F5 Field CISO Chuck Herrin on Preparing for Post-Quantum Cryptography Challenges
Chuck Herrin, field CISO for F5, explains why organizations need to get ahead of the post quantum cryptography (PQC) now before they are overwhelmed by myriad challenges.
Transcript
Hey guys, thanks with Throw, we're here with Chuck Hern, who's field CISO for F five, and we're talking about quantum computing and a, what are some of the actual real world applications today, and B um, we're gonna dive into cryptography a little bit and what's gonna be required and what we should be concerned about, and maybe what's a little more fanciful. Chuck, welcome to the show. Thanks Very much, Mike.
It's great to be here. I think we all think of quantum computing as some awesome thing that's gonna happen three to five years out, but there are applications being used today. There are APIs and cloud services.
So what are you seeing folks actually doing with this stuff? I Mean, there, there's certain fields where it's already making a difference, you know, uh, uh, materials, engineering, medicine, things like that. But I haven't seen a lot of broad adoption yet.
But there are a live quantum computers that you can go and rent space for, you know, right now, and have been for, for some time. Um, what we haven't seen yet, what's not real yet, as far as we know, are, um, the biggest areas of concern for security practitioners, which would be what we call a cryptographically relevant quantum computer or A-C-R-Q-C. So, jargon alert, there, there are some specific terms that, uh, uh, you know, some of our viewers may, may not have heard before, so I'll try to spell those out.
You know, without getting into acronym, uh, acronym stew here, but what we don't think that we, any, any quantum computers exist that can break modern encryption and modern key strings now, but we do know that they're coming and we've seen a great deal of investment in, uh, into quantum just in the last month, for example. Well, this month was a big watershed month. We had, uh, one quantum computer company go public.
We saw over a billion dollars in inflow from VC going into quantum players. So we're, we're definitely getting to a, a critical mass takeoff point that defenders need to be ready for. Yeah, we hear a lot of people talking about Q Day, which is the day when these things can break some of these more relevant cryptography algorithms, but, um, no one's quite sure when that's gonna be.
Some folks are, you know, pointing to the end of the decade, and other folks say, well, uh, it may have already happened and we just don't know it. So, where are we on this curve? Yeah, right, right there with you.
Um, if it exists today, it is most likely in the hand of one of the nation states and it's poor strategy to, for them to tell us that it exists. Um, so I, I don't, I don't want to get into the, uh, you know, the dark sections of speculation too much there. But, but what I would say for the, um, for the defenders who are trying to figure out, like, when do I need to start tackling this?
The time is now. I don't think that it's time to panic, but now is the time to start laying the groundwork because there's a lot more to this and getting ready for the world of, of, you know, where post quantum, uh, cryptography becomes something we actually have to worry about every single day. There's more to it than just swapping out a cipher.
There's a great deal of inventory, supply chain stuff. I think people are, are not factoring in the amount of GRC type of compliance that we're gonna have to deal with from a supply chain and ecosystem perspective. Testing, integration testing, uh, IOT devices, you know, OT devices, things that don't have a clear upgrade path.
This is gonna take some time. So, uh, as, as we're telling folks, you know, we're, we're closer to 2030 than we are 2020, and and you are not gonna be over prepared for this. Um, there are a lot of good reasons to solve problems today by reaching what we call the, the, the crypto agility target state, where you can roll your encryption whenever you need to without starting a new quantum project.
Um, and this is a key point that I wanted to, to kind of bring the, the viewers into the target state for, this isn't a one-time upgrade. The, the target state for getting ready is crypto agility. So we're recommending things like, you know, start thinking of crypto as a service where you centralize your libraries and you centralize services for cryptography across your applications to the degree that you can, so that when you have to roll your ciphers in the future, it's a much lower lift than it would be today, right?
Because the, the computers that we're trying to defend against or protect against, they, to our knowledge, haven't been built yet. And these new standards, even though they went through very rigorous testing from NIST when they were ratified, right at a year ago in August of last year, the first set was ratified. They've never really been run at scale in the real world.
So there's a lot of stuff we really don't know yet about how it's gonna go. We don't wanna try to do all this all at the same time in the panic that now we have to do this, you know, in the next three months, right? This is gonna be a longer tail effort than this.
So it is time to get started and start laying that groundwork, especially when it comes to stuff like creating internal business cases for this, this is a very technical, kind of esoteric topic, and to your point, it's always been a future problem. I think CISOs and CIOs are gonna have to do a lot of internal education about what is this, why do we need to do it? How much do we think it's gonna cost?
Uh, what is the impact to our supply chain? I don't think this is as much a security issue, although the clearly security implications, this is a, this is a business continuity and supply chain governance issue. Like this is a much bigger thing than if you think like patching open ss l for Heartbleed, right?
That there's a lot more moving parts to this and it's gonna take some, some coordination and governance. Uh, we, we need to get started. Now, To your point, um, this isn't really an event.
It's gonna become more of an ongoing process. And I say that because won't the quantum computers just get more and more powerful so that, which we think today is quantum resistant, might not be quantum resistant. Three to five years out, Totally eight character passwords used to be just fine, then 12 character passwords were fine.
Now, you know, anything, but, but, but pass phrases and pass keys is, you know, almost immediately vulnerable and, and passwords in general are broken, uh, without MFA. So, you know, as, as the capabilities for for the attackers continue to, to escalate, we're gonna have to continue to respond and, and hopefully respond as quickly as we can. Because, you know, a lot of critical industries, if you can't keep your secrets, you, you know, you can't play along, you can't be in that space if you, if you can't secure your encryption, you can't like, you know, be a bank, for example.
Um, and so what we may see, and what I think we'll probably see is I think we'll see compliance requirements actually driving a lot of the timeframes. Um, we talk about 20, 29, 20 30 windows that we're seeing pop up, you know, in the federal space here in the US New Zealand, for example, just published a paper that said, uh, we haven't defined standards yet, but as soon as we do, you've got two years from that date to get ready. So we, we think that compliance is gonna drive a lot of these timelines, and I hope that the compliance timelines are conservative enough so they actually front run Q day, but we don't know, Right?
And even so, if history's any guide, compliance mandates will be the bare minimum, right? And that may not be good enough anyway, A hundred percent. I I I, I, there's very little, I I really struggle with more than compliance driven security, right?
Compliance is the bare minimum. Like being compliant is like showing up to work mostly sober wearing pants most days. You know, it, it is not the hallmark of a well run shop to meet the minimums that somebody else said you had to do to be a responsible participant in your industry.
That's not the target. Uh, it shouldn't be the target. It's the bare minimum to avoid getting fired or excluded.
Um, so yeah, I really hope that that that doesn't wind up being the end all be all benchmark, uh, because there's a lot more business value you can unlock by actually having a good handle on your inventory and your cryptographic assets, right? There's good business reasons to get this under control. So what will be required here, and I think a lot of organizations are struggling with this because they're saying, well, you're gonna tell me that some of my data will be exposed three to five years from now.
I don't care about that data three to five years from now. So do I gotta pick my shots here about what data I do need to maybe upgrade? But at the same time, they'll also say, well, I'm gonna get new infrastructure and I'll probably have new applications in that timeline that will come with PPQC capabilities.
So what is this journey gonna look like? Yeah, totally. And, and you're spot on some of the data that we need to protect every day.
Like, let's take credit card numbers, for example. Um, mosque's theorem is a good, uh, is a good sort of way to explain the, the time factor here, uh, for pqc. And that basically says, um, how long do you need to protect a certain set of data and add that to how long it's gonna be to get ready for PQC and migrate your stack over?
And if those two things are longer than the date that we expect a, a, a full fledged, uh, cryptographically relevant quantum computer, then you've got a today problem. But to your point, not all of our data we need to keep safe forever. Credit cards, they expire every few years.
Yeah. I'm not worried about a credit card number 20 years from now getting exposed, right? That that's, that's a, it's, it's a temporal thing.
But other things, intellectual property, state secrets, uh, source code, um, internal information that, that you want to keep secret for long periods of time. Medical records, banking records, financial transactions, and the ability to, to impersonate and spoof, uh, official parties, right? Because it's not just the confidentiality, but there's also the, the message digest and hashing and the binding of that encryption to the signing object.
All of that stuff is, is gonna be, is gonna be relevant and, and we need to prioritize that based on what, what's the longest length of time that you need to secure particular data and really start there first and focus on, uh, the, the asymmetric encryption, right? So symmetric encryption like a ES, um, we've had a lot of speculation about, um, whether or not symmetric ciphers were gonna be as dramatically impacted. It looks like they won't be.
And, um, further, when you actually break down how an attack against a ES works, for example, I've seen very recent research that says maybe a ES 1 28 is actually gonna be fine. Um, so we know where we can focus and we know we need to focus on asymmetric graphy and long-lived data. And that's where we can start.
And for companies that don't have an idea of where to start, I recommend starting with your business continuity program. Hopefully you've got a BCP that shows what your critical apps are, where they live, who they own, who you know, who they're owned by, uh, and things like that. So you don't have to do it all at once.
Absolutely not. Is this just a quantum issue? And I asked this 'cause I've seen some research that suggests that people are using GPUs and conventional computers to crack some encryption codes as well.
And this could become a broader problem that goes beyond just quantum. It could be sooner than we think because somebody's gonna do some sort of technical advance. We weren't thinking about Yeah, well, to totally.
Um, and, and I don't know about what specific is, is going to, um, is gonna break next, but I will say that we are living in an exponential age. And so if you look just, just in 2025, just this year before January, or excuse me, before February of this year, uh, we had no way, uh, to have a stable enough environment that you could put a thousand qubits or a million qubits on a single chip. Well, now we think we do.
Microsoft said in, in February that they've got a clear path with, with their breakthroughs in Miana to get a million qubits on a single chip. And that's what they're targeting. In May of this year, just three months later, the estimate that we would would need 20 million noisy qubits to crack modern encryption, Google researchers released a paper and said, nah, we think we can reduce that by about 95%, so we need about a million noisy qubits.
Uh, and so that was three months in, in three months we went from needing 20 million to 1 million and also, uh, a path to 1 million on a single chip. This is happening fast. I, I don't know what the next convergence is gonna be, but I do know that the, the, the more advanced AI gets and the models that we're using now are amazing, and they're only getting smarter.
Things are gonna move faster than we think. I don't think Q Day is a 20 35, 20 40 problem. Um, and humans aren't very good at predicting this exponential adoption curve, right.
In 2021, if you asked a bunch of AI experts, when do you think we may see a GI? The consensus was 2040 to 2070. That was just four years ago.
I don't think anybody says we're 25 to 40 years away from a GI, you know, sitting here in September of 2025. If we haven't hit it already, it's right around the corner. Mm-hmm.
Um, when you kind of piece this together for a minute, we've always talked about data security and compliance and all that. Well and good, but is this also starting to be elevated into a national security issue where because of the nation states that are involved and what they're gonna do with that data, governments around the world are gonna be paying a lot more attention to this? A hundred percent.
A hundred percent. If you're in a government supply chain, this will impact you, uh, and it will impact you on the government's timelines, not necessarily yours. But when you think about the, the geopolitics, uh, of, of the situation, which is notable in material, because I'm glad you brought it up.
There's really two parallel race conditions that the US and China are, are on. And there are others that are in this race, but the, the most consequential I believe are, are the US and China as the major superpower sort of military powers. Uh, that's AI and quantum, uh, AI supremacy.
AI dominance means potential global dominance. Uh, it's very hard to fight 'em in an enemy militarily that's smarter than you are. And quantum dominance also means, uh, you know, potential geopolitical dominance, uh, at the intersection of AI and quantum, who knows what's gonna happen.
So a hundred percent the the nation states are, are run at this. Both the US and China are on very, uh, combative and adversarial, uh, footing. And neither one is, is really making much provision for off-ramps.
So we're, we're in this race condition, and, and I don't see a way out of it, uh, without, uh, a substantial shift in relations between the superpowers. Uh, and I I don't see that happening in the next few years. So what's your best advice then, to cybersecurity people about how to have this conversation, you know, with business folks in a way that, you know, they'll listen and they don't mix.
Don't sound like, you know, here's another chicken, little sky is falling thing happening. A hundred percent. I really encourage, especially for, for organizations that are part of, uh, industry groups, uh, for example, we spend a lot of time in, in banking.
I come from banking. I was a bank and, uh, insurance company, CISO for a long time. Uh, groups like FSI, sac, uh, the Financial Services Information Sharing and Analysis Center, they, they're, they're pushing and we're advocating and we're supporting an ecosystem view of this, right?
So, so that the, the member banks can go and say, Hey, everybody's doing this. The banking industry is moving this way. And take the pressure away from, you know, Chuck presenting a compelling business case internally, or Mike presenting an internal business case that's compelling.
We're saying, look, we're all going this way. We all need to do this. And, and take the attention away from the individual necessarily that's bringing it.
I think that'll help. And the other is, I think to frame it in just a, a credible business continuity type situation, that this isn't just a security issue, this is integrity, it's availability, it's confidentiality, it's, it's all of it. Um, and start with, we need to do some discovery.
We need to understand how big this is gonna be for us so that we can come back with better numbers for how much we're gonna actually gonna need to, to remediate this. But there's gonna be some long tail stuff with you're, you're gonna have to deal with suppliers and physical devices and things don't have upgrade pads and HSMs and things. So I think it's worthwhile to explain kind of the basics.
The entire industry that you're in is moving this way, or maybe you're a key supplier to somebody that's moving this way and you have to do it, or you're gonna be replaced as part of, you know, their, their supply chain management. And let's get our arms around this, see how big it is, and then come back with some credible numbers and, and describe the actual work that you have to do. But most companies really haven't even started with the inventory yet outside of banking, telecoms, and government.
All right. Hey folks, you heard it. Here.
We have an opportunity to do something historic. For the first time ever, the cybersecurity industry could be ahead of a problem rather than chasing one. Hey, Chuck.
Thanks Pete, on the show. You Got it. Thanks very much, Mike.
All right. And back to you guys in the studio.