
Black Hat Talk on Quantum Computing Threats and Post-Quantum Cryptography Migration
The video presents a Black Hat talk by JP, a cryptographer with 20 years of experience, focusing on quantum computing and post-quantum cryptography (PQC). Quantum computers leverage quantum mechanics to solve specific mathematical problems—factoring and discrete logarithms—that underpin RSA and elliptic curve cryptography (ECC), threatening current encryption and authentication systems like TLS, SSH, and cryptocurrencies. While quantum computers are not yet practical (current prototypes have ~100–1,000 qubits but lack stability), advancements like Google’s Shor algorithm optimization and startups like Orotomic propose theoretical breakthroughs requiring 10,000–500,000 qubits. NIST has standardized PQC algorithms, including ML-KEM (Kyber) for key encapsulation and ML-DSA (Dilithium) for signatures, with a 2035 deadline for U.S. government migration. Hybrid cryptographic schemes combine classical and PQC methods to ensure security during transition, though PQC keys and ciphertexts are significantly larger (e.g., ML-KEM keys are ~1,600 bytes vs. 32 bytes for ECDH). Major tech providers like Google, Apple, and Cloudflare already integrate PQC into services (e.g., iMessage, Cloudflare tunnels), while regional standards in China, Japan, and South Korea are emerging. Migration requires an iterative OODA loop approach—observing systems, assessing risks, and prioritizing fixes—rather than a one-time replacement.