Dr. Garfield Jones on Why Post-Quantum Cryptography Preparation Must Start Now
Dr. Garfield Jones, newly appointed senior vice president for research and technology strategy for QuSecure, dives into why organizations need to start preparing for post-quantum cryptography (PQC) now.
Transcript
Hey guys, thanks for the throw. We are here with Garfield Jones, who's the newly appointed senior Vice president for research and technology strategy at Two Secure, and we're having a chat about, well, what will it take to make us safe in this post quantum era that we're about to enter? Or who knows, maybe we're already in it, we just don't realize it yet.
Garfield, welcome to show. Thank you, Mike. Thanks for having me.
So what is the status of this right now, in your mind? 'cause a lot of folks are talking about this, but it's kind of a threat that's far off in people's minds, but how soon is this coming and how much time do we have to deal with it? Yeah, that's a, that's one of those questions that, you know, you, you're always like, well, how shall I answer this?
And then the, the, the first thing I wanna say is that it should not be the fur, you know, out, way out from people's mind. It should be something that's, that's pretty prevalent because we have problems that are, we're dealing with now on the quantum side. And then we, we will have bigger problems that we will have to deal with on the, once a, um, cryptographically relevant quantum, a computer does come online.
So I, I think, you know, how we're dealing with this is, you know, we're the, the government needs to really look at, and, and the private sector needs to look at, at the urgency that that's coming. Um, we, we have to look at it as, as it is something that is, is not, is not going to it. It's coming closer and closer and closer and we, we seem to be just be kicking the can down the road.
And, you know, what happens when you kick the can down the road? You get a lot of cans and it builds up. So I, I think now we, we really have to look at it as, um, the, it's, you know, with the release of some of the articles and some of the, the, um, the pending, uh, government documentation, I think, you know, we're starting to see, um, that the, the date, the initial date was 2035, but now we're, we're looking at and much closer and, and, and we're, we're probably looking at something less than five years out, uh, based on some of the, the, um, documentation that IBM and, and, and, you know, AWS and, uh, all the other Microsoft, all the, all the big players that put out that they're actually heading towards a, um, error corrected, uh, quantum computer.
Um, we, we definitely have to look at urgency. We, we definitely have to look at it as, um, focus on, on getting things done correctly. I mean, we have the, the now problem, which is the, uh, we're, we're losing data harvest now, decrypt late, um, harvest now, decrypt later problem.
Uh, so we're, we're our adversaries have taking that data and they're waiting for that, that four or five year time. And, and we have to put, um, we have to put more, uh, security around our data, uh, wrap that data into, into tighter and tighter, uh, security enclaves so that, that people cannot take that data and use it for, uh, nefarious purposes later. So we definitely have to, um, look at it as, as not only the, the far out problem, uh, it's coming a lot closer.
And then we, we also have to now problem with the harvest now decrypt later problem. Alright, how big a lift is it to kinda replace what we have today for encryption with something that is gonna be quantum safe? 'cause I think that will also dictate the level of, well, maybe panic that we may get into, because if suddenly, um, you know, it's 20 27, 20 28, and now there's a quantum computer coming next year, am I gonna make it in time or am I gonna wake up one morning and go, you know, uh oh.
Yeah. Yeah. I I think it's, it's a lot easier lift than we, we think it is in, in the sense of, um, getting, you know, NS developed those, um, uh, release those three algorithms right now and that the, the ML chem and, and M-L-D-S-A and, and, and others that, and they're working on the HQC algorithm right now, and it's a fourth algorithm that that will actually be integrated into the systems that we have today.
It's an encryption problem. We, we have to an architecture problem, we have to put that. So updating our, our devices, our updating our encryption so that, that we can have, that, that security, um, is, is actually, you know, we need to start it now.
So if we, if we start it now, it won't be that big a problem as we get to, you know, 20, 30 and so on, if, but if we keep waiting and waiting, we've seen, um, transitions to, to other encryptions and, and there are still encryption around, uh, shot one is still around and then, and that's been, you know, that's been out for so long. And you, you look at systems that have, you know, the, to transition to something like this, it, it doesn't take it, it's not a switch. It, it takes a long time.
So you have to start as soon as things are ready, which the, the, the algorithms are ready. And if we start moving towards that, that side and we start updating our, our encryption, there won't be, it won't be that hard to live. I mean, it, it just has to be, be started early.
Um, you know, we have, um, we have the legacy devices and the, the OT devices, the operational technology devices that we have to worry about. But those are, when I say an architecture problem, how do we wrap those into a more secure on cliff? How do we, how do we put it assets that are p qc ready or PQC resistant around those assets to protect them until we can rip and replace them.
We don't need to rip and replace all our things, all our assets right now, we just need to update it so that they, they can be, um, safe. But then the, the devices, like the OT devices that may not be able to, to, um, carry the, the algorithms that, that are, that are released by NS or the future algorithms that are released by, by ns. Um, those you have to gradually rip and replace them, but you have to wrap them into something that's a little bit more secure.
And that's where I think, you know, the, the Q secure technology is really, is really gonna help. Do we need to get smarter though, to your point about what we are encrypting or what we're gonna encrypt using the next generation of algorithms? Because while we have a massive amounts of data, and I think today we often encrypt stuff just by routine, but not all that data is necessarily worth protecting to the level that it is being at least protected at the moment.
And some business folks I've talked to are like, so let me get this straight. You think business data that I have today is gonna be relevant five years from now? Probably not in their mind.
So how do you kind of start to triage and prioritize, Right? So I mean, this is one of those big, uh, that's, that's one of those bigger problems, right? Um, so data lifecycle is, is a, is a really important, is issue, uh, understanding how long your data is relevant.
Yes. You know, um, if, if, if your business data is not relevant in three years and, and, uh, CRQC doesn't come online in, in, in three years, then you're okay. You know, if you, if you believe that as a, as an organization, if you believe your risk tolerance is three years from now, I don't have to worry about my data, and I don't think A-C-R-Q-C is gonna come online, then, you know, I I would say, you know, you handle, you do what you're, you can handle, right?
So, um, as if it's relevant five years from now, or if you have government data that you're protecting and things like that, you need to put, um, you need to put the those, you know, uh, you know, those systems and solutions in place to, to protect that data. The other piece of it, you need, uh, on, on not only the data owner side, but you need to understand, uh, how long is that data good for? How, how can I sit there and, and start to assess how long my data is good for?
You know, if you look at, um, mosque's timeline and you look at, you know, how long is your data good for? If you the data that's good for 30 years from now, if it's stolen now, you know, it's, it, you might as well, you know, say it, it's, it's out there, right? You know, you might as well, you know, um, I, I was at a, a conference and one of the gentlemen said, you know, just, you know, everybody, you know, pass your, open your phone, open your bank app and pass it to the person next to you.
That's basically what you're doing. And, and, and when you're, you're, you're doing your data. So I mean, all these things are gonna be, be really, really relevant.
So you have to understand that your data is, data is king. You know, everyone talks about, oh, you know, we've got gold, we've got money, but that data is really what makes businesses money and everything else. So if you are willing to risk that, that's, that's on your organization, you know, as, as far as as my advice is, I'm not willing to risk any data.
I, I don't care how how old it is, you should be, be protecting it, and you should be protected, not, not necessarily to the max, but you should have some protections in there that, that if it does get out, you know that you're, you're ready for it. Get risk mitigation in place. So if it does leak, what do I do?
What if analysis, what, what happens if this data gets out? What happens if this data gets out and start to, to put that in place? But those are, those are, you know, we, we, if if we're cynical about the, about the data, you know, once it gets out, you know, we there, there's no, you can't put it back in.
This is true. Um, so prior to joining Q Secure, you were with ciso. What is the role of the public private partnership for driving this change?
Should be, I mean, do governments around the world, should they just kinda issue an edict and says, thou shalt, you know, have this level of encryption? Or is this more of a, you know, coaching and general suggestions? No, I, I, I definitely believe on the, on, on the first one, right?
You, we need the policies and the governance in place. Uh, we need the governments to work with the private sector to understand not only their capabilities, but understand what, what the order of the possible is in, in certain timelines, setting the milestones. Um, we need to start putting milestones in place as, as, as, as the government, you know, governments should say, Hey, we are going to use this if, you know, if you don't use this, you can't work with us.
You know, that would be my then my way of doing things, because then that way you will force everyone to really be on that more secure, uh, encryption, um, the, the more secure encryption lane. And you're not looking at, at things that, oh, everyone's using something different, and then that, that brings a whole bunch of vulnerabilities in place. I mean, when everyone is not talking on the same, it's like, you know, if if you're talking, you know, a, a different language and I'm talking one language, you know, and we, we have a translator, it, it may miss some things, right?
I may use a slang, you may use a slang and it may miss some things. And, and I'm just trying to make it in a, in a simplified form, but I think, you know, you have to, everyone has to be on the same sheet of music with that, everyone has to, okay. You know, when, when I was at cisa, we did our, i I say, our international tour because we wanted to, to make sure that the, the international sector, what countries were going to adopt the, um, the n algorithms and what countries that we had to make sure that we, we tried to convince that, hey, this is, this is a, this is the way we are going and what is the way that you're gonna go?
You know, we, we had a couple countries that said, you know, we're gonna adopt some other algorithms as well, but we're gonna still adopt the, the n algorithm, which is fine, but we just wanna be able to, to talk to you and be able to communicate. So that's really important that everyone starts to focus the government, start to, to put more pressure on the, on the private sector to get their, their products, um, updated to, to where they need to be. You know, I, I'm, I'm here at qq and I, I've really seen some, some great things.
0, um, to, to really help with the procurement and, and, and get, you know, a start to, to get organizations, you know, to focus on, on some of the, the, the policies that, that the US government has put out. So I think that there's a lot of, um, there's a lot of good that the public private partnership can, can kind of, um, yeah, can kind of, you know, birth, I guess you could say. Are you at all worried that there'll be countries around the world that are researching this quantum computing platform stuff?
And, um, if they do have a breakthrough, it's not like they're gonna announce it. So they may just decide to hold onto that. And, you know, what we're calling Q Day could be coming a lot sooner than we think.
Yeah. I, I, I have to admit, I I, that does worry me every day. Um, the, the thing is that we've, I, you know, we always talk about this is the, the new Manhattan project, right?
The nuclear weapon. Um, is it something that you want to say, yeah, I've got it. No, because you wanna be able to take that data and, and use it.
You wanna be able to take that data that, that you're, you're still ingesting and still be, and, and be able to decrypt it. If you look at, you know, I, I always try to use this analogy about the, the historical significance when we're in the US and we're looking at, you know, uh, the codebreakers in World War ii, as they, as they, as they broke the code, the Germans were using, we didn't announce to them, Hey, we broke your code. You know, um, it, it, it was, no, let's use it for our advantage.
So I, I don't think that the, the adversarial countries or anyone who who gets it is going to announce it, I think it'll eventually come out because of the amount of power that it'll, that'll be used. Um, it'll like, you know, darken some cities and it in there. But, um, I, I do think that it, it is going to be one of the, the best kept secrets of, of any country that, that, um, is able to, to achieve that.
And, and it'll be a weapon that can be, that can be used to actually make, um, to actually become a world power. Because like I said, data is power. You know, uh, there's data oil and a couple other things that now electricity that, that are, that are paramount in, in this world.
And I, I think that data is, is, is really, um, once you're able to break your, your, uh, uh, any country's, um, data, you're able to use it against them. Mm-hmm. Um, what's your best advice to security people to have this conversation?
'cause I think they're a little tired of, you know, sounding like chicken little, and then the business people don't listen necessarily unless there's some, you know, immediate present threat. But, so how do I have a, you know, an intelligent conversation with folks about this so that, you know, they might allocate some dollars to go deal with it? Yeah.
You know, they, they often talk about tech debt. You know, I, I, I hear folks talk about tech debt and all those things, and, uh, they, they don't address it and everything else. Um, if you are willing to risk your, your company and the, and, and your business and have all your IP and all your intellectual property, all that makes you, you know, a true business, the, the, the secrets that make you a true business.
If you're willing to risk that and, and, and not put something that you know is coming and you are not willing to transition to that, you know, that is, that is, that is something that I, I, I say that, you know, that's, that's not the best move right now in, in transitioning this. I would say the, the, the main thing you need to do is get aware of the threat, understand how this threat is going to, uh, impact your business, impact your organization, get aware of it, you know, talk, talk to the experts, talk to the companies that are involved in it. You know, we're not alarmists.
We're just saying, Hey, look, you need to transition over to these more secure algorithms. You know, you know, we've, we've, we've been using encryption for, for many, many years, but it's always been that, that, you know, guy in the basement that's, that's dark and, and doesn't, you know, doesn't talk to anyone. And so, you know, you're like, oh, yeah, you know, that's, that's, that's, uh, that's Mike.
You know, he, he's in the basement just hanging out, but he does so much stuff for, for us. But if Mike takes a sick day and Mike drops out, then things fall apart. And that's basically what's gonna happen with encryption, is that it's gonna take a couple sick days, and then you, you're really gonna see, oh my gosh, we've lost all, all our encryption.
And then you're gonna worry about, why didn't we, why didn't we transition and have somebody, you know, uh, come in and, and have a backup to mic or, or have an upgrade to mic or something like that. So that those, those are things that you really have to worry about that, that, that you're, you're not looking at. So I think here, my best advice is, is prepare your organization for a transition.
Get the awareness, um, on, you know, start the education on there. Start taking the actions where, you know, you're, you're, you're procuring quantum safe, uh, you know, quantum safe, uh, products, quantum or quantum resistant products. Um, you know, talk to, to folks like us, you know, Q Secure that can help you with the risk management of, um, of your organization and, and get you into a place that you are not going to be at risk.
And, and with your competitor who did something who, who actually put some things in place and, and, and was able to, to be a little bit more secure. Because when you're, now, when you're trying to get government contracts or you're trying to work with foreign governments, you're not gonna have any leg to stand on. You're gonna, they're gonna be like, well, you, you're a risk, you know, you don't have these things in place.
And it's fairly easy, you know, if you, if you work with a company that's, that's really doing this and really understand it, and, you know, I'm working at Q Secure now, so they, of course, they're the best company to work with. But, um, if, if you work with them and you pull them in in place and, and, and they can help you get your risk management, get your tools, get your solutions in place to, to actually make things a lot more safe, so you can have con business continuity as, as we head towards the PQC era. All right, folks.
I heard it here. Hey, even in 2025, you know what's still true? Better safe than sorry.
Hey, Garfield, thanks for being on the show. Uh, thank you. Thanks for having me.
All right. And back to you guys in the studio.