Keyfactor CSO Chris Hickman Warns Q-Day Is Closer Than Many Realize
Chris Hickman, chief security officer for Keyfactor, explains why the day when quantum computers will be able to break existing encryption algorithms, also known as Q-Day, is much closer at hand than most organizations realize.
Transcript
Chief security officer for key factor, and we're talking about, well post quantum cryptography 'cause everybody's talking about it, but I'm not sure they know what to do about it. Exactly. Chris, welcome to the show.
Thank you very much, and thanks for having me. Mike. We have seen an inordinate amount of discussion about this topic, and it comes up because, well, there's a lot of advancements in quantum computing lately, and everybody's wondering when quote unquote Q Day is gonna be.
I guess my question to you is, when does this move from something I am theoretically concerned about to something that I need to be concerned about and do something about today? Uh, I mean, the answer is really yesterday. Um, because we don't know what exactly Q Day is, and, and I would argue we don't even know what Q Day is, um, you know, in a lot of respects.
Um, you know, so we kind of have to take it from a perspective of risk. What we do know is things like data is being stolen now to be decrypted later by, uh, a quantum computer when it's strong enough to do so. Um, so it's a today risk.
And yeah, what organizations really need to understand is there's a timeline now that's been put in place by NIST for the deprecation of, uh, RSA and ECC, which are two of the most commonly used algorithms for things like websites and, and internal, uh, authentication. And that timeline, uh, points towards 20, uh, 30 as a, uh, as a a time at which you should stop using those and, and absolute no longer allowed past 2035. And that's a pretty short amount of time to start uplifting and changing all the cryptography within a, uh, within a reasonable size organization.
And is this all tied to quantum computing or are there other platforms and technologies that the bad guys might be using crack encryptions and there might be parallel threats emerging alongside quantum? Yeah, you know, it's an interesting question and, and, and, and again, it kind of comes back to the, uh, uh, you know, what really is Q date, right? Uh, there's been a lot of work done around using existing quantum computers.
So most, there's sort of this fallacy that quantum computing is something of the future. Uh, there are actually quantum computers available today that are doing really good work, uh, in areas of, you know, natural sciences and drug simulations and, and all sorts of other things. Um, yeah, those, those computers just can't, uh, really reverse engineer, uh, the algorithms we have in place yet.
It requires a certain amount of qubits and, and certain, uh, amount of error protection. But, uh, you know, the, the reality is, is that the pace at which that development is happening is significant. And, uh, there are, um, studies that have been done and some success shown around using less capable quantum computers and then things like, uh, artificial intelligence to sort of do the last mile calculation against smaller key links, uh, and being very successful with that.
So, uh, you know, it, it really comes down to the fact that we've had RSA in particular for 30 odd years now, uh, you know, not a lot of other things have D lasted in technology that long. It, this is really just sort of a, uh, a maturation, if you will, of, uh, of the cryptography space. Then quantum computer, the threat of quantum computers is what's driving it.
I'm not sure people understand just how big a lift it is to replace the, uh, encryption codes that might have been used in a legacy application. So what is involved in that, and is it worth doing? Or should I just go buy some new hardware and software that comes with something that feels like it's resistant to quantum computing techniques to decode it?
So I guess the, uh, the, the, the easy answer is, uh, uh, you can go and buy all new stuff. Uh, you might have to, uh, in some cases, however, that's actually not gonna fix the problem. I mean, if we think of cryptography as a codependent ecosystem, uh, it really layers of things that give us cryptography from things, let's say like a, like a PKI certificate and there's a crypto library underneath, and then there's, you know, applications using that, and that's going through routers and so on and so forth.
Cryptography is everywhere within your organization. It's not a one, uh, point solution or a one place solution. Um, you know, I heard somebody recently say, if you've got data, wherever you've got data, you've got cryptography, um, you know, and the reality is, is because, uh, we wanna keep our data safe, um, so the, the uplift required to do the migration is considerable because it's not a single faceted asset that you just swap out A for B, uh, as a matter of fact, it requires a lot more consideration than that.
And cryptography is probably embedded in places your organization, you didn't even realize that it was. Uh, hence why the need for, for, uh, you know, one of the first steps to be that discovery piece, to go out and find it all, figure out what you've got so that you can make an assessment of what needs to change, at what points in time to keep your data safe. Hmm.
Not all data's created equal. Do I need to kind of spend some time trying to figure out, well, what data might be interesting to somebody to three, four years from now who's harvesting it and maybe focus on those applications first? Yeah, because I, as I mentioned earlier, you know, this notion of steel now decrypt later, or harvest now decrypt later, um, you know, those, those are assets that are being stolen today and they're encrypted and, you know, in a lot of cases, you know, they're, they're, uh, they're meaningful to whoever's stealing them for whatever reason.
I mean, you've gotta look at the sensitivity of the data that the shelf life of that data, right? How long is that data useful for? And then, um, yeah, what's the impact of, of that data becoming available to somebody else, let's say a foreign nation state or a competitor, perhaps even, uh, you know, and, and so yeah, data lasts, uh, over different periods of time and has usefulness over different periods of time.
Um, yeah. So it is important to sort of say, okay, what are the most critical things that I need to protect first? What are the things that I really don't ever want to have anybody else see?
Uh, and to go after those? 'cause you can't boil the ocean all at once. You sort of gotta have to take this, this, this methodology.
This is, okay, these are critical assets. I need to protect other critical assets, other critical assets, other critical assets, and sort of do it in that type of a, a, a timeframe or a sort of a, a data risk management approach, almost. How do I move this up the agenda?
Because especially in an age where, you know, most organizations are trying to throw every dollar they can find that ai, but, um, I need funding to go do this stuff. And so how do I get the business side to view this as something that is a near and present issue versus something that feels like, yeah, one of those Y 2K things that I'll worry about later. I guess there's, there's two sides to that coin, right?
Which is the first one is, uh, yeah, if we don't do this, our data is going to become public. And well, that sounds a little bit like sort of you, um, I'm crying, uh, wolf, uh, it is, it is a reality. I mean, that, that, that time will come if we don't take that step.
And if you, the closer we get to that Q day, um, you know, the more expensive it's going to get. Plain and simple. So let's do it systematically now, make sure we don't miss things.
I mean, the other thing, and you mentioned ai, right? Is AI is riding over top of exactly the same security. So, uh, you know, uh, you can, you can be putting piles of money into ai, but at the end of the day, you're still using certificates, you're still using TLS, you're still using those sorts of underlying technologies that are also prone to this same set of risks.
So you're really building a foundation for not only your existing applications moving forward, but as you start to really do things with ai, you need that, you know, post quantum secured, uh, um, platform to be able to really, uh, to use those sorts of technologies over time. Hmm. How serious or governments around the world taking this, I mean, have you seen them put out some mandates to require businesses to respond to?
Or are they mostly focused on their own data? So they're, they're, uh, the mandates that have come out so far have very much been directed towards, um, their own, uh, internal, um, you know, hygiene, if you will. Uh, you know, Canadian government, uh, US government, uh, eu, Australia, uh, every major geography has now come out with guidance.
Uh, however, it's not only to the, um, you know, federal departments, uh, necessarily, it's certainly is, uh, guidance that they're hoping industries will pick up. I think we will start to see some, uh, bits of regulation sort of come into play, especially in things like banking and critical infrastructure and, um, you know, uh, on, on the commercial side of things, starting to hear rumors and, and mumblings about, uh, you know, cyber security, uh, insurance, uh, starting to say, okay, you know what, cryptography is kind of the backbone to keep your data safe. If your cryptography is no good, maybe that's not something we wanna underwrite quite the same way as we used to.
Um, so I think, you know, there are things coming that are going to be, uh, causing organizations to step up and pay attention. Certainly what we are seeing is government, finance, healthcare, and manufacturing are very much, uh, uh, the, the organizations that are well down the path today. Mm-hmm.
And the folks that are harvesting this data, they seem to be mainly nation states, but they are passing that on to their favorite manufacturing partners or software developers. And this information is gonna be used to, uh, inform their future product development plans. I mean, they're gonna wind up using this data to compete against the people they're stealing it from.
Right. I think there's a high likelihood of that. Um, you know, the, the, the data is of value to them, whatever, you know, they see in it.
So, uh, you know, I don't think it's, um, uh, completely by mistake that some of the advanced precision threats that we've seen have been going after. Uh, things like, you know, uh, the US Department of State things of the sort, we know, you know, that the encryption they have there is very strong, but the data that they sold it encrypted, you know, it has a lot of value in future. So I think it's, it's very much, uh, uh, uh, you know, in, in commercial instances, IP and IP based, you know, uh, intellectual property based type of theft.
But I think in other ways it's also theft of, uh, of, of state secrets and, and things that can be used, uh, along those lines in future. Hmm. Ultimately, therefore, what's your best advice to security folks about how to have this conversation with people?
'cause um, they don't all wanna be perceived as chicken little in the sky as falling. 'cause no one will listen to them. Right?
Well, I mean, I think what's exciting is that, you know, we've been talking about this for quite a while, a key factor. 'cause we've seen it coming. Uh, you know, n started their work in 2016 in this space.
Here we are 2025. Uh, you know, we have been tracking on it for that long. But it is actually starting to get attention.
There is, uh, definitely boardroom conversations. It's become a boardroom, uh, type of conversation. Now, what are we doing to prepare, you know, I've heard about this, this seems to be real.
Uh, you know, there's, uh, been some announcements commercially. Uh, IBM recently made an announcement about their next generation quantum computer by 2029 probably being in a spot where it could start to break cryptography. And that's a, that's commercial implementation that anybody can go and use.
Um, so I think, you know, we are definitely seeing the attention there. Uh, but I think where organizations are not yet committed is, uh, is very hard as an individual. Let's say, you know, there's a PKI administrator type of person to go in and, and say, Hey, we've gotta solve this entire corporate problem of cryptography.
Um, you know, I think where it does start is let's go and figure out how big the problem is. So we can take, uh, you know, bite size, uh, but eat the elephant, if you will, one bite at a time to use that analogy. Um, you know, it really does start with that discovery and that inventory piece to be able to say, okay, here are the the things that I need to be most concerned about and the things that I can then begin to allocate in a meaningful way budget towards an effort towards to resolve and make my security better.
And then grow on that foundation with, you know, the intent being to build something that becomes agile with cryptography in the long run. Uh, so that next time we have a change, we don't have to go and rebuild the entire house. We can just sort of, you know, change out the, uh, the curtains and, and change the look and feel of the place, uh, you know, without having to rebuild the house.
Mm-hmm. Hey folks, one way to think about this is prior to IBM's announcement, Q day was thought to be sometime after 2030, and now we're talking 2029. If you're gonna assume that there's gonna be no further renovations, then you might be wrong because we might see some new advancements in quantum computing that could move Q Day up to well, 2028 and who knows, maybe even sooner.
Don't bet, Mike. My biggest fear is, is that we don't know when, you know, what? We will not know necessarily when Q Day is.
Q Day is not going to probably be a public announcement from a university that they were successful with doing this. Q Day is very likely going to be, you know, more nation state based more, uh, more, more, more, uh, uh, dark ops type, uh, of, uh, of, of, uh, uh, an announcement, if you will, if there is such a thing. And the data will simply be in the clear and we just won't know it.
Mm-hmm. And for all we know tomorrow, might the QA minus one. Hey Chris, thanks being on the show.
It's my pleasure. Thank you very much. Alright, and back to you guys in the studio.