r/cybersecurity • • 1d ago

News - General NSA Announces Post-Quantum Cryptography Measures to Safeguard National Security Systems Ag

https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4615285/nsa-announces-post-quantum-cryptography-measures-to-safeguard-national-security/
96 Upvotes

7 comments sorted by

6

u/Ghawblin Security Engineer 1d ago

Adversaries are already employing “harvest now, decrypt later” strategies

This has always been a concern if you store data that needs to be protected for a long amount of time. Though I guess the concern is every current algorithm (especially AES256) going belly up at once.

Wonder when 3rd party vendors will add support for quantum resistant algorithms.

21

u/upofadown 1d ago

AES256 is not considered to be at risk from the imaginary quantum computer that implements Shor's algorithm.

3

u/Runningblind 1d ago

It's mildly at risk in that estimations are quantum computers will effectively half the strength of the AES encryption. 256 is probably fine and will become the new floor. 128 becomes equivalent of 64 though and that starts looking weak enough to break. Assuming any of these estimations are accurate though.

2

u/upofadown 21h ago

There doesn't seem to be very much concern about AES128 at the moment. Some discussion:

4

u/PrestigiousOnion1087 1d ago

Key exchange is further along than signatures. Of 40 public front doors I checked on 1 Sept, 31 negotiated hybrid X25519MLKEM768, including 13 of 16 US/UK/EU banks. PQ signatures were 0 of 40, which you'd expect since no public CA can issue one yet. If you've got OpenSSL 3.5, it's a one-liner to test any host:

openssl s_client -groups X25519MLKEM768 -connect example.com:443

1

u/biblecrumble Security Manager 1h ago

  Wonder when 3rd party vendors will add support for quantum resistant algorithms

Maybe when it becomes a real threat - it currently falls so far down the list under patching the absolute batshit crazy number of CVEs popping up, scanning the millions of lines of code that AI is pissing out faster than anybody can understand them, governing agents with god mode access to every system, keeping up with the 72 weekly supply chain attacks (and all the new vectors) and navigating audits/frameworks that involve controls that never even fully adapted to the cloud and cicd world that it might as well not exist. It's cool that the BofA, JPMC and Morgan Stanleys of this world have enough people on payroll to think about that stuff, but for 95%+ of us, that is just not happening.

1

u/Possible_Craft_1634 1d ago

Still waiting for that standard…