Right, so the original title that you have in your program, that was super long, yeah, I just realized I couldn't put that all on one slide, yeah, so I shortened it to say Quantum Computing Worry or Not, right, and my name is Ingo Schubert, I'm the field CTO for the national region at RSA, and if you think RSA, RSA, RSA, hold on, RSA Algorithm Encryption, so let's get one thing straight from the beginning. RSA Security, the company where I work for, does not sell cryptographic toolkits anymore. We don't make money with the RSA algorithm.
The company and the algorithm share a common history, an interesting history, yeah, ask me about that, but that's it, right. I stand here, I have nothing to sell you, right, I'm not just a dude on stage talking about stuff he has some ideas of, right, nothing to sell you.
Now, also disclaimer, I started with RSA about 24 years ago and I started in the group that handled the cryptographic toolkits, so I do have a background in this, right, so this is why I can stand here and talk about this with some confidence. So, quantum security, quantum computing and security.
Now, this is the first session on this track. Now, if quantum computing pops up one day, it will pose a threat to IT security in general and that's largely due to the fact that traditional asymmetric cryptography is then broken in almost no time, right. The idea is quantum computer shows up, it can essentially almost in real time break any key that is RSA based, elliptic curve or Diffie-Hellman, right, so it's not just RSA, it's any traditional asymmetric cryptography.
Now, that's the threat, right. The actual algorithm that is relevant for this is Shor's algorithm, yeah, that one is the algorithm that will run on a quantum computer and that one will be able to break all those algorithms or the keys to be precise.
Now, there have been some recent advancements in Shor's algorithm and that's mostly around optimizing it. Initially, it was thought you need about a million qubits to make this run, so relatively large quantum computer that is nowhere near to be practical and it was like 100,000 and that's around on 10,000 give or take, yeah.
So, basically, there were optimization going on saying, we can get this running on a quantum computer with around 10,000 qubits now, again, give or take. That doesn't mean the algorithm runs as fast on 10,000 qubits than it can be on a million, yeah, that's I think everybody should realize that, yeah, you can have small processors and big processors, yeah, you can play Doom on a pregnancy test, you can play Doom on your gaming rig, that's not the same, right, so just keep that in mind.
It's important that because if this is broken, pretty much every protocol we in this room care about is affected. TLS, SSL, TLS is affected, IPSec, SMIME, SAML, XMLSec, OAuth, OpenID Connect, FIDO, all of them use one of those algorithms to do stuff, right, so all would be affected and they all would need to be adjusted to deal with this threat.
Now, the problem is quantum computing is an interesting topic.
Now, if you've been around, you notice that this is probably not the first time you hear about this, yeah, maybe you were like way younger and you already heard about quantum computing, maybe you're a Star Trek fan, quantum stuff plays a huge role in Star Trek, right, that's why I actually blame why this actually is bubbling up now, Star Trek is to blame, and a bit like fusion reactors, yeah, quantum fusion reactors are about always like 20 years away or 30 years away, right, it could very well be that the first quantum computer is powered by a fusion reactor, think about that, right.
Now, quantum computing does make progress and we have seen this over the last couple of years, it's not revolutionary progress, I'll get to that one, but there is progress, keep that in mind because sometimes, I'll have a section on this, it seems like, wow, this is just around the corner, right, once quantum computing is there, again, that's Shor's algorithm, then things become very interesting for all of us. The question is, when is that?
And the answer is, nobody knows, right, if somebody tells you they know when this happens, like, no, they don't, right, so NIST, EU or non-EU agencies in cyber security around the world, you will see they have some recommendations or regulative framework around this, so roughly, right, roughly around 2030, you're not supposed to use any of the traditional algorithms only, exclusively, and roughly around 2035, you shouldn't use them at all.
It depends a bit on which jurisdiction, which country you're in, yeah, but roughly, that's the goal, right, from the EU, from the US, and again, other regulations around the world. Those states, just to be precise, are educated guesses. Nobody knows. They assume, like, yeah, around 2035, things get, you know, really interesting, 2030, it starts to get interesting, but in the end, they don't know, right. This makes the whole Q-Day thing different than the year 2000 problem.
Some of you, I see gray hair, you're old enough to remember year 2000 problem, right, some of you are young enough to not remember that because you weren't even born, right, but the point is, we had a date to walk towards to, yeah, nobody in 1999 said year 2000 will happen in 2003, right, that didn't happen. We had a date and we had urgency, right, because, you know, 1st of January 2000, things get real. With quantum computing, we don't have that date. We have those guesses, but that's about it.
So, it's a quick reality check because depending on which news you read, you probably have a different concept of how advanced quantum computing actually is. First of all, I realized over the last couple, like, two, maybe three years, the level of noise increased, which is a plain word because noise is a problem with quantum computers, but basically, the amount of press that is around the subject increased.
My guess, it's venture capital looking for the next thing after AI, right, then it sees this bubble, yeah, and think like, you know, where can we actually invest next, and AI, you may be agreeing it's a bubble or not, yeah, if not bubble, why bubble shaped, yeah, so let's just keep that in mind. So, there are some pretty strange and or impractical solutions out there based on quantum computer, quantum cryptography.
One of the things that keeps popping up is quantum random number generators, right, it's like, there are companies out there, this is their thing, and I go like, Jesus, we as IT industry have many problems, random numbers are not one of them, right, so there are some instances where random numbers are an issue, but those are embedded devices, you know what doesn't help with embedded device, a quantum computer that actually generates random numbers, right, the next is quantum key distribution, and oh my god, is he talking about quantum key distribution, yes, I am, now, I'm not saying it doesn't work, it works beautifully, right, the problem is you need actually a pipe, a fiber or laser that you can look through, and on the other side, and then you can actually get this quantum key distribution working.
Now, I'm just guessing that for most of us, yeah, we don't have a direct link to Amazon, yeah, a direct fiber link where we do, yeah, ordering through Amazon, most of you probably don't have direct fiber links between your data centers, and I'm talking about direct fiber link, no amplifiers in between, it's a direct pipe that you need to look through, that's when it works, so does it work? Absolutely, is it practical?
For some, yes, but for most of us, absolutely not, right, so just keep that in mind, and then there are some overhyped advancements, as I said, there are advancements, I'm not disputing that, right, but there are some things where I go like, oh, yeah, did anybody actually read the actual white papers? Somebody want to say something?
No, so one of them, if you remember, that was the, like in December of 2024, beginning of 2025, there was news about Google Willow, that's a quantum chip from Google, maybe some of you remember, and that, like in all the press, and it was really press, like normal magazines and newspapers, right, says that it can do in five minutes what a normal computer needs to, like I think in 25 septillion years, yeah, like longer than the age of the universe, and to be fair, Google never made that claim, right, but in one of the white papers, you have a table where it actually says that if it could run for five minutes, then it could do this thing, what a normal computer can do in whatever million, trillion years, yeah, that's the fact that it cannot run for five minutes, and the fact that the problem it solved is totally impractical, an artificial, like a artificial benchmark for quantum computers, again, like that was totally ignored, and Microsoft had a similar thing with their chip, so I'm not saying it wasn't not an advancement, it was, but it was way, way smaller than it appeared.
Then just recently, I'm not sure if some of you saw that, there was a cryptocurrency, of course, yeah, company that claimed, well, we gave away a price because elliptic curve, 15-bit elliptic curve got cracked on a quantum computer, right, very thin on details. How much time do you think it's needed to crack a 15-bit ECC key? Any guesses? On a normal computer?
Exactly, yeah, less than what takes me to actually ask the question on my laptop, on this laptop running this PowerPoint, yeah, just think about that, so, and then they make, in the press release, there was also, yeah, we know, it's like, it's a couple of bits short of what is actually practical, but that is just an engineering problem, and I've been offended as an engineer, right, it sounds like, you know, it's just like stacking Lego blocks, right, it's like, dude, it's like a space elevator, that's just an engineering problem, because in theory, we know how to build a space elevator, right, so, yeah, as you can see, it's like, yes, there's this, there are real advancements, but it's not like this thing is just happening tomorrow, right, so, coming to post-quantum cryptography and the algorithms, now, NIST has been running a, like a, like a contest to pick winners for the post-quantum world, and it worked for AS, it worked for a hashing algorithm, so there's no reason why they're not picking a good, or some good candidates for that use case, that's a well-established process, nothing against that, now, one thing to note, they need to pick multiple algorithms, because depending on the use case, you cannot do one with all algorithms, so, previously, you could, for example, do pretty much everything with RSA, right, key agreements, signing encryption, that's no longer the case with post-quantum cryptography, you need some algorithms per use case, which is not a problem in itself, but just keep that in mind, now, it looks, I'm not disputing that, because that's way above my math grade, that those algorithms are quantum safe, I'm not disputing that, again, because I don't know anything about that, but what I am saying is that, you know what, there's actually a good chance that they are suspicible to traditional attacks, right, so it might be this bizarre scenario where a quantum computer cannot hack them, but a traditional computer can, and one of the things is the algorithms themselves are more complex than, for example, RSA or Diffie-Hellman, and if you think about the lines of code you need to implement RSA, or one of the post-quantum algorithms, it's hard to actually, where to count, right, but it's roughly twice to three times the size, and the problem is also that you need a lot more math functions for those, and most more advanced math functions for those new algorithms, and that actually increases the attack surface, and this is not necessarily the algorithm itself, but maybe the implementation, because we have seen that in the past, where there are implementations of RSA, or Diffie-Hellman, or ECC, where it was not the algorithm that was suspicible to attacks, it was the actual implementation.
Think about side channel attacks, timing attacks, right, so one of the things where you go like, where I'm a huge fan of, is hybrid encryption, right, so four times we actually encrypt with some old algorithm and a new algorithm, one after the other, double encryption, right, or double signature. Unfortunately, this is not what every standard body actually is recommending, or doing in a complete 100% case. Let's give you some examples. TLS 1.3 and PQC.
Now, there are, and there will be, post-quantum cipher suites, so those combination of algorithms that use this hybrid encryption, which is fine, right. Now, there is, however, one that is exclusively using a post-quantum algorithm. That's MLTM, post-quantum key agreement, TLS 1.3, right.
Now, this basically is no, like, usually you have belt and suspenders, this is basically just assuming that your suspenders do your job, right. So, this is exclusively saying, yep, I'm sure that MLKM is adequate for the future. Should there anything be affected by some side channel attack or an attack on the algorithm itself? No safety net, right.
So, why are they doing this, yeah? There's no double encryption.
Yes, I agree, like, you know, that needs more CPU to double encryption, all that, I agree, I get that. But I think it would be worth the effort to actually do that, at least for, I don't know, the next 10, 15 years, until we have more assurance that the algorithms and the implementation are actually secure, which we currently do not have. We have four decades on that for the other algorithms, just be clear, right. We don't have that for those new algorithms.
So, when later you get tasked to actually make a web server or whatever, or SSL VPN secure, now you only have to worry about, hey, I enabled the post quantum cipher suites, you have to also have to worry which one, right. Do I want this exclusive one or do I want one that actually does double encryption, right?
So, crypto agility, yeah, and it's not really there. And that's relevant for all of us because TLS is probably one of the one of the protocols that underpins all of this, right.
FIDO, somewhat in a similar bucket, right. So, the current FIDO keys, the physical keys that you may have, they are unlikely to actually be able to use post quantum cryptography. First of all, they probably need to update their firmware, and they can't do that right now. Maybe their process isn't up to spec or the RAM.
So, it might be that you probably need new hardware, that's what it probably boils down to, right. This, again, the CPU is probably not the bottleneck because those algorithms are surprisingly fast, right, but memory is probably an issue because the keys are longer and so on.
So, the same thing, then, TLS applies. If we go with something that exclusively does a post quantum algorithm, is it actually safe? And the answer is, I don't know.
Hopefully, it is. Let's not make the, I hope it is, right. I don't hope that it's not safe, but I don't know. I have my doubts. That's the point.
So, if there's double encryption or double signature, I would be way more happy with that. And now we come to something that's, ah, this is, if, and who is really worried about quantum computing? Just a hands up, just very quickly.
One, two, three, four, five, right. If you're worried about authentication, yeah, you know what you should do? You should look into OTPs.
Like, what? Yeah.
So, OTPs, especially hardware OTPs, and let's ignore SHA-1 based, that still would be safe, but I know people get nervous with SHA-1. HOTP, TOTP, the standards, and the RSA, the QID, they either use SHA-2 or AES to calculate the OTPs, and those algorithms are quantum safe.
So, provided you do the seeding correctly, you have something quantum safe today. Now, of course, it means if you use that, the rest of the infrastructure also needs to be quantum safe somewhat, yeah, so let's just not forget that.
So, now you have the option, like, do I want something phishing resistant or something quantum safe, yeah? Have fun with that.
So, one thing also to keep in mind, attackers do not need a quantum computer. There is so much more they can do, right?
So, if you worry about quantum computing, well, if you have all the other issues solved, please, worry about quantum computing, but there's so much more, right? The attackers can get in with many other, in many other ways. Nation states, they have more than plenty of resources to attack you, yeah? Essentially, it's like, you know, which way to get in, right? That's the worry, which one is, you know, less, most effective, you know, takes less noise and so on. You need to do your homework first. Before you get ice cream, which is post-quantum, you need to eat your vegetables, right?
All the stuff that you should have been doing the last 10 to 20 years, don't get distracted by the next shiny object. Do that first.
MFA, password list, zero trust, least privilege, all of that stuff, because it helps you in general, right? So, it's like you have a mess in your apartment, and what you do, you buy a new TV and think that, oh, that fixed it, right?
No, it did not. It's still a mess, yeah?
So, while speculations on my part, right? So, a quantum coprocessor with, you know, some working Shor's algorithm will be there in the 2030s. I think that's pretty safe to say, right? I think that governments probably will regulate quantum computing somewhat, because it's easier to regulate hardware than it is software, yeah?
That makes it distinct from some of the AI models, because as we probably have seen, like, with, you know, Nvidia chips not reaching China, could be that, you know, there are also some barriers erected to actually not ship quantum computers in one way, shape, or form from one end of the globe to the other. It could also, by the way, mean that China has a quantum computer and is not exporting it, right?
So, keep that in mind. It's not just the US has one and doesn't ship it to China, it can be the other way around, right? But the point is that it probably will limit who has access to this thing, which means also, you know, the usual bad guys may not have access to this. And the other thing is, should quantum computing be delayed for any reason, right? People will get lazy, because they don't have that data. It's seen 2030, nothing is happening, so, yeah, don't worry about it, right? Which probably is the wrong approach.
So, what can we all do today? First of all, you should know how you encrypt, how your servers are configured, key management, all that. That should be in order. Classify data, which data is like, you know, short-lived, which is longer-lived, proper risk assessment. And if you think like, that sounds familiar, yeah, it should be, right? You should be doing this already, right? And keep your software up to date. I know this sounds like, well, that's obvious. Not really, right?
So, I still have time for a story. No, not really.
Yeah, that's okay. I don't. But that's basically what you can do, is keep yourself up to date and do that.
So, if you need the threat of quantum computing to do this stuff that you should have been doing the last 20 years, fine. I had to get more money, yeah?
Otherwise, who is that guy? That's Immanuel Kant, exactly, yeah? And all the native English speakers, stop giggling, yeah?
So, ideally, yeah, you should be doing that because it's the right thing to do, not because somebody told you to, right? That it's quantum safe. And with the quote from Immanuel Kant, I'll set you free and thank you for your attention.