Defeating the Harvest Now Decrypt Later Quantum Threat
The cybersecurity industry has spent decades pushing quantum computing threats into the “five to ten years out” bucket, but the reality of Q-Day arriving before the end of the decade has completely changed the math. Techstrong TV recently explored the terrifying reality of “harvest now, decrypt later” attacks, with Vikram Sharma – Founder and CEO of QuinressenceLabs, where adversaries are actively stockpiling today’s encrypted intellectual property and state secrets to crack open tomorrow. To combat this radioactive data problem, enterprise leaders must urgently adopt true quantum random number generation, implement massive-scale key management, and bake crypto-agility into their infrastructure before the quantum clock runs out.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. I'm really happy to introduce this next gentleman here.
You're gonna have to excuse him. He's been, he's literally been traveling around the world, and he's on a stop here for a few days before heading out to join the rest of us at RSA next week. But let me introduce you to Vikram Sharma.
Vikram is the founder and CEO of a company called Con-Quintessence Labs, and let's welcome him. Vikram, welcome to Techstrong TV. It's nice to have you on here.
Thank you for having me, Alan. Real pleasure to be here. Thank you.
So I understand you're in New York today, having just arrived, actually Australia via Auckland, New Zealand. I've done that flight. It's a flight, it, you know, into Newark- ...
and, yeah, that's a flight okay. Um, but I appreciate you getting on. You, your body probably doesn't know exactly what time it is, but that's okay.
Um- Still working it out. Oh, yeah, you'll figure it out. Vikram, I, I mentioned you're the founder and CEO of Quintessence Labs, but play be- let's go to Vikram before Quintessence.
Let's, let's understand a little bit about your makeup, right? Uh, you know, what gets someone to travel halfway around the world to talk security and, and crypto agility and so forth? Let, let us hear a little bit about your path.
Well, thank you very much, Alan. Um, yeah, quite a career in, in IT over a, a number of years. Had the good fortune to be at, graduate school, something called the Sloan program at Stanford a number of years ago.
Um, an amazing program, but on finishing that, had the, remarkable good fortune to sit in on some classes taught, at quantum physics by a gentleman called Steve Chu, who actually went on to become, way back when, energy secretary for the United States, Nobel laureate in physics. And he exposed us to the idea that we are on the cusp of being able to harness quantum effects to create all kinds of new capabilities. Um, I'm sure you've heard a lot about quantum computing.
There's quantum sensing, but equally quantum security. Now, this struck me as a, a really important problem, something I was very interested in, and something, even though it wasn't a thing then, but that, in, in, my perception was something that really would need, addressing. And, so oddly, went back and I found back at my doorstep in Australia, they were about to embark in some cutting-edge research at the intersection of quantum and cybersecurity.
I was really fortunate to be a member of this, amazing team they had, and, this is at the Australian National University, and we had some world firsts in the application of quantum effects to deliver strong data protection. Uh, culminating out of that research was the seed of science, which then resulted in, my being able to form Quintessence Labs, well over a decade ago now. Really?
Oh, so this, this, this sounds to me like you, you, the fact, you found the passion of your life in, in quantum and then quantum security, right, where it intersects, and, and you've spent the last 10 years exploring that. Yeah. You know, and it's- Absolutely, Alan.
It's funny, you, you say that because I, I don't, I never really followed... I, I mean, I heard of quantum. I, I kinda know what the idea behind quantum computing is and why, why it's a threat to our cryptography and everything else, but, you know, I'm more of a generalist, let's call it.
" Mm-hmm. " Yeah. Five years later, still five to 10 years out.
Yeah. Ten years later, still five to 10 years out. But now, but now that's changing, right?
Agreed. Now that's changing. It's no longer five to 10 years out.
We could, we could taste it. It's... You know, IBM is pledging to have something by, I think, by 2029 or 2028.
I mean- Yeah ... we're talking a two to three-year window, and, and we're seeing breakthroughs and, and, and technology advances every single day. We really are.
And you know, Alan, it's interesting. It, it's sort of a bit of a similar trajectory with AI, if you think about it. Yes.
Right? Yeah. It was very similar, you know, 30 years in the making.
Then all of a sudden with the ChatGPT moment, it sort of exploded into our consciousness and, uh- Yeah ... gone stratospheric in the last three or four years. So- Yes, it has ...
I think similarly with quantum, it's been, you know, as you said, probably two decades plus in the making, in the maturation of those seeds of science, into things which can start to lay the foundations for practical applications. And now we're seeing very clearly, as you mentioned, IBM and others have on their roadmaps to deliver what they call a utility scale quantum computer, before the end of this decade. So, you know, roundabout, as you said, the 2029 timeframe.
And equally, much as there's been progress on the hardware side, from a, a risk to cryptography side, there have been equal advancements in software as well. So, in the efficiency of Shor's algorithm, for example, which, p-10 years ago suggested for 2048-bit RSA, you'd need a billion qubits. Late last year, Google published something suggesting that was down to a million qubits, so that's a one thousand-fold reduction, and that journey's not finished.
It's likely over the next few years to continue. Plus, there's the possibility of alternative algorithms which might be partially run on supercomputers and partially on quantum computers through a hybrid, which also offer interesting promise. Absolutely.
Vikram, before we jump into that, though, I-I'm getting the sense you're humble and modest. Let's return back to your, your work, both at the, Australia University and, and over the last ten years at Quintessence Labs. You were, you were, if I'm not mistaken, you were, singled out or, or acknowledged by the Australian government, the Australian Prime Minister's office, as one, one of the leaders in quantum- Oh, well- ...
security? Thank you very much, Alan. I was very fortunate, in November last year to be the recipient of the Australian Prime Minister's Prize for Innovation for work in quantum.
Uh, while I had this tremendous honor to be recognized, I think to be fair, it really is representative of the tremendous work done, by our team at Quintessence Labs in, making advancements, fundamental advancements in quantum cybersecurity to the point where we do now have that science going to tech and then tech going into, to solving problems and being deployed, globally today. Absolutely. You know, we, we've been involved a little bit recently with quantum security with our friends at DigiCert- Right ...
and, and so I've had the chance to interview and speak with many quantum, many quantum, experts out there. And, one, one of the things that we saw was the, the, the idea of what we call, you know, take it... I forget what the exact term is, but we're gonna, we're gonna steal it now and decrypt it later kind of- Yeah ...
thing, right? Mm-hmm. Um, harvest now, decrypt later, I guess is the term.
Yep. And, and this is a real, this is a real problem as, as we get closer to the time where, you know, Q-day arrives and we can, not we, the bad guys can- Mm-hmm ... decrypt what, you know, payloads that they've been harvesting.
This becomes more and more of a problem, right? Because, you know, the, the data that gets harvested, Vikram, in my mind is almost like radioactive data, right? Mm-hmm.
It has a half-life. Mm-hmm. And, and so every X period of time, you know, half of that data becomes obsolete, you know, not worth anything.
However, that's fine when you're 10 years out and that half-life is every year, right? So in 10 years- Right ... you get some.
But when that Q date, you know, the runway's not that long, the half-life doesn't necessarily protect you as much anymore. The radioactivity, right, doesn't protect you as much. And, and it's a valid, you know, strategy by, by these, you know, call them bad guys, call them hackers, call them whatever you want to call them- Yeah ...
but, you know, they're, they're, they're figuring they're gonna harvest this sooner than later. Absolutely, Alan, and, you know, to your points there, probably couple of ideas to throw in there. So one is, as we've just discussed, that that day where a cryptographically relevant quantum computer, as they call it, will become a reality is now not so much a theoretical date, but something which will practically be achieved.
I think we can see a clear pathway towards that. Um, but right now, today, as you said, these harvest now, decrypt later or Handel attacks, as we call them, are rife. We understand state-sponsored activity, is ongoing where, as you noted, you know, data which has a short half-life perhaps is not so much at risk.
But there are very valuable, information sets which are being targeted by the harvest now, decrypt later actors, whether they're, valuable intellectual property, designs of technology, medical, devices or medical technologies which take a decade, to, to mature, or indeed state secrets. All of these need to be protected today, but many of them need to be protected 10 years out from now, and such data, is at risk, and its compromise could have tremendous political, geopolitical and financial consequences. Oh, absolutely.
Yeah. So- So talk to us about what Quintessence Labs is doing to help us here. Yeah.
Um, we believe to protect well against, such attacks should be a critical priority today. Now, the interesting thing is, you know, that the time to transition or important thing, maybe more correctly say, is non-trivial for large organizations. To change cryptographic infrastructure to become quantum resilient is, for many organizations, a three-plus-year journey.
So we should really, as a imperative, start understanding what crypto we have today. So I think a lot of organizations are actively involved in crypto inventory. From that, build a roadmap to transition to a quantum-resilient posture, start some trials and pilot programs to understand what it does take to transition, and then implement that roadmap.
At Quintessence Labs, we believe there are four key elements to being well prepared. The first of those is quite a simple one to implement, is to mo-remove the risk of pseudo-random numbers, so which are used to fashion cryptographic credentials. So let's use a true random number source.
It turns out quantum is a good one. So at Quintessence Labs, we have something about the size of a cell phone. It's a PCIe card form factor, but also available as an appliance, which puts out a gigabit per second of full entropy, so a billion random numbers per second, and in fact, it now appears on the NIST-approved website as approved sources of, of entropy.
Really? The second is to be able to manage encryption keys at very large scale with the performance, the resilience, and the control that large enterprises require. So, if we look at, you know, today, we're managing probably thousands, tens of thousands of encryption keys, but as we move to five G, six G, and fine-grained encryption, that will move IoT also, to millions, if not hundreds of millions of keys.
So to be able to manage at that scale with the performance and redundancy that's required is another, we believe, essential piece of this. The third element, is about crypto agility. So as we see or as you may be aware, Alan, about eighteen months ago, the NIST, standardized the first three so-called PQC's, Post-Quantum Cryptographic Algorithms, and that we understand is just the beginning.
Over the next decade, we understand there will be several dozen new ciphers that will be standardized. So enterprises will be in a position, situation where they have to handle legacy ciphers, existing ciphers that we have today, but also transition to these new PQCs as they're progressively announced. And to be able to handle that transition smoothly, you need to have an agility to be able to ingest these new algorithms as and when they are announced, so you're not investing huge costs every time a new cryptographic algorithm is, is standardized.
So crypto agility is the third piece that we deliver to market, that ability to support, existing legacy ciphers... sorry, ex-existing ciphers today, but equally bring in the new PQCs as they are standardized. And the final piece that's, that's critical is the secure distribution of these keys.
So we have a, a product called Q-Connect, which allows you to distribute these keys very securely between locations that need to exchange cryptographic keys. Collectively, these capabilities give you the cryptographic infrastructure foundations, security infrastructure foundations to support a comprehensive and agile transition to a quantum-resilient posture. I love it.
Vikram, these interviews are only fifteen minutes, and we're, we're out of time, but for people who want to get more information around Quintessence, about Qu-Quintessence Labs, what's the website? Well, thank you. com.
Uh, we have a host of information available there, and we would love for anyone that's interested to contact us. We will also be exhibiting at the RSA, security conference, upcoming- Next week. Mm-hmm ...
and we're booth forty-three hundred there. Fantastic. Forty-three hundred.
I th- I'm just thinking about that floor. Um, but RSA is a great show for you there. I'm actually looking forward to seeing the presence quantum has this year at RSA 'cause I think that'll be a good indicator as well.
You know, sort of like the predictability markets by what presence you, you see how, you know, you could probably make a bet to see how, how real it is, right? How it develops, right? Yes.
How it develops. Yep. Mm.
Anyway, Vikram, I know your body is telling you it might be bedtime, so I'm gonna let you go. Rest up. Good luck in New York.
Safe travels to San Francisco for RSA. Hopefully, we'll see you there. Thank you very much, Alan.
Real pleasure to chat with you today. Pleasure. My pleasure.
Vikram Sharma, founder, CEO, Quintessence Labs here on Techstrong TV. We're gonna take a break. We'll be back in a minute.