❌

Reading view

There are new articles available, click to refresh the page.

The G7 tells industry to hurry up and prep for post-quantum encryption

A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption.

The working group’s report, prepared in June at the G7 Summit in France, said organizations “can no longer afford to postpone” work transitioning critical systems and data to “post-quantum” forms of encryption.

“The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence,” the working group report said. “Yet, a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk.”

Instead, leaders in government and industry “must reframe the quantum threat from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure.”

The report acknowledged uncertain timelines for quantum computers, but identified that threats like harvesting current sensitive, encrypted data to decrypt it in the future do exist today.

The report also warned that quantum computers could compromise authentication and assurance mechanisms—by forging trusted data or stealing confirmation— jeopardizing secure communications and legal contracts.

The working group’s conclusions are largely in line with what governments have been recommending for years, urging industry to inventory and prioritize their critical systems and shift over to newer, “post-quantum cryptography” encryption algorithms.

These encryption algorithms, originally designed by independent cryptographers and vetted by the National Institute for Standards and Technology and National Security Agency, will be used to protect the government’s own systems and data from cybercriminals and foreign governments.

The Trump administration recently issued an executive order directing agencies to boost the domestic quantum industry and move up internal timelines for migrating to PQC encryption from 2035 to 2030. Google, a potential industry bellwether, and other companies have opted to move their own migration timelines to 2029.

But while that work has proceeded on schedule in some areas, like the federal government and the highly regulated financial sector, it has lagged in other industries where owners and operators feel they have more immediate concerns than quantum computers.

“We acknowledge that transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition that can only be achieved with early engagement, coordinated planning and informed decision making across the public and private sectors,” the working group wrote.

While often referred to as “Post-Quantum” encryption, the reality is more complex. Cryptographers believe the algorithms selected by NIST and NSA will stand up to attacks from a quantum computer, but since one doesn’t exist today, designing cryptographic protections against it requires some guesswork and mathematical estimation.

Estimates can be wrong, or overlook the entire cryptographic attack surface. Some NIST-selected algorithms have already been broken with traditional computers or AI. That’s why the agency backs multiple algorithms and concepts like “crypto-agility,” allowing organizations to quickly switch between them.

The G7 report was signed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), The French Cybersecurity Agency (ANSSI), Germany’s Federal Office of Information Security (BSI), Canada’s Communications Security Establishment (CSE), Japan’s National Cybersecurity Office (NCO) and Italy’s National Cybersecurity Agency (ACN).

The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.

Bipartisan Senate bill aims to prepare energy sector for Q-Day

A new bipartisan Senate bill would require federal regulators to prepare the U.S. electric grid for cybersecurity threats from quantum computers and create a technical sandbox to study how the technology could impact  both information and operational technology systems.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Sens. Mike Rounds, R-S.D., and Chris Coons, D-Del., would direct the Federal Regulatory Energy Commission when reviewing proposed reliability regulatory standards for electricity owners and operators under the Federal Power Act.

FERC updates its reliability standards to account for emerging cybersecurity concerns, and the legislation would expand those reviews to include the future threat of hacks from quantum computers.

The legislation also directs FERC to explore potential uses of post-quantum cryptography in IT and OT systems and “take such action the Commission determines to be appropriate based on that consideration.”

In a statement, Coons said quantum computing brings “new economic opportunities” along with “tremendous cybersecurity risks.”

“As the technology races forward and our adversaries continue to seek vulnerabilities in our critical systems, we need to pass the Quantum-GUARD Act to ensure our government is using every available tool to meet this threat,” said Coons.

The federal government has been an early adopter of post-quantum cryptography for its digital systems. The National Institute for Standards and Technology has worked with cryptographers to develop new “post-quantum” encryption algorithms that will be used by most governments and the private sector.

Under the Biden administration, most federal agencies were required to migrate their systems and data to “PQC” encryption by 2035. In June, an executive order from the Trump administration pushed that timeline up to 2030. 

Ali Shaikh, CEO of Graphiant, a networking infrastructure startup, told CyberScoop that the bill would represent a good start in terms of pushing greater adoption of quantum-resistant encryption, “the real work is upgrading infrastructure, not applications, ahead of the deadlines.”

Evgeny Gervis, CEO of SafeLogic, compared the energy sector’s challenges to previous efforts by FERC and industry to gain adoption at scale for other technological upgrades, like smart grid equipment. Among those challenges is prioritizing security upgrades in a sector where reliability is paramount.

“The highest priority for electric utilities will be preservation of integrity and availability, both services that are widely supported by legacy public key cryptographic controls that are quantum vulnerable,” said Gervis. “It is essential that quantum computers do not undermine the integrity and authenticity of SCADA communications or the software update process.“

The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.

Supply chain challenges loom large in quantum race, White House official says

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

Here’s what Anthropic found when it turned Mythos loose on encryption algorithms

Anthropic researchers used Claude Mythos Preview to find new weaknesses in two cryptographic methods, the company said Tuesday, including one that is being considered by the National Institute of Standards and Technology for both traditional and quantum computing.  

In a blog post detailing the work, the frontier AI company called it a “substantial” research advancement, but also emphasized that neither flaw affects software now in use.

“The attacks described in these two papers are the strongest attacks we have found to date,” the company wrote in the post. 

One of the weaknesses found was in HAWK, a digital signature scheme under review by the NIST as part of a search for encryption methods that could survive attacks from quantum computers. Working with a human researcher, the AI system found a mathematical shortcut, known as a nontrivial automorphism, in the lattice structure (a complex mathematical grid underpinning its security) HAWK relies on.

The discovered weakness cuts HAWK’s effective key strength in half, meaning key sizes would need to double to keep the same level of security. Anthropic said that change would erase much of what made HAWK an appealing candidate in the first place.

Ellen Boehm, senior vice president of strategy and AI innovation at Keyfactor, a digital identity and cryptography management provider, told CyberScoop that research like Anthropic’s proves that the NIST PQC evaluation process is working. 

She also said the research “elevates the importance for organizations to have visibility of where cryptography sits inside their enterprise, what business systems and processes it’s connected to, and the need for PQC readiness, if they haven’t already built a plan.” 

The other flaw was found in a weakened version of the Advanced Encryption Standard, or AES, the cipher NIST adopted in 2001 and the most widely used method for scrambling data in transit. Working largely on its own, Mythos invented a mathematical shortcut dubbed the “Möbius Bridge.” While real-world encryption scrambles data through 10 sequential layers, or “rounds,” researchers regularly study a simplified seven-round test version to measure security margins. In previous theoretical attacks, codebreakers had to check 256 separate values against a memory table, but Mythos created a shortcut that eliminated that lookup process entirely.

Combined with other optimizations, this discovery made the strongest known theoretical attack against seven-round AES 200 to 800 times faster. The attack is purely theoretical: It requires an impossible amount of target data — over 400 octillion messages — and cannot touch the full 10-round encryption protecting everyday software. Additionally, Anthropic pointed out that real-world systems remain completely safe.

Anthropic said it followed standard disclosure practices, notifying HAWK’s designers in June and coordinating public release with a NIST mailing list, and briefing government and industry partners beforehand. It also worked with researchers at ETH Zurich, Tel Aviv University and the University of Haifa to build a shared testing tool, called CryptanalysisBench, meant to let other researchers measure how AI systems perform against a range of ciphers.

The findings come as frontier AI models are being deployed by cybersecurity researchers in order to find vulnerabilities in all kinds of software. In June, intelligence agencies in the Five Eyes alliance warned that advanced AI models capable of wreaking havoc in the cyber domain are “months away.” However, a recent report found that despite the avalanche of bugs being unearthed, the threat level across the internet has not materially changed. 

Anthropic said it expects the same AI capabilities eventually to be applied to systems already in wide use, raising a separate question it said it has not yet resolved: how researchers, companies and governments should respond if a language model uncovers a flaw in a cryptographic system that protects critical infrastructure.

“As we develop increasingly powerful cryptanalytic results, it would be prudent to consider how researchers should react if a language model were to discover vulnerabilities in cryptosystems where attacks do have an immediate real-world impact,” the company wrote. “We hope that our work here will help launch these conversations.” 

Boehm said work like Anthropic’s further shows that enterprises should not rest on their laurels with any facet of their security apparatus. 

“AI is becoming a powerful tool for many things, including software quality assurance, code development, and in this case cryptographic analysis,” she told CyberScoop. “As AI tools become more widely and continuously used, it just elevates the need for enterprises to treat their trust infrastructure in an ongoing, operational manner versus thinking of it as a static environment that only changes every few years as new cryptographic algorithms are released.”

The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on CyberScoop.

Lawrence’s List 081916

Lawrence Hoffman // So Microsoft is open sourcing PowerShell and putting it on Linux. Realistically Linux already has a full suite of administrative tools and some very powerful scripting languages […]

The post Lawrence’s List 081916 appeared first on Black Hills Information Security, Inc..

❌