America's Cryptocurrency 'Clarity Act' Fails Spectacularly, Despite Hundreds of Millions in Industry Lobbying
Read more of this story at Slashdot.
Read more of this story at Slashdot.
A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption.
The working groupโs report, prepared in June at the G7 Summit in France, said organizations โcan no longer afford to postponeโ work transitioning critical systems and data to โpost-quantumโ forms of encryption.
โThe quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence,โ the working group report said. โYet, a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk.โ
Instead, leaders in government and industry โmust reframe the quantum threat from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure.โ
The report acknowledged uncertain timelines for quantum computers, but identified that threats like harvesting current sensitive, encrypted data to decrypt it in the future do exist today.
The report also warned that quantum computers could compromise authentication and assurance mechanismsโby forging trusted data or stealing confirmationโ jeopardizing secure communications and legal contracts.
The working groupโs conclusions are largely in line with what governments have been recommending for years, urging industry to inventory and prioritize their critical systems and shift over to newer, โpost-quantum cryptographyโ encryption algorithms.
These encryption algorithms, originally designed by independent cryptographers and vetted by the National Institute for Standards and Technology and National Security Agency, will be used to protect the governmentโs own systems and data from cybercriminals and foreign governments.
The Trump administration recently issued an executive order directing agencies to boost the domestic quantum industry and move up internal timelines for migrating to PQC encryption from 2035 to 2030. Google, a potential industry bellwether, and other companies have opted to move their own migration timelines to 2029.
But while that work has proceeded on schedule in some areas, like the federal government and the highly regulated financial sector, it has lagged in other industries where owners and operators feel they have more immediate concerns than quantum computers.
โWe acknowledge that transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition that can only be achieved with early engagement, coordinated planning and informed decision making across the public and private sectors,โ the working group wrote.
While often referred to as โPost-Quantumโ encryption, the reality is more complex. Cryptographers believe the algorithms selected by NIST and NSA will stand up to attacks from a quantum computer, but since one doesnโt exist today, designing cryptographic protections against it requires some guesswork and mathematical estimation.
Estimates can be wrong, or overlook the entire cryptographic attack surface. Some NIST-selected algorithms have already been broken with traditional computers or AI. Thatโs why the agency backs multiple algorithms and concepts like โcrypto-agility,โ allowing organizations to quickly switch between them.
The G7 report was signed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the UKโs National Cyber Security Centre (NCSC), The French Cybersecurity Agency (ANSSI), Germanyโs Federal Office of Information Security (BSI), Canadaโs Communications Security Establishment (CSE), Japanโs National Cybersecurity Office (NCO) and Italyโs National Cybersecurity Agency (ACN).
The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.