Cracking Encryption Schemes with Next-Gen Processors – Skip Sanzeri, QuSecure
QuSecure co-founder and COO Skip Sanzeri explains how encryption schemes might be cracked using next-generations processors long before quantum computing becomes a cybersecurity issue.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Skip Zeri, who's co-founder and COO for Q Secure.
And we're talking about how well encryption algorithms might be cracked. And we don't have to wait around for quantum computers to do it because well, there are other advances coming along that will be here a lot sooner. Skip, welcome to the show.
Thanks, Mike. Good to be here. So explain to us what can happen here.
I know there's some advances in asics and other processor technologies out there, but um, suddenly maybe quantum computers aren't the thing we ought to be keeping us up at night. Yeah, I mean, we have to start with the basis, Mike. So think of all the encryption we use for the internet now, in most cases as consumers, we don't even know it's just gone on in the background, but that encryption was invented in the late seventies.
So this, this stuff is 50 years old. Um, and the way that we've stayed ahead of the curve is we've made those keys longer. So, and then that encryption, it's a factoring, it's a math factoring problem that it's a bigger number to factor.
It's harder. So we've kind of stayed ahead and we've been okay with that for now. But quantum computers came about, and I think a lot of people know about these now, maybe a year or two ago it was less, but now everybody's sort of quantum, these operate in a way where they can crack that encryption when they're powerful enough.
Um, yet at the same time we're finding now there are new ways that people are coming up with to go after these prime factory problems, go after this encryption that protects the internet that aren't quantum. So the real message is, it is time to start upgrading off of 50 year old algorithms to new algorithms. And that's really the message that needs to get taken home today by, you know, enterprise corporate consumers.
It's time to look at new cryptography so that we can be protected against future threats. How prevalent are these new processor technologies gonna be? Are they easily accessible?
Is this becoming a near and present danger? Well, it's hard to say because no one really knows when these breakthroughs come about, but humans are very clever. And if you think about the prize being literally global domination.
So again, all of the encryption that runs the internet is basically the same. So the entire internet, this is a trillion dollar upgrade, by the way, the biggest upgrade cycle in human history. This is all at hand.
In other words, it's all available. So when the prize is big, people will put a lot of resources in to figuring out how to, how to win that prize. Um, we know that China's got at least $15 billion into a program to try to break that encryption.
Um, you've got very clever ways where people are using classic and quantum or they're using different versions in this thing. We saw a couple weeks ago, a group outta San Diego Mem Computing was asked by the Air Force, US Air Force to see if they could crack encryption using asics, which are sort of just specific processors. Um, and they were able to do some factoring of these numbers that was pretty amazing and pretty scary.
And they found that they could factor, it was about a 300 bit number in a minute, 22 seconds that had never been done that fast before. Um, and so, you know, the idea is that people are going to go after the big prize because either you protect yourself and you're able to stop, you know, getting taken over or you're doing it for global domination. So either way, there's a lot of reasons to start looking at switching out because these things will be here much sooner than anybody thinks.
The last thing I'd say to that is it also is going to take a decade, 10 years or more to upgrade enterprise and government. So that's why you've gotta start now. Well, what goes into upgrading encryption and will people swap out encryption and existing applications or will they just replaced the applications?
That's a great question, Mike. So a lot can go into an upgrade. Um, now if you're going to do it yourself, uh, and, and you're going to take this task on, um, many people have heard of open source code.
The algorithms now this new, this new cryptography is just open source code. It's like Linux and these other types of open source, um, where you can get it. Any enterprise can get it, any, any go agent can use it.
But trying to figure out how to move it in your network, how to move it out to edge devices like phones and laptops, how to move it to iot like sensors and cameras, how to move it to satellites or servers. That all takes a lot of coding and work. And so in some cases it can be very hard.
Now, Q Secure, what we've done is we've created what we call a control plane. That's a single way, like think of an interface. Like when you go into any application, you got your interface, you got, here's how what's happening, here's how you operate stuff.
If you want to change something or do that or click on that, we provide an interface so that they can move all of this new technology out to the edge. So the upgrade process can be a lot. The other thing that we did, uh, in order to make this easier, uh, was we also, uh, allow the enterprise government to leave their existing encryption in place.
So we're not asking anybody to take anything out, but just put ours on top of it, which means that they leave it there, they get the quantum protection, the future proofing, um, all with one control plane, one control area, and that we think is the best solution. And so we try to make it easier to deploy this stuff rather than the enterprise or federal government agency taking the whole thing on themselves. Is it just a matter of time before we have a problem?
'cause it seems like governments around the world, we're already collecting encrypted data that is encrypted using older algorithms anyway. So we're probably gonna have to assume that a lot of the data that we think is encrypted today at some point in the near future is gonna become unencrypted Abs a hundred percent. Um, you know, I I'd like to say there's two types of companies in the world, those that get hacked and those don't admit they got hacked.
I mean, that's it. So everybody loses data. Everybody in, in some cases you hear a ransomware like MGM Caesars, remember that thing about a month ago, uh, Cisco got hacked two weeks ago.
These are big companies. SolarWinds, oh my goodness, one of the biggest ones. Um, everybody's going to get hacked and lose data.
So the, the, the question is not, not, you know, if, but when that data's gonna go out the door. Um, there's also easy ways to listen. Like with a few hundred dollars of hardware, any of us can listen to any satellite signal we want and we can store that signal.
Now, we can't decrypt it, but we could store it for later. So there's a lot of what we call steel now, or harvest now decrypt later, where people and nation states primarily are storing data for the time when they'll be able to decrypt it. Now, they can't decrypt it today, but with Quantum and some of these other things, they will be able to decrypt.
And if you think about the treasure trove of data, it's estimated China will have about 27% of the world's data stored. They have everything. Um, and what could you do with that?
Well, you can do about anything you want with that data if you can get through it and you can decrypt it. So this is a real problem that has to be addressed, and that's why again, we've gotta move now. Um, and with the way that we do it at Q Secure, we make it easy.
So there's no reason not to start moving towards that new encryption. Also, a lot of folks don't know, we Biden, uh, president Biden signed into law last December that all federal agencies have to upgrade to these new algorithms. So this is no longer a choice.
The NSA nist, uh, cisa, other government agencies have said, this upgrade has to happen. It's now law. We're gonna move that direction.
Now, just how quickly can we do it? And the faster that we do it, the more the data's protected for the future. How do we make this, uh, higher priority for the business executives?
'cause I think a lot of times they're always having competing agendas and issues, and it's difficult for the cybersecurity folks to get this one up the top of the list. So what's your best advice there? Oh, you hit on, you hit on one of the toughest things is everybody's busy.
They're working on their own things. You know, we talk to different, you know, we, we, we hear all the, uh, all the, some folks are saying, yeah, we want to try this. We know this is an issue.
Uh, uh, you know, we want move this direction. Others are saying, well, we're thinking about it, but you know, we can be convinced. And others are saying, yeah, we'll just wait till those, you know, it's down the road, right?
We don't care. And like, oh, man, you know, if your data gets hacked, think of it this way. If your data gets hacked today, you have a chance of getting decrypted by some of these advanced devices in a few years.
Um, however, if you put quantum protection on it, you have decades of support. Decades. And you know, if, again, remember the data we talked about getting stolen, Mike A.
Little while ago? Most data has to have a pretty long shelf life. Like think of banking information, 25 years, that data needs to stay safe.
Um, military sequence, 50 years, uh, personal information, 75 years to life. I mean, your social security number, you know, your personal identifiable information, it's as long as you live. Mike has to stay secret because if somebody has it, that becomes an issue.
So it, it's the idea that if, if these things aren't addressed today and we don't deal with these things right away, that of course all of this data comes into play, becomes a big factor and then somebody can decrypt it. So the best advice is, again, everybody moved. Now the pressures that we're seeing, which I think are going to really start moving the needle, is now boards of directors are starting to get held responsible for breaches.
And the the thumb screws are tightening because, you know, prior in my just non-scientific humble opinion, somebody gets breached. It's like, oh, we got breached. Everybody gets breached.
You know, you got breached, I got breached, we all got breached. We all lose data. But it's not that anymore.
Now they're starting to say, because it's the consumers and the individual citizens that lose, right? Because like when our data gets stolen, it's on the dark web now, and it gets sold out to everybody, or a nation state uses it. And guess what?
That's when weird stuff happens in the future. And you, you know, I haven't seen where people go back and sue the company. Like when Target had that huge breach, hundreds of millions of records out the door, uh, when the, when the government got breached about six, seven years ago, literally tens of millions of classified individual records.
Like if you get a security clearance, you fill out 80 pages of information on you and all of your friends and all your contacts. They stole the entire database. I mean, what could that do for later?
Right? And by the way, that wasn't a decryption problem. They stole it and they, they got that data.
The problem is, is that we have to hold people responsible. And when there are penalties out there for getting breached, other than say a brand of a corporation getting hurt or ransomware paying out, like if, if MGM Caesar's board of directors and c-level were held responsible legally, then change is start because it's their own versus saying, oh, that's just the CISOs problem. I guess I'll fire the ciso, get another one.
So I think it's gonna be, it's gonna be that we have to treat data as almost as important as people. Because you know, the way our digital footprints are like, you know, right now your phone, my phone, all of our computers up, everybody knows all about us. It's almost us.
If you think about it, it's almost you, Mike, on all your, your, your, you know, your, the devices you use, the apps you go to, you know, the, the, the websites you look at, that's almost all you. Um, there's, you know, hardly a difference now with DeepFakes and the rest between that. And you, we have to start treating that, that Mike as important as the real Mike.
We have seen the rise of data privacy regulations and a couple other mandates here and there along the way. Do you think that these are all gonna get more stringent as the people who write those regulations become more aware of this encryption issue? I think so, yeah.
I think the trend, see, and from the privacy standpoint, they did a good job and Europe led the way, by the way, right? Europe and then of course California followed, that's where I live. So, so we actually followed right along.
But um, they live the way in saying, okay, consumers have rights. And you know, just because you go on the internet doesn't mean that you give up all those rights and people can do what they want with what you, what with, with the, the uh, relationship to who you are out there, you know, and, and your preferences and everything else. So that's the beginning and that's kind of the, I I I think of it like a pincer movement where you're kind of coming into both sides.
So that's the consumer side saying, okay, we gotta protect consumers because you know, if, if we don't, no one will. Right? So government's done that.
The other side of it is now they have to push from the company leadership point to say, okay, for instance, on these new algorithms, how are you protecting your consumers, your constituents, your partners against these hacks? And you know, what sorts of hygiene, cyber hygiene are you using? Um, are you starting to use new algorithms?
And again, I was, I sat with the director of office management and budget last week, Nick Polk. And, um, and, and the OMB is the one that's funding the, the upgrade to move federal government to this new encryption. And he's saying, yeah, we're starting to, to push on, on federal government to make sure they're getting this stuff done.
'cause again, it's a decade, but we have to start. And I think it's a matter of people really thinking. Now again, cyber assets, digital assets are as important as people.
And I think when we get to that point where they say, okay, we gotta protect those digital assets just like we protect individuals, I think you know that, that to me is where we'll, we'll start making the real progress. Alright folks, it seems like it's almost inevitable that some form of encrypted data is gonna come back to ha us one day. The question is, is how to minimize that from here.
Hey Skip, thanks for being on the, Yeah, thank you Mike. Great to be here. Thank you.