CISOs urged to push vendors for roadmaps on post-quantum cryptography readiness

2 westurner 5 6/9/2025, 4:57:18 PM csoonline.com ↗

Comments (5)

Bender · 3h ago
How do people test post-quantum cryptography? How do they verify their encryption can not be defeated by quantum computing without having access to real world quantum computing? Are they basing everything off theories?
westurner · 3h ago
Are there additional published analyses in addition to the NIST PQ competition rounds?

RSA was also based off a theory.

westurner · 3h ago
Best be ready, for Q-day:

> The looming ‘Q-Day’ should also be used as the stick to get approval to carry out a cryptographic inventory and roll out projects that foster cryptographic agility more generally.

> Q-Day will not be announced and businesses need to take action now in the face of a growing threat.

[...]

> “An orderly transition will cost less than emergency planning,” Holmqvist said. “It’s like Y2K but without an actual date.”

sybercecurity · 2h ago
Q-Day is in a superimposed state! It's everyday from today to the heat death of the universe. We won't know for sure until we measure it.
westurner · 2h ago
Could be software, Could be hardware. AI could be making it sooner, nearer in time.

Practically,

How to add the PQ library or upgrade to the version with PQ ciphers?

How to specify that PQ Ciphers are optional in addition to non-PQ Ciphers (TLS 1.3, downgrade risk) or necessary? Where is the configuration file with the cipher list parameter?