Quantum Computing Threats to Code Signing Security

Explore top LinkedIn content from expert professionals.

Summary

Quantum computing poses a serious threat to the security of code signing, which is how software and digital documents are authenticated and trusted. Because quantum computers will be able to break widely used encryption algorithms, they might allow attackers to forge trusted signatures on software updates or contracts, undermining both security and safety.

  • Start migration planning: Begin evaluating current cryptographic systems and set a strategy to shift toward post-quantum cryptography to protect long-lived devices and sensitive data.
  • Build crypto agility: Design systems that can easily swap out cryptographic algorithms so you can adapt quickly as new threats and solutions emerge.
  • Update trust management: Revisit how digital signatures, time-stamping, and evidence logs are handled to ensure your records and contracts remain trustworthy well into the future.
Summarized by AI based on LinkedIn member posts
  • View profile for Anna Beata Kalisz Hedegaard

    CEO @Quantum Security Defense and @QuantumPrime || TOP10Women in Engineering PL ‘25 || Host of Weekly “Quantum Innovation” show

    13,823 followers

    The Integrity Crisis: Trust Now, Forge Later. 🤓 In my last post, I discussed HNDL (Harvest Now, Decrypt Later)... the threat where attackers hoard encrypted data today to read it tomorrow. That is a crisis of confidentiality. (see link in comments) But there is a second, arguably more dangerous vector emerging in post-quantum security discussions. It targets integrity and authenticity. It is called TNFL: Trust Now, Forge Later. What is the basic mechanism? Current public-key signature algorithms (like RSA and ECDSA) rely on math that a Cryptographically Relevant Quantum Computer (CRQC) will break using Shor’s algorithm. The threat model is simple: ➡️ Trust Now: An attacker records a digitally signed artifact today, a firmware update, a digital identity, or a long-term contract. These are valid and trusted right now. ➡️ Forge Later: Once a quantum computer becomes available (est. 2030s), the attacker uses the public key information from those recorded artifacts to derive the private key. 🤯 The Breached Future: They can now retroactively sign new, malicious artifacts that your systems will accept as authentic. So why this is different (and dangerous)? 🤷♂️ Well... while HNDL reads your diary, TNFL hijacks your car ‼️ HNDL (Confidentiality): Exposes past secrets. The damage is informational. TNFL (Integrity): Allows active compromise. A forged signature on a firmware update in an OT (Operational Technology) environment doesn't just leak data; it could cause physical damage to critical infrastructure. We often mistakenly think signatures are ephemeral, overlooking the significant "long-tail" of trust they actually create. Examples 👩🏫 software/Firmware: Embedded devices often have lifecycles of 15–20 years. A satellite or medical device deployed today with a hard-coded root of trust could be hijacked in 2035 via a forged update. Legal & Finance: Blockchain ledgers and digital contracts signed today must remain immutable for decades. TNFL threatens to rewrite that history. The Fix: Crypto-Agility and Post Quantum Cryptography 🤩 We cannot simply wait for the quantum era to arrive. The mitigation strategy is crypto-agility: building systems today that allow us to swap out cryptographic primitives without rewriting the entire infrastructure. There are good choices of Post Quantum Cryptography already available for implementation. All around the world governments recommend implementing them. It's time to "keep secrets" and "maintain trust". Join Quantum Security Defence for continuous education, business networking and advisory, link in the comments. 💚 🔜 In my next post I will discuss evidence logs as the proof of what happened in the past. #PQC #QuantumSecurity #DigitalTrust #Cybersecurity #TNFL #Integrity #CISO #TechTrends2026 #QSECDEF #QuantumComputing

  • View profile for Marin Ivezic

    CEO, Applied Quantum | Author, PostQuantum.com | Quantum Systems Integration, Quantum Security & Post-Quantum Cryptography (PQC) | ex-Fortune Global 500 CISO/CTO & Big 4 Partner

    35,519 followers

    We’re all bracing for “Harvest Now, Decrypt Later.” The risk that keeps me up at night is its more dangerous twin: “Trust Now, Forge Later.” This isn’t about reading your secrets tomorrow. It’s about forging the signatures and certificates your systems trust today - software updates, firmware, documents, device identities - once quantum computers can break RSA/ECC. When the control plane (signing and verification) fails, attackers can push "validly signed" malware and instructions that our systems accept without a blink. Why this matters - especially in OT and cyber‑physical environments: - Integrity -> safety. In factories, energy, healthcare, and transport, forged signatures can become physical harm. - Long‑lived devices. Roots of trust burned into ROM, narrow maintenance windows, and legacy protocols mean PQC migration in OT is harder (much harder) and slower than in IT. - Evidence and provenance. If signatures become forgeable, non‑repudiation and long‑term legal trust need PQ‑secure timestamping and re‑signing strategies. I lay it out here - including why “Sign Today, Forge Tomorrow / Trust Now, Forge Later” is often a bigger risk than HNDL for OT and critical infrastructure, and why the migration is uniquely complex. #QuantumThreat #QuantumComputing #TrustNowForgeLater #TNFL #QuantumSecurity #PQC #PostQuantum #QuantumReadiness

  • View profile for Dr. Rajesh Dhuddu, Ph.D

    Partner & Emerging Tech Leader, Leadership Team @CEDA, PWC| Forbes Blockchain 50| Most Inspiring Web 3 Leader| CXO Innovator of the Year| Tedx Speaker| Author| Passionate about Connecting People & Ideas|

    35,190 followers

    Lets Learn #Quantum – Post #16: Post-Quantum Cryptography (PQC) The Invisible Safe: Why Hackers Are Stealing Data They Can't Read Yet The biggest short-term impact of quantum computing isn't what it can create. It is what it can destroy. Right now, our digital world relies on encryption algorithms like RSA to protect banking, emails, and cloud data. Standard supercomputers would take thousands of years to crack them. But quantum computers change the rules. Running Shor’s Algorithm, a quantum computer could break today's encryption in hours. The Threat Happening Right Now Why care today if full-scale quantum computers are still year away? Because cybercriminals are actively executing a strategy known as Harvest Now, Decrypt Later (HNDL). Imagine a thief stealing a locked titanium safe. They cannot open it today, so they hide it in a basement and wait. Years from now, a new tool is invented that pops that safe open instantly. That is HNDL. Bad actors are intercepting and archiving sensitive enterprise data today, waiting for the day a quantum computer can unlock it. If your data needs to remain secret for the next decade, it is already at risk. Enter PQC: Upgrading the Locks Post-Quantum Cryptography (PQC) is the defense. It is a new generation of math shields designed to resist attacks from both conventional and quantum computers. The breakthrough? PQC runs seamlessly on your current servers, smartphones, and cloud platforms. Think of it as swapping out a traditional door lock for a multi-dimensional biometric scanner. The house stays the same; only the lock changes. Instead of traditional math, PQC relies on Lattice-Based Cryptography. Think of it like a maze with thousands of overlapping dimensions instead of two. Even a quantum computer gets completely lost trying to find the exit. The Strategic Reality You cannot swap out the security architecture of a global enterprise overnight. Migrating infrastructure takes years, which is why forward-thinking leaders are already auditing networks and testing PQC algorithms today using a hybrid approach. The quantum threat is not a future IT issue. It is a current strategic risk. The question for leadership is no longer: "When will a quantum computer be built?" The real question is: "Will our data still be secure when it arrives?" #QuantumTechnology #PostQuantumCryptography #PQC #QuantumSecurity #CyberSecurity #QuantumComputing #DigitalTransformation #DataProtection #TechnologyLeadership Co-authored with Atul Tripathi Sundar Ram, Sachin Arora, Himanshu Ghawri, Azizur Rahman, Shivendra singh, Prasun Nandy, Jaydeep Sarkar, Joydeep Roy, Arihant Garg, Amit Kumar, Hetal Shah, Arun Rangaraju, Sayantan Chatterjee, Rajesh Kumar Ojha, Dr. Raghav Manohar Narsalay, Praveen Sasidharan, Sundareshwar K (Sundar), Manu Dwivedi, Venkat Nippani, Himadri Ganguly, Ritesh Jain, Abhijit Chakraborty, Sumit Srivastav, Anit Shanker #soyoucan

  • View profile for Julien Bouteloup

    Founder & CEO, Stake Capital · Deep Tech & AI Compute

    12,535 followers

    🚨 Two major new research papers just dropped that dramatically accelerate the quantum threat to crypto. Google Quantum AI optimized Shor’s algorithm down to roughly 1K logical qubits, potentially allowing private keys to be cracked in minutes on advanced superconducting hardware. A follow-up from Oratomic then brought neutral-atom implementations down to just 26K physical qubits with a runtime of around 10 days. This makes Q-Day feel much closer, within just a few years of being reachable. This year at Satoshi Roundtable the mood around quantum computing wasn’t very enthusiastic. We openly discussed how a powerful enough quantum computer could break ECDSA signatures (secp256k1) used across Bitcoin, Ethereum, and most protocols, exposing massive on-chain value including dormant and early-mined coins. The big question was: how do we prepare, and prepare well? Crazy times to be living through. Honestly, teams working in encryption and blockchain should seriously consider stopping everything else and prioritizing this now. It’s time to start integrating quantum-resistant encryption algorithms into modern protocols. No matter if a cryptographically relevant quantum computer arrives in one year or in five, adversaries are likely already collecting encrypted traffic and on-chain data today waiting to decrypt everything the day quantum power crosses that threshold. The shift is real: migrating to post-quantum cryptography is no longer optional. It’s urgent infrastructure work for wallets, bridges, staking, exchanges, and every system holding long-term value. https://lnkd.in/dGUR24xH

  • ⏳ 𝗤𝘂𝗮𝗻𝘁𝘂𝗺 𝗖𝗼𝗺𝗽𝘂𝘁𝗶𝗻𝗴 𝗮𝗻𝗱 𝗖𝗿𝘆𝗽𝘁𝗼𝗴𝗿𝗮𝗽𝗵𝘆: 𝗧𝗵𝗲 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 𝗜𝘀 𝗦𝗵𝗿𝗶𝗻𝗸𝗶𝗻𝗴 𝗖𝗹𝗲𝗮𝗿 𝗣𝗮𝘁𝗵 𝘁𝗼 𝗖𝗿𝘆𝗽𝘁𝗮𝗻𝗮𝗹𝘆𝘁𝗶𝗰 𝗥𝗲𝗹𝗲𝘃𝗮𝗻𝗰𝗲 The Bundesamt für Sicherheit in der Informationstechnik (BSI) analysis is clear: Quantum computing is progressing steadily toward cryptanalytic relevance. The technical path is established: fault-tolerant Shor algorithms on superconducting systems with surface codes or ion-based systems with color codes. In 2024, key obstacles were removed. Quantum error correction works. Fault-tolerant computation is real. What remains is large-scale engineering. 𝗪𝗵𝘆 𝘁𝗵𝗲 “𝟮𝟬-𝗬𝗲𝗮𝗿” 𝗡𝗮𝗿𝗿𝗮𝘁𝗶𝘃𝗲 𝗜𝘀 𝗪𝗿𝗼𝗻𝗴 Error-correction break-even across several platforms in 2024–2025 invalidates the claim that relevant quantum computers are always decades away. A conservative estimate now points to around 15 years. This matches observed qubit growth and implies that systems with roughly one million qubits could be available in that timeframe, which is sufficient for cryptographic attacks. 𝗔 𝗦𝘁𝗿𝗮𝗶𝗴𝗵𝘁𝗳𝗼𝗿𝘄𝗮𝗿𝗱 𝗦𝗰𝗮𝗹𝗶𝗻𝗴 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 The same result emerges from a modular view. Five years to design a scalable platform. Five years to produce and integrate modules. Five years to operate at full scale and quality. This is a scaling problem, not a scientific unknown. 𝗪𝗵𝗮𝘁 𝗖𝗼𝘂𝗹𝗱 𝗦𝗵𝗼𝗿𝘁𝗲𝗻 𝘁𝗵𝗲 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 Advances in qLDPC codes, error mitigation, and neutral-atom platforms could reduce the horizon further. Ten years is no longer unrealistic. 𝗨𝗻𝗰𝗲𝗿𝘁𝗮𝗶𝗻𝘁𝘆 𝗜𝘀 𝗦𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗮𝗹 Multiple hardware platforms progress in parallel. Companies protect core technology. Some work happens in stealth mode. National security plays a role. A hidden qualitative leap seems unlikely today, but cannot be excluded. 𝗤-𝗗𝗮𝘆 𝗮𝗻𝗱 𝘁𝗵𝗲 𝗛𝗡𝗗𝗟 𝗥𝗶𝘀𝗸 To stay on the safe side, Q-Day planning should assume a horizon of no more than 10 years, especially for nation-state actors and cyber agencies. AI will accelerate engineering, scaling, and cryptanalysis. This increases the risk that Q-Day arrives earlier than expected. The HNDL threat—harvest now, decrypt later—is already active. Sensitive data intercepted today can be decrypted in the future. This affects critical infrastructure, government systems, and industrial communication with long confidentiality lifetimes. Protection must start now. This requires crypto-agile architectures and the early deployment of hybrid schemes combining classical and post-quantum cryptography. 𝗜𝗺𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻𝘀 𝗳𝗼𝗿 𝗖𝗿𝘆𝗽𝘁𝗼𝗴𝗿𝗮𝗽𝗵𝗶𝗰 𝗜𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 Post-quantum migration is no longer optional. Waiting increases risk. 𝗢𝘂𝗿 𝗔𝗻𝗮𝗹𝘆𝘀𝗶𝘀 𝗳𝗼𝗿 𝘁𝗵𝗲 𝗗-𝗦𝘁𝗮𝗰𝗸 We at Spherity assessed these risks and transition paths for the German D-Stack, with a focus on crypto agility and long-term resilience: https://lnkd.in/eTJT4erD

  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 20,000+ direct connections & 55,000+ followers.

    55,100 followers

    NIST – Migration to Post-Quantum Cryptography Quantum Readiness outlines a comprehensive framework for transitioning cryptographic systems to post-quantum cryptography (PQC) in response to the emerging threat of quantum computers. Quantum technology is advancing rapidly and poses a significant risk to current public-key cryptographic methods like RSA, ECC, and DSA. This guide aims to assist organizations in preparing for and implementing PQC to safeguard sensitive data and critical systems. Key Points  The Quantum Threat Quantum computers are expected to disrupt cryptography by efficiently solving mathematical problems that underpin widely used encryption and key exchange methods. This would render current public-key systems ineffective in protecting sensitive data, emphasizing the need for cryptographic agility.  NIST PQC Standards NIST is spearheading efforts to standardize quantum-resistant algorithms through an open competition and evaluation process. These algorithms, designed to withstand quantum attacks, focus on two primary areas: 1. Key Establishment: Protecting methods like Diffie-Hellman and RSA key exchange. 2. Digital Signatures: Securing authentication processes.  Migration Framework The document provides a phased approach to migrating cryptographic systems to PQC: 1. Assessment Phase:    - Inventory cryptographic dependencies in current systems.    - Evaluate systems at risk from quantum threats based on sensitivity and lifespan. 2. Preparation Phase:    - Conduct pilot testing of candidate PQC algorithms in existing infrastructure.    - Develop a hybrid approach that combines classical and post-quantum algorithms to ensure interoperability during transition. 3. Implementation Phase:    - Replace vulnerable cryptographic methods with PQC in a phased manner.    - Ensure scalability, performance, and compatibility with existing systems. 4. Monitoring and Updates:    - Continuously monitor the effectiveness of implemented solutions.  Challenges in PQC Migration - Performance Impact: PQC algorithms often have larger key sizes, increased latency, and greater computational demands compared to classical algorithms. - Interoperability: Ensuring smooth integration with legacy systems poses significant technical challenges.  Best Practices - Use hybrid encryption to maintain compatibility while testing PQC algorithms. - Engage in collaboration with vendors, industry groups, and government initiatives to align with best practices and standards. Conclusion The transition to post-quantum cryptography is a proactive measure to secure data and communications against future threats. NIST emphasizes the importance of starting preparations immediately to mitigate risks and ensure a smooth, efficient migration process. Organizations should focus on inventorying dependencies, piloting PQC solutions, and developing cryptographic agility to adapt to this transformative technological shift.

  • View profile for Shellie Delaney

    CIO | The Rebuilder | Enterprise Architecture, Data Governance, Cybersecurity & AI Readiness | M&A, ERP & Regulated Transformation | $1.5B+ Value Delivered

    4,103 followers

    Quantum risk will not break the network first. It will break trust first. The OSI model still explains how data moves. In a post-quantum world, it also becomes a useful lens for understanding where trust dependencies are embedded across protocols, identities, endpoints, applications, firmware, and management planes. Most leaders still look at the OSI stack as a classroom model. I look at it as an exposure map. Quantum computing does not pressure every layer equally. The most immediate pressure falls on quantum-vulnerable public-key mechanisms used for key establishment and digital signatures, including PKI, certificates, TLS handshakes, VPN key exchange, software signing, and related trust services. NIST finalized its first three post-quantum cryptography standards in 2024 and is encouraging organizations to begin transitioning now. That matters because long-lived sensitive data is already exposed to a harvest now, decrypt later risk models. NIST’s migration work specifically calls out TLS as one of the most widely deployed security protocols and a prime target for that threat. When you map that back to the OSI model, the message is clear: The problem is not Layer 1 cabling. It is the cryptographic trust fabric spanning protocols, identities, endpoints, applications, firmware, and management planes that still depends on quantum-vulnerable public-key cryptography. That is why this is not just a cryptography discussion. It is an enterprise architecture discussion. A PKI discussion. A certificate lifecycle discussion. A software signing discussion. A vendor governance discussion. An OT and IoT lifecycle discussion. NIST guidance and CISA’s OT-focused post-quantum materials both point organizations toward first identifying where quantum-vulnerable cryptography exists across hardware, software, services, firmware, PKI, IT, OT, and vendor dependencies before trying to migrate. For boards and executive teams, the real questions are straightforward: Do we know where we use quantum-vulnerable public-key cryptography? Do we know which data must remain confidential longer than our migration window? Do we know which OT, IoT, and embedded assets are not crypto-agile enough to adapt? Do our vendors have a credible roadmap for PQC in certificates, TLS, VPNs, browsers, firmware, and signing? The OSI model still explains how data moves. In 2026, it can also help explain where trust dependencies may fail first if cryptographic migration is delayed. Quantum readiness is not about hype. It is about rebuilding the trust layer before the threat catches up. #Cybersecurity #PostQuantumCryptography #EnterpriseArchitecture

  • View profile for Roman Kruglov

    Cloud & Infrastructure Leader | Cloud Strategy & Architecture | Cybersecurity, Zero Trust & AI | Building Secure, Resilient Enterprises | Board Advisor

    2,372 followers

    Quantum computing will shred RSA and ECC like tissue paper, yet many are still treating the migration to Post-Quantum Cryptography as a "later" problem. ⬇️ On August 13, 2024, NIST finalized the first three PQC standards, signaling that the era of "Harvest Now, Decrypt Later" has met its match. Whether you are managing service account sprawl or securing cloud ecosystems, these standards are ready for immediate use to prevent your digital keys from shattering. The New Standards Framework NIST has provided three primary tools to secure our infrastructure against quantum threats: ➡️ FIPS 203 (ML-KEM): Derived from CRYSTALS-Kyber, this is the primary standard for general encryption. It is built for speed and uses small encryption keys that are easy to exchange. ➡️ FIPS 204 (ML-DSA): Based on CRYSTALS-Dilithium, this serves as the primary standard for digital signatures. ➡️ FIPS 205 (SLH-DSA): Utilizing the Sphincs+ algorithm, this acts as a stateless hash-based backup for digital signatures in case lattice-based methods prove vulnerable. A Practical Migration Path Migrating isn't just a technical swap; it's a strategic shift toward "antifragile" identity. You can begin strengthening your enterprise posture today by following these steps: ✔️ Inventory Your Endpoints: Identify where legacy RSA and ECC are buried in your stack. ✔️ Test in Hybrid Mode: Use a combination of classical and PQC algorithms to ensure stability. ✔️ Update Your Stack: Leverage tools like liboqs or OpenQuantumSafe to update your TLS 1.3 implementations. We often delay security updates because we fear downtime or "friction," but quantum doesn't negotiate. Adopting these standards now is how we stay one step ahead of state actors and safeguard the future of our data.

  • View profile for Dr. Paul de Souza

    Founder & President at CSFI.US | Securing Critical Infrastructure through Cyber Threat Intelligence | National Security Advisor | University Professor

    52,843 followers

    🔑"𝐇𝐚𝐫𝐯𝐞𝐬𝐭 𝐍𝐨𝐰, 𝐃𝐞𝐜𝐫𝐲𝐩𝐭 𝐋𝐚𝐭𝐞𝐫" (𝐇𝐍𝐃𝐋) attacks intercept RSA-2048 or ECC-encrypted files, stockpiling them for future decryption. Once a powerful quantum computer comes online, they can unlock those archives in hours, exposing years’ worth of secrets. This silent threat targets everything from personal records to diplomatic communications. 🔐 📌 HOW CAN CYBERSECURITY LEADERS AND EXECUTIVES PREPARE? 🎯🎯𝐁𝐮𝐢𝐥𝐝 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐀𝐠𝐢𝐥𝐢𝐭𝐲: Ensure your systems can swiftly swap out cryptographic algorithms without extensive re-engineering. 𝐂𝐫𝐲𝐩𝐭𝐨-𝐚𝐠𝐢𝐥𝐢𝐭𝐲 𝐢𝐬 𝐭𝐡𝐞 𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐭𝐨 𝐫𝐚𝐩𝐢𝐝𝐥𝐲 𝐭𝐫𝐚𝐧𝐬𝐢𝐭𝐢𝐨𝐧 𝐭𝐨 𝐮𝐩𝐝𝐚𝐭𝐞𝐝 𝐞𝐧𝐜𝐫𝐲𝐩𝐭𝐢𝐨𝐧 𝐬𝐭𝐚𝐧𝐝𝐚𝐫𝐝𝐬 𝐚𝐬 𝐭𝐡𝐞𝐲 𝐛𝐞𝐜𝐨𝐦𝐞 𝐚𝐯𝐚𝐢𝐥𝐚𝐛𝐥𝐞. Designing for agility now will let you plug in PQC algorithms (or other replacements) with minimal disruption later. 🎯𝐈𝐦𝐩𝐥𝐞𝐦𝐞𝐧𝐭 𝐇𝐲𝐛𝐫𝐢𝐝 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐲: Do not wait for the full PQC rollout. 👉 𝐒𝐭𝐚𝐫𝐭 𝐮𝐬𝐢𝐧𝐠 𝐡𝐲𝐛𝐫𝐢𝐝 𝐞𝐧𝐜𝐫𝐲𝐩𝐭𝐢𝐨𝐧 𝐍𝐎𝐖! Combine classic schemes like ECDH or RSA with a post-quantum algorithm (e.g. a dual key exchange using ECDH + Kyber). 🎯𝐌𝐚𝐢𝐧𝐭𝐚𝐢𝐧 𝐚 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐁𝐢𝐥𝐥 𝐨𝐟 𝐌𝐚𝐭𝐞𝐫𝐢𝐚𝐥𝐬 (𝐂𝐁𝐎𝐌): 👉𝐈𝐧𝐯𝐞𝐧𝐭𝐨𝐫𝐲 𝐚𝐥𝐥 𝐜𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐢𝐜 𝐚𝐬𝐬𝐞𝐭𝐬 𝐢𝐧 𝐲𝐨𝐮𝐫 𝐨𝐫𝐠𝐚𝐧𝐢𝐳𝐚𝐭𝐢𝐨𝐧: algorithms, key lengths, libraries, certificates, and protocols. A CBOM provides visibility into where vulnerable algorithms (like RSA/ECC) are used and helps prioritize what to fix. 🎯🎯𝐀𝐥𝐢𝐠𝐧 𝐰𝐢𝐭𝐡 𝐍𝐈𝐒𝐓’𝐬 𝐐𝐮𝐚𝐧𝐭𝐮𝐦 𝐌𝐢𝐠𝐫𝐚𝐭𝐢𝐨𝐧 𝐑𝐨𝐚𝐝𝐦𝐚𝐩: Follow expert guidance for a structured transition. 𝐓𝐡𝐞 𝐔.𝐒. 𝐠𝐨𝐯𝐞𝐫𝐧𝐦𝐞𝐧𝐭 (𝐂𝐈𝐒𝐀, 𝐍𝐒𝐀, 𝐚𝐧𝐝 𝐍𝐈𝐒𝐓) 𝐚𝐝𝐯𝐢𝐬𝐞𝐬 𝐞𝐬𝐭𝐚𝐛𝐥𝐢𝐬𝐡𝐢𝐧𝐠 𝐚 𝐪𝐮𝐚𝐧𝐭𝐮𝐦-𝐫𝐞𝐚𝐝𝐢𝐧𝐞𝐬𝐬 𝐫𝐨𝐚𝐝𝐦𝐚𝐩, starting with a thorough cryptographic inventory and risk assessment. Keep abreast of NIST’s PQC standards timeline and recommendations.  National Institute of Standards and Technology (NIST) #𝐇𝐍𝐃𝐋 Cyber Security Forum Initiative #CSFI 🗝️ Now is the time to future-proof your encryption! 🗝️ 𝑌𝑜𝑢 𝑠ℎ𝑜𝑢𝑙𝑑𝑛'𝑡 𝑎𝑠𝑠𝑢𝑚𝑒 𝑡ℎ𝑎𝑡 𝑦𝑜𝑢𝑟 𝑑𝑎𝑡𝑎 𝑖𝑠 𝑠𝑒𝑐𝑢𝑟𝑒 𝑗𝑢𝑠𝑡 𝑏𝑒𝑐𝑎𝑢𝑠𝑒 𝑖𝑡 𝑖𝑠 𝑒𝑛𝑐𝑟𝑦𝑝𝑡𝑒𝑑...

  • View profile for David Duong, CFA

    Institutional Crypto Markets | Former Global Head of Research, Coinbase | Board Director & Advisor focused on research-to-commercial impact, macro/on-chain integration

    10,952 followers

    *** The Quantum Threat (Part 2) *** Mitigating Quantum Risks A plausible roadmap is taking shape to counteract these vulnerabilities. The primary long-term strategy is to integrate post-quantum cryptography into the network – using new algorithms that are resistant to quantum attacks. The U.S. National Institute of Standards and Technology (NIST) has a short list of PQC protocols that include CRYSTALS-Dilithium, SPHINCS+, and FALCON. Note too that we have established the Coinbase Independent Advisory Board on Quantum Computing and Blockchain, a group of world-renowned experts convened to evaluate the implications of quantum computing for the blockchain ecosystem and provide clear, independent guidance to the broader community. Guidance from Chaincode Labs – a bitcoin research and development center – sketches two multi-year processes to mitigate the risk. First, if quantum computing experiences a sudden breakthrough, a short-term contingency path could be implemented within two years that quickly deploys protective measures to secure the network by prioritizing migration transactions exclusively. On the other hand, if quantum breakthroughs do not occur, a longer-term path could be used to standardize quantum-resistant signatures via a soft fork, though post‑quantum signatures are larger and slower to verify than today’s signatures, so wallets, nodes, and fee economics need time to adapt. This could take up to seven years to fully implement. Fortunately, the most advanced quantum machines today have fewer than 1,000 qubits, far short of what would be needed to compromise the cryptography that secures blockchains like Bitcoin. Promising technical proposals to address the quantum threat include: 🔹 BIP-360 (Pay-to-Quantum-Resistant-Hash) to keep public keys off-chain and pave the way for post quantum signatures 🔹 BIP-347 (re-enabling OP_CAT to support hash-based one-time signatures) 🔹 Hourglass (rate-limiting spends from vulnerable outputs to stabilize the transition) Best practices include avoiding address reuse, moving vulnerable UTXOs to unique destinations, and developing client-facing materials to institutionalize quantum-ready operations. This approach is supported by the current understanding that vulnerable scripts are not in production and that per-address fund limits mitigate concentration risk. Overall, we do not view quantum computing as an imminent threat because today’s machines are orders of magnitude too small to break Bitcoin’s cryptography. That said, we are glad that the open-source community remains vigilant about engineering post-quantum migration paths.

Explore categories