quantum computer or a traditional computer
  • Able to produce encrypted data that is efficient in size and not so “bloated” that it is impractical to use
  • Compatible with the staggeringly complex array of hardware, software, and services that depend on standards-based Public Key Infrastructure (PKI) systems today
  • Well, enough tested and understood that we could be confident it won’t prove highly vulnerable to future, unknown attacks

The PKI industry has also introduced technologies such as hybrid certificates which will enable the transition to the new quantum resistant algorithms.  The time is now to start engaging with these technologies as toolkits have been made available.

Time is of the essence

Fortunately, despite the best efforts of nation states and mega-corporations, we are still in the early days of quantum computing, and researchers are getting ahead of this imminent threat. And, despite the work of Google, NASA, and IBM, the computers that will break modern day algorithms are not yet with us today. However, these machines are years – rather than decades – away, so now is the time to make sure basic PKI encryption is quantum-resistant. In order for digital lives to function in a post-quantum world, and to safely take advantage of the computing power available to us, time is of the essence.

Nick France

Nick France, CTO at Sectigo

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Visual data is the blind spot in enterprise security: that’s about to change

    May 4, 20267 Mins Read

    Making stolen data worthless: why security must start with the data

    March 30, 20265 Mins Read

    Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

    March 10, 20264 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}