Episode 165: Security Awesomeness Podcast

Post-Quantum Cryptography: Why ‘Harvest Now, Decrypt Later’ Matters

video
Play Video

Quantum computing is coming, and it changes everything about how you think about cryptography. In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen from Enterprise Management Associates (EMA) talks with Saqib from Gigamon about post‑quantum cryptography (PQC), the “harvest now, decrypt later” threat, and why visibility into encrypted traffic is essential for your PQC roadmap.

0:03

Hello and welcome to the Cybersecurity Awesomeness Podcast.

0:07

Hosted by Enterprise Management Associates, an industry leading technology research and consultant group that provides deep insights across the full spectrum of technology and cybersecurity solutions.

0:17

The Cybersecurity Awesomeness Podcast will take a deep dive into the security topics that are top of mind for information security practitioners, IT professionals, and technology business leaders.

0:28

Join security expert Chris Steffen, Vice President of Research at EMA for some truly awesome conversations.

0:34

Chris, take it away.

0:36

Good morning, good afternoon, good evening.

0:38

Welcome to the Cybersecurity Awesomeness podcast.

0:40

I am your host.

0:41

My name is Chris Steffen.

0:43

Today, joining me is Saqib from Gigamon.

0:46

We are going to talk about PQC.

0:49

He's going to give you a brief introduction about himself.

0:51

But again, as you all know from listening to this podcast, PQC is something that has my attention.

0:57

I sincerely hope at this point that it has your attention to, I want to take and make certain that you are hearing from real world experts on why PQC and quantum computing isn't necessarily scary and doomsday and so on and so forth.

1:14

But at the same time, it is something as IT professionals we need to be thinking about and need to be preparing for.

1:21

And so to that end, I am bringing in these experts that can take and talk to you about their perspective, some of what their companies are doing, give you a basic idea of things that you need to be doing to prepare for the the quantum universe that we live in.

1:36

So with that, Saqib, why don't you give me a quick introduction about what you do and then we'll kind of take it from there.

1:43

Hi, thank you very much, Chris.

1:45

I'm Saqib, I'm part of the product management team at Gigamon.

1:50

I look after security decryption and security, other security related products.

1:56

My special interest is in PQCII.

2:00

Think we need to be talking much more about it than we are today.

2:03

It needs to be made much, paid much more attention than what people are paying attention to it today.

2:12

I think it's a threat which is not waiting for a particular day like Y2K or anything like that.

2:17

It's a threat that is must be managed today.

2:20

So I'm very glad to be here.

2:22

Yeah.

2:23

And I really appreciate that you're here.

2:25

And I couldn't agree with you more.

2:27

I again, it's one of these things that I, I think at this point everybody agrees that quantum computing is coming.

2:34

I know there are, believe it or not, there are naysayers that believe that it's still like a, a glorified science project that doesn't really have any end.

2:41

Our friends at Google have kind of shown that that's not the case.

2:44

NVIDIA has done their thing, so on and so forth.

2:46

I'm pretty rest pretty good at night knowing that is coming.

2:51

I do not rest very good at night knowing that we aren't really prepared about it.

2:55

So what I wanted to talk to you about specifically is that why is this different, this this whole quantum computing thing?

3:03

Why is this different than some of the threats that we've seen in the past?

3:07

Because you and I've been around the block for a bit.

3:09

We know that there's quantum where there's security threats about everything and this quantum threats a little bit different.

3:15

Talk to me a little bit about how quantum is a little bit of a different threat.

3:19

Well, you know, cryptography has been around forever.

3:23

I don't need to go into the history of why cryptography is there, but it basically underpins all the security on the network as it is today.

3:33

So, and the basic portion of it, which has been in practice since like 1970s or even earlier than that, which is the asymmetric cryptography that is relying on a kind of math which, you know, I don't want to go into a lot of details on the math itself, but it relies on the math which traditional computers are not very good at solving.

3:57

But guess what?

3:57

Quantum computers, they're, they're on the horizon.

4:01

And there's an algorithm which was given like in 1994 or something like that by Peter Schorr, which is, you know, breaks these algorithms in a reasonable amount of time.

4:13

And so that's the threat from the quantum computers that, you know, any computation that we can do using, any mathematics that is hard for traditional computers is going to be really easy for quantum computers to do.

4:30

So the traditional cryptography as we see today is going to be broken by these quantum computers.

4:35

I mean, the reason we are really worried about it today is that we don't really have to wait for these quantum computers to become available.

4:44

It's to, you know, to have this risk.

4:48

People can harvest the data today and it's, you know, the four words that are that keep you up at night is harvest now, decrypt later is that people are harvesting your encrypted data today in the hopes of that when the quantum computer become available, they will be able to decrypt that data and figure out your secrets.

5:09

Yeah, big concern for me too, right.

5:12

So again, the, this idea that, and I, I can't emphasize this enough when I do it every time that we talk about it, it isn't that the encryption that you have today is bad and using a normal computer chip that exists today that does something in that the realm of maybe even a billion calculations a second or something along those lines.

5:33

That's fantastic.

5:35

OK, so your ability to break a even AES 250 86 or even a 10/24 bit cipher is something measured in centuries, right?

5:45

I mean, it goes on and on and on and on and on.

5:48

Because just the ability to use your computer in that way takes that a long amount of time.

5:55

That same AE AES 256 algorithm with a quantum computer that might take under normal circumstances, take a regular computer decades if not centuries to break.

6:07

We'll take a quantum computer, something measuring in seconds.

6:11

And so of course it becomes very, very straightforward and very simple to break that particular encryption and have access to that data.

6:21

You mentioned one of the things that concerns me the most, and that's this idea that the bad guys are harvesting your encrypted data today with the idea that they are going to decrypt that data at a time where a quantum computer becomes available to them.

6:40

That is a huge concern.

6:41

It's the major concern of financial institutions, of the government, of the healthcare industry.

6:47

Talk to me about why that is such a big deal and why it is making companies start their transition right now even though those quantum computers don't exist yet today.

7:00

Yeah, that's a very good question.

7:01

I think the main problem is that people don't realize that data life can vary.

7:08

So there's data which doesn't have any value after it's used, and then there's data which can be still valuable after 70 years from now.

7:18

So the data life differs, varies a lot.

7:23

And if for example, the health data or the census data or something like that, there are government mandates that such data should be kept secure for many, many years, 70 years I believe in case of census data.

7:37

So just imagine that in five years from now, a quantum computer becomes available, which is able to decrypt the encryption that you've put on that data and able to harvest all that, I mean, able to gain all the information that was encrypted in there.

7:55

And you were thinking that it was all secure.

7:59

That's a big threat.

8:01

And that's a threat.

8:01

I mean, people think, OK, how much can they store?

8:05

You know, they're harvesting all this data.

8:07

So how much they can store a lot of data.

8:09

There are big, big data centers being built a lot in the data.

8:13

Yeah, that you can imagine.

8:15

Big nation states are after it.

8:16

So they're building huge data centers to store this data.

8:21

And you should absolutely be worried about this today.

8:24

It's even simple things like you talk about your personal bank account.

8:29

Do I really care if somebody knows what my bank account was in 1993?

8:33

You know, I probably don't.

8:35

I mean, in the grand scheme of things, I, you know, the, but it's the idea that, that the integrity of that data is somehow exposed.

8:43

And if they can, if they can expose the data from 1993, maybe they would be exposing the data from 2026.

8:50

Well, of course I don't want that information.

8:52

The government's concerned because of course they protect, you know, all the state secrets, military technology, so on and so forth.

8:59

And some of it is really straightforward how to make an airplane fly.

9:05

OK, well, we know how to do that.

9:07

But there's even things like how the engine technology for the latest SpaceX rocket and, and how they had to artistically Weld how the engine Cowling works and so on and so forth.

9:19

That is extremely proprietary.

9:22

It it's something that we don't want other nation states to be able to have that information because it gives the United States a competitive and technological advantage.

9:31

Things on the intellectual property in your organization.

9:34

Things on the intellectual property in your organization.

9:38

You even want them to know like even your salaries and, and what your, your CEO is making, if you're a private company or, you know, maybe a price list or a customer list.

9:49

And, and so you can go on and on and on about stuff that you protect today and you protect it with a secure algorithm.

9:56

But the reality of it is, is that you, you want to keep that information protected.

10:01

And with quantum, you have the potential of losing some of that information.

10:05

So one last question for you and then we'll kind of wrap it up.

10:09

I wanted to talk to you about what, what does the transition look like?

10:13

What I mean, I know that Gigamon already has a solution here and this isn't a commercial, but I wanted to talk to you about when, when you are talking with customers, what is your recommendations to the tech professionals, the practitioners that you're talking to about PQC?

10:29

Yeah.

10:29

So the interesting thing is that there was a recent survey, the hybrid cloud security survey in which you know, there were the about 93 percent of financial services leaders, the highest response among all industries.

10:46

They said the visibility into encrypted traffic is critical to post quantum cryptography readiness.

10:52

You cannot migrate simply you cannot migrate what you can't see.

10:56

You have to know what is on your network, what cryptography are you running, and where are you running it?

11:03

Without that information, you're running blind.

11:05

I mean, it's like shooting darts in the blind, in, in, in the dark or something like that.

11:09

So you do need that visibility.

11:12

The first step, CSIC gave out this road map sort of thing, right?

11:17

The guiding road map that you need to follow.

11:20

And that basically shows that the first step in any PQC transition is to look at what cryptography or create an inventory of what cryptography you're running inside your network, inside your organization.

11:34

Based on that information, then you classify the data that you have.

11:38

Like I mentioned, not all data is going to be as valuable tomorrow.

11:43

So you need to figure out what data you need to protect today and build your road map based on that.

11:50

Now, one more thing I would like to add to it, since we're talking about PQC, did you see algorithms they came up in, you know, in like they really were standardized in 2024.

12:02

Before that there was a missed contest and things like that.

12:05

The real thing is not even those algorithms.

12:07

I would go a little bit further than that and put another word out there, which is crypto agility.

12:13

You need to be able to, you know, these, the RSA and ECC, they have been battle tested algorithm.

12:20

They were, they have been in use for many, many, many years.

12:26

But we have seen, for example, in case of psych, for those who know it, I won't go into details of it.

12:32

It was one of the top contenders which was broken by a normal computer.

12:36

So I don't want to scare people, but you need to really think about having crypto agility and even, you know, being able to put that agility into your environment requires, you know, your environment very well.

12:51

So you need the visibility into where the crypto is and how are you going to replace it.

12:57

Only then you can manage the things beyond that.

13:00

I couldn't agree with you more.

13:01

And I want to preface this by saying too is Gigamon is not paying to be here.

13:06

I invited them.

13:07

They are truly the leaders when it comes to understanding the visibility in your network.

13:13

So to keep you are absolutely right on there.

13:16

You can go look at my previous reports that that talk about network visibility and you can see what Gigamon does.

13:22

I of course then would like to recommend that if you have questions about PQC, go check out gigamon.com.

13:30

They have great information there about PQC and they'll be more than willing to take and talk with you and help you in that regard if you have those kind of questions.

13:39

I really appreciate you coming on.

13:41

We are not done talking about PQCI.

13:45

Really appreciate your expertise taking and sharing.

13:48

So keep thanking you for coming on today.

13:50

With that.

13:50

I think that we've called it pretty good today.

13:53

If you have questions about PQC, go to gigamon.com, talk to them.

13:57

You can always come to me.

13:58

I can take and give you better recommendations too.

14:01

I hope this is interesting to you and until next time, thanks for listening.

14:06

Thanks Chris for all your great insights today.

14:08

Make your next podcast awesome.

14:10

When you work with the EMA team on your organization's next project, demonstrate thought leadership, differentiate your solution, and add the credibility of a third-party expert to your message.

14:21

Visit cybersecurityawesomeness.com to listen to past episodes.