Chris McHenry on Quantum Threats and the Future of Encrypted Data Security
Chris McHenry, chief product officer for Aviatrix, dives into the degree to which nation states are harvesting encrypted data today with an eye toward being able one day decrypt it using quantum computers.
Transcript
Hey guys, thanks for the throwaway here with Chris McHenry, his Chief Product Officer for aviatrix. And we're talking about, well, the degree to which maybe nation states or steel and encrypted data that they plan to decrypt someday and using quantum computers and how prevalent this all is. Chris, welcome to show.
Thank you very much, Mike. Good to be here. Some people, my friend, are a little skeptical of this is even happening.
So what evidence do we have so far that nation states are doing this? Is this a theory or do we have some actual examples thereof? Yeah, it, you know, I think it's, it's difficult to ever say exactly what a nation state is doing, uh, but it is really interesting.
I think there's several pieces of evidence, especially with the investment that nation states are making in quantum computing now. Uh, particularly we know that China has made some very big investments, uh, in, in terms of de developing the technology. And one of the primary use cases, uh, that are, has been most attractive to nation states and for potential military applications has been the fact that it has the ability to, to break most of the fundamental standards of modern encryption.
So I think, I think the, you know, the, the things we know about quantum breakthroughs and we know who's making the investments in them, definitely lean towards the fact that, you know, there is some serious interest in this space and, and we need to be aware of it. Now, I will say one more really, really interesting piece of evidence that we have is one of my favorite, um, examples of a hack probably happened about 10 years ago, and it was a manipulation of the global internet routing tables that temporarily, temporarily rerouted about 40% of the traffic through, uh, through China. Uh, and so, you know, you gotta ask the question like, why is that even interesting to some extent, especially when most of the traffic on the internet is encrypted.
And then we did see last year, uh, a, uh, a really high profile attack on US service providers by an organization known as SA Typhoon, which is generally associated, um, with the Chinese nation state. Uh, and they, uh, managed to penetrate a lot of the core US service providers. And, and I think the use cases there were primarily about snooping on, um, very targeted communications.
Uh, it, it, you know, relative to national security, uh, maybe not as relevant for enterprise data, but we do also know that there's a long history of stealing trade secrets. So, I mean, it's, it is, uh, it, it's hard to say ever if something specific is, is happening, but we have a lot of evidence that points towards this being a potential potentially very real issue. Yeah.
Some people, of course, are waiting for what's known as Q day, which is when the quantum computers get smart enough to break some of those encryptions. Um, the question I have is how close are we to that and might we even know when that day arrives? Yeah, I, I, it's a really, really, it, it's incredibly difficult to predict.
Um, I think one of the things that's really interesting though is we have seen very meaningful progress in the development of quantum computers over the last couple years. Uh, not just from nation states, but also from private companies with announcements from Microsoft and Google and the investments that they're making there. Uh, you know, we also saw the federal government ratify post quantum encryption standards last fall, and we're gonna start to see a lot of those come into regulations in the next couple years.
But my best prediction is that we're looking at like early 2030s, but I think the preparations that organizations, the technology to help be preventative about this is, is gonna be, it's here now in many cases, and, uh, we're gonna start to see this be a, a best practice, uh, really next year. I, I, my, my prediction is the next fall is really gonna be the year where everybody starts to kick off their, their quantum encryption upgrade programs. Now, one thing that's important is this is not the first time many enterprises have gone through this.
3. That was maybe 2016 ish timeframe. So, uh, we are practiced in this, but I don't know that anybody really has a process.
And so whether it's quantum or not, we are going to need to upgrade our encryption algorithms over time as both traditional and quantum computers get better. And I think next year is gonna be the year where enterprises really put this on their whiteboards. How do I have this conversation with business execs who are gonna kind of look at you and say, well, let me get this straight.
They're stealing data today that they might decrypt three or four years from now. And the business exec goes, I don't think any of that data's gonna be valuable three or four years from now. I think that's a really real question.
Right? And, uh, and so, you know, it, it, it, a lot of it depends on, on when Q day ultimately happens, but if you don't start preparing for how you can keep your encryption is incredibly important. Like, we want to best practice as all of your data in transit and in rest needs to be encrypted, and organizations need to invest in technologies to allow them to keep their encryption up to date.
This is really just another threshold there. So I think the harvest now, decrypt later schemas are obviously, um, you know, very interesting and very pressing, and we'll have an incredibly, you know, when Q Day comes, we'll have a huge, huge, huge impact on how we think about cybersecurity. Uh, but it's, uh, you don't know when that's gonna happen, right?
And, and, and in most cases we probably won't even know because a lot of it is funded by nation states when it actually does happen. And so that's, you know, it, it, it, we are, we're getting close, we've seen the signs and, and now really is the time to prepare. To your point, it may have already happened and we just don't know about it, but how big a lift is it to swap out my encryption scheme as on different products and what kind of effort is gonna be required and, you know, what kind of funding for that matter?
Yeah, it's a great question, and I think that is one of the big challenges, right? 3, that we put it systems in place to make that easier down the road. But I was, I've had multiple conversations with enterprises even in the last couple weeks where they know it's gonna be in a huge challenge for them to upgrade.
One of the, one of the big challenges is that, you know, not all of your applications running in your environment are modern applications. And so we need to think about multiple different layers of security here. And, uh, and that's really where tools in the network I think will become in incredibly powerful, uh, to be able to, uh, do network level encryption even when the applications can't.
So it's like you are solving the problem at the trunk of the tree rather than at the leaves. You wanna do both. Um, but there will be a lot of, there will be a lot of techniques and I think technology to, to ultimately improve that process.
We're definitely investing in that space. You will see from us next year a one click easy button to do PQE and, and all of your, you know, for all of your application traffic in the cloud. And, uh, and I think a lot of other vendors will be investing in this, in this space too.
Some folks I talked to are counting on forklift upgrades. Their assumption is that sometime in the next four years, they're going to upgrade their server storage infrastructure and applications and whatever it may be. And whatever that new thing is, it will come with the appropriate level of encryption.
Is that a decent strategy? Uh, no. Is the, is the short answer to that que short answer to that question, right?
I mean, all you have to do is look at, uh, typical enterprises and, and, and see, especially ones that have been, uh, around longer than 10 years. Like, you don't forklift your entire application environment. I mean, up until recently when you booked an airline ticket, it still went back to a mainframe.
I was talking to a health insurance company, uh, the other day where a lot of their claims are still processed in cobol. I mean, there's, it, it, it, it, it, it's a, there's no such thing as a forklift. Every organization does rolling upgrades, right?
And, uh, and so that's where, you know, where, where you can make big impacts is looking at the, the roots of the problem, right? Going down to first principles. And I do think many organizations are gonna look at services at the infrastructure layer that will help them to, um, to get larger swaths of their environment ready, both from a data storage encryption perspective.
That's gonna be a big one. Um, you'll already see that in some of the cloud providers. And then obviously also at the network level.
One of the big challenges at the network level is that, um, it's, it, it in many cases may be hardware dependent. So I think what we're gonna see is a lot of software solutions and some innovation in software that will help you upgrade your encryption without necessarily doing a, a hardware forklift. So what is your best advice to folks about how to go about putting together the plan and executing it and getting everybody on board?
Because there's just a lot of moving parts? Yeah, I mean, uh, my advice almost always, and, and you'll hear me say this across a variety of cybersecurity topics, is look at first principles. We have a tendency as organizations to play whack-a-mole.
'cause we're looking at, you know, the, the things that are at the higher levels that's like, Hey, I want to go patch my servers to eliminate the vulnerabilities. Well, you know, if your servers weren't available on the internet, maybe, maybe, maybe they wouldn't be as exploitable, right? Same thing, I think with encryption.
I talked to a lot of companies who say, Hey, we have encryption at the application layer, right? Great. Do you have it on every single application in your entire environment?
And the answer is, I've literally never seen a customer that that can say yes to that, right? So, uh, what's really powerful is when you think about it at lower layers of the stack, when you think about at the network layer, at the storage infrastructure layer, those are places where we can make a really big and broad impact without having to play whack-a-mole. What do you think the government's gonna say about all this?
Will they come up with some mandates? I know that NIST has been involved with creating some of the specifications, but, uh, at what point might someone show up and say thou shout? Yeah, I, I think it's gonna be next year, honestly.
Um, but I don't think it's just gonna be government, right? I mean, typically the way that the government mandates work is the, they'll, they'll make rec strong recommendations to industries that they contract with, right? I'd say from an enforcement mechanism perspective, what is really interesting is when the industry specific, um, regulations or, or, uh, you know, uh, standards start to come out, like PCI as an example, uh, I, I strongly suspect in the next 18 months we'll see a modification to PCI that recommends particular encryption standards, uh, really focused on, on, on, on post quantum encryption.
And, uh, and so it'll be the government first and then we'll see the industry specific, uh, industry specific recommendations and standards follow. Do you think the insurance companies are gonna show up and say, Hey, we're not gonna give you that cybersecurity insurance if you don't fix this encryption issue? Yeah, it's a great question.
I mean, I think, uh, what you typically see with insurance from a cyber insurance perspective is that you have to have your first principles covered. Encryption is always one of those, and as soon as the standards change, it definitely will follow that from a, from an insurance perspective. We've seen that multiple times.
All right. Hey folks, you're heard it here. We're upgrading our encryption.
It's just a question of when and how painful and how long. And the sooner you start, the easier it'll be. Hey, Chris, thanks for being on the show.
Thank you, Mike. All right. And back to you guys in the studio.