We are migrating all of PKI to the more costly and less efficient postquantum cryptography, even though nobody will reasonably use a quantum computer to snoop on your home IoT daily reports. I mean, I assume that what you are doing on your free time is not worth governmental attention.
The rationale of mass migration is that if you don't impose it, nobody migrates. This has notably been the case with famously insecure SSL parameters (512 bits RSA keys, PKCSv1.5...). And many companies may believe they are not critical, which might be true until it is not.
Case in point: you manufacture walkie talkies and suddenly your products have bombs inside. Or you maintain a compression library for free and suddenly you are shipping a backdoor to all Linux products.
Exactly. Reasonably speaking, nobody tries to pierce encryption at all, ever. That doesn't mean we should stick with 3DES. Reasonably speaking, nobody will try to break in to your house at all, ever. That doesn't mean you shouldn't lock your door. Security is already about protecting against infrequent events.
> And many companies may believe they are not critical, which might be true until it is not.
I'm at a K-12 public school. That shouldn't be on the front lines of a war with Iran, but, in cybersecurity terms, we are. If you disrupt a school district, you disrupt one of the largest employers in the area. You also disrupt the largest childcare facility in the area. The amount of economic damage you could inflict on a community by disrupting the public school system is pretty extreme compared to the amount of funding provided to protect it.
Sure, but here I guess the main idea is that everything is linked, especially how libraries package managers work nowadays.
In order to compromise the big player, you only have to compromise the weakest link in its supply chain. In effect that means that leaving the migration optional is as useless as doing nothing.
As for "nobody will reasonably use a quantum computer to snoop on your home IoT daily reports", they already have access to your data one way or another, so really no need for a quantum computer. :P
I don’t understand your comparison with walkie talkies. What are you trying to highlight here? In the case of the pager attack in Lebanon the devices were booby-trapped. Are you trying to say that the device designers should have somehow done something about it? I cannot really make sense of it
My point is that the business of pagers is rarely seen as something likely to be booby trapped by a nation state. Yet in the context of Lebanon it happened.
I don't remember where the compromise happened (factory, distribution, sell point), but very clearly at least one of them did not expect to be a critical asset in the Israel - Lebanon war.
Pretty much everyone. There's a reason people lost money with ftx, Mt gox and other scams.
Managing your private keys is cumbersome, error prone, requires some computer literacy, the list goes on.
Tbh I have been kind of impressed by how fast L2 businesses brought back centralisation in every possible way. I guess it's more efficient for them.
In the same way, the internet was supposed to be decentralised, everyone being in charge of their own servers. But in practice nobody has the time to set up their own MX servers.
> Despite the limitations in size and speed of today’s quantum computers, our algorithm provides quantifiable liquidity savings when applied to the Canadian HVPS using a 30-day sample of transaction data. By reordering batches of 70 payments, we achieve an average of Canadian (C) $240 million in daily liquidity savings, with a settlement delay of approximately 90 seconds
It has to be noted that the technology used (quantum annealing) is at best erm disputed, and that the company DWave has made very wild claims in the past. Also note that many "quantum speedups" have been de-quantumized, i.e. classical algorithms with equal or even better performance have been developed, sometimes by drawing inspiration from the quantum algorithm. Quantum supremacy is still quite unclear.
Now, could the problems we are talking about be efficiently solved on a classical computer? Maybe. But if nobody knows how to do it, we might just as well use the quantum computer.
Man, the CBOM is such a pain. There is no standardised format yet (let alone efficient tools for crypto discovery), nobody knew what it was one year ago but now every client is asking ours anyway.
Tell me about it! We've got slightly under 10'000 distinct software assets we are trying to catalogue. There are now a handful of vendors claiming to be able to scan for crypto, but they all suck.
I'm not even there for my employer. I have compiled a list of ~20 different inventory/CBOM solutions and I cannot even fathom how to move to the next step other than picking a few vendors at random and ask them for a demo, but the public info I found was not convincing.
While I can assume these tools do a decent job at crypto asset discovery (a `grep -r "-----BEGIN RSA PRIVATE KEY-----"` is not the hardest product to design), I have no idea what to do for code scanning. CBOMkit and friends do not scan C code, which we actually need.
There has been a lot of new stuff over the last few years.
For instance, breaking RSA or ECDSA is requiring much fewer logical qubits than previously thought, and thus fewer physical qubits as well. Progress in error codes, quantum processing etc. made it that in 2019, it was estimated we needed ~20 million noisy qubits to factor RSA 2048. In 2025, we know we need fewer than 1 million. [0]. Some other papers even claim the need of 1000 physical qubits but they rely on a very exotic architecture so I would not consider them feasible.
Progress on the hardware is also continuing, see [1]. Researchers managed to have functional-ish error correction for the first time last year, and experts in the topic are confident that a cryptographically relevant computer will appear in around 15 years.
I personally am less optimistic than the experts (admittedly I am not an expert either), but there is enough activity to get worried for critical infrastructure.
Regarding the factoring issue, as you point out factoring 15 and factoring 21 are two very different tasks. The first one can be used to show that your quantum computer is indeed doing quantum computation; the second will prove that you have a functional error correcting code. If you can factor 21, it is probably only a matter of months/maybe a few years until you factor RSA 2048. As Scott Aaronson said [3], "Once you understand quantum fault-tolerance, asking “so when are you going to factor 35 with Shor’s algorithm?” becomes sort of like asking the Manhattan Project physicists in 1943, “so when are you going to produce at least a small nuclear explosion?”"
Y2K devs had it easy, they knew the bug would arrive and when.
The problem with PQC is not that nobody knows when a CRQC (cryptographically relevant quantum computer) will appear, but that by the time it appears, you are already ~10 years too late for migrating (5 years of migration time and 5 years of your adversary silently storing all your classical crypto messages to decrypt them at a later time, the "harvest now decrypt later" attack).
Of course the HNDL attack is only relevant for the most critical pieces of infrastructures, 99% of companies are not a real target for that, especially given the storage cost of such an attack.
There is also the "trust now, forge later" attack, in which a CRQC could break a chain of trust (i.e. digital signatures), and that attack does not need any storage besides the logs of past messages. If you want to guarantee authenticity and unforgeability of your logs for, say, 20 years, you better hope that no CRQC appears by 2050 at least. Once again, it only concerns maybe 1% of companies.
But hey, these 1% companies are exactly the ones that are needing specialised crypto equipment so the move from ANSSI tracks.
I personally do not believe a CRQC will appear before 2050 either. I am willing to bet some money on it, despite researchers in quantum computers being quite confident it will appear in the next 15 years, but I am not willing to bet the entirety of Internet security on it.
Don't quote me on this but I once heard that in the EU you always need to confirm purchases, ie. you cannot have the Amazon 1-click system.
But in general, yes, having a confirmation dialog on important buttons is good UX; similarly as to setting minimum/maximum saturation will increase accessibility by visually impaired people, epileptic people etc.
Pretty sure this is wrong. Code pénal, art. 434-25, translated with deepl.
"Any attempt to publicly discredit a judicial act or decision—through actions, words, writings, or images of any kind—under circumstances likely to undermine the authority or independence of the judiciary is punishable by six months’ imprisonment and a fine of 7,500 euros.
The provisions of the preceding paragraph do not apply to technical comments or to acts, statements, writings, or images of any kind intended to seek the reversal, annulment, or review of a decision."
You are free to disagree with the ruling, but you cannot say that the trial is a parody of justice, the judge biased and the whole thing a conspiracy (cough cough Sarkozy)
10 years ago I won the only hackathon I participated in (not by choice). The jury was especially impressed in our report with the AI section. That part was a bunch of technobabble that I wrote, more or less saying "in the future the system should do this and that", quoting some popular algos from that time. None of it was implemented in our demo in any way, shape or form. They checked that I knew what I was talking about, and talking with confidence was all it took.
We did not even try to win the hackathon, just to get a passing grade.
I mean, this is hardly surprising. Who takes the most points is an accumulative score from subjective opinions(judges, audience, etc.). We didn't win the one in Amsterdam but got second: Around 50 teams began, 20 managed to deliver something, even if the winner is picked at random, that's a 5% chance, which is a very high random chance. When you toss in several senior developers(who at the time worked together in the same company and team), a dedicated frontend developer, ux designer and a few others, second place no longer sounds that impressive, but we all had fun. But to my mind, the value of hackathons is(or rather 'was', given what I said above) forcing people to push their mental abilities to the limits. If being able to write coherent text is good enough to make you the top performer, then we clearly have a problem.
My point is that flashy presentations already were an issue before the rise of LLMs. The evaluation of a hackathon relies on presentations and subjective opinions rather than pure benchmark of technical assets, there is nothing new under the sun here.
You can now win with 20 skills.md files now, you could win with "it would be great to use this sexy tech" 10 years ago.
Seems like the blog succumbed to the HN hug of death (`Actioning this file would cause "jbkempf.com//blog/2026/dav2d/" to exceed the per-day file actions limit of 160000 actions, try again later`), is there a copy available somewhere?
The rationale of mass migration is that if you don't impose it, nobody migrates. This has notably been the case with famously insecure SSL parameters (512 bits RSA keys, PKCSv1.5...). And many companies may believe they are not critical, which might be true until it is not.
Case in point: you manufacture walkie talkies and suddenly your products have bombs inside. Or you maintain a compression library for free and suddenly you are shipping a backdoor to all Linux products.
reply