The Qubit Cometh: Preparing for post-quantum cybersecurity
Once reserved for science fiction, quantum computing is increasingly a hot-button topic for discussion in various circles—not least in cybersecurity. While projections of when cryptographically relevant quantum computers (CRQC) will become available vary quite widely, researchers continue to make breakthroughs in their development. Moreover, the inevitability of CRQCs and the relative predictability of their impact on cybersecurity procedures make them a risk worth mitigating now.
What is quantum computing?
Though doubtless an over-simplification, it suffices to say that quantum computing leverages complicated physical properties, such as entanglement and superposition, of rare particles to perform computations that would be prohibitively difficult for traditional “1s-and-0s” (binary) computer architectures. While the notion that quantum computing will be unilaterally faster and more efficient than traditional computing is not true in all cases, it is for certain tasks. Scientists believe that quantum computing will revolutionize the way we model complex chemical reactions, understand nuanced economic trends, and build cybersecurity systems.
How will quantum computing impact cybersecurity?
Analysis of quantum computing’s impacts on the domain of cybersecurity tends to focus on encryption. A core principle of modern security, the many methods and applications of encryption accomplish a simple goal: prevent the bad guys from reading sensitive information. Where other cybersecurity techniques focus on preventing malicious actors from collecting information or catching them in the act, encryption techniques assume that the information will be acquired, one way or another, and make that information useless to anyone without proper access. This is accomplished using math, and lots of it. The sensitive information is converted into a string of numbers, which are then scrambled using one of many algorithms, such that they can only be readily unscrambled using a special, numerical key. Attempting to decode adequately encrypted data without a key is technically possible but takes so much time and computing resources that it is generally not considered worth doing in practice.
That’s where quantum computing changes things. Pre-quantum encryption standards can be defeated with relative ease using algorithms designed for quantum computers, so much so that the data currently protected by these algorithms is, for all intents and purposes, not encrypted at all for a quantum-enabled threat actor. Quantum encryption will certainly step in to fill the gap but will almost certainly be prohibitively expensive for all but the largest organizations. What’s more, hackers don’t need to wait until CRQCs become available to begin investment in quantum-enabled attacks.
A “harvest-now-decrypt-later,” or “post-hoc decryption” attack involves hackers stealing massive amounts of encrypted data with the intent of decrypting it once they have access to a CRQC. Imagine a bank heist: what if, instead of dodging cameras and distracting guards while breaking through the heavy vault door, the thieves could instead steal the whole vault and crack the combination from the comfort and safety of their dimly lit warehouse? They might not know precisely what’s in the vault, just as hackers don’t really know what data they are acquiring when it is encrypted, but this approach is lower risk and easier to accomplish, especially at-scale. Even if not every encrypted file contains valuable information, the odds that they get something useful across terabytes of data make this type of attack a tempting option for certain types of threat actors.
This risk is not purely speculative, either. United States entities like NIST and the NSA, as well as European regulators, are warning about just such an attack. In response, NIST has released a list of encryption algorithms rated for post-quantum cryptography (PQC) and recommended their immediate adoption across the public and private sector to reduce risk. Organizations that maintain good cybersecurity hygiene—such as accurate risk-informed data inventories, data stratification, network segmentation, and data life-cycle policies—also reduce their risks from such an attack. To learn more about quantum readiness through proactive, pre-incident risk management, contact Blair Dawson or anyone on the McDonald Hopkins' Data Privacy Team.