Preparing for the Quantum Computing Threat to Encryption
Quantum computing poses a significant threat to current encryption methods, with organizations varying in their awareness and readiness. Regulated industries are taking proactive steps towards post-quantum readiness, but migrating encryption schemes is complex and requires prioritization. Concerns exist about nation-states potentially harvesting encrypted data for future decryption. The role of AI in enhancing security and automating processes is highlighted, along with the proposal for a crypto agility committee to prepare organizations for evolving threats.
Transcript
Hey guys, thanks for the throw. We're here with Dino De Marino, who's the newly appointed CEO for app vx, and we're talking about encryption and post quantum computing and all these things that are happening around our ability to secure on data. Dino, welcome to show.
Yeah, thanks for having me, Michael. I think everybody's kind of generally aware now that quantum computing might break our existing encryption schemes and that we need to replace those things, but I'm not quite clear that everybody's prioritizing that effort and it's significant. So what's your assessment of, where are we right now?
Yep. I think your, um, your observations are, are accurate to what we see as well. So between the trade shows we've attended, uh, the customers that I've spoken to, I think you've got a very broad spectrum of organizations that are acutely sort of aware and on top of this challenge, and some that are still, they still believe it's a little bit of a cloak and dagger when they hear quantum computing.
And so what we are seeing primarily is that in the highly regulated industry, so specific specifically financial services, insurance, uh, those organizations probably due to regulatory pressure are already sort of building a three to five year roadmap to be post quantum ready, uh, by 2030. Uh, so when you look at that cohort, they're actually quite, I'd say, acutely aware of the challenge. Um, and I think they have both, both monetary and compliance reasons to be, but you go downstream to some other verticals and to your point, you see people still struggling their so shoulders saying, Hey, this isn't really a thing yet.
We have a lot of time to sort of watch the market mature and see if the problem space actually comes to life. So how long does it take to actually migrate, um, your encryption scheme and are there certain things I should prioritize over other things first? Yeah, great question.
So it takes a while, uh, as you can imagine. 'cause when you think of the world of encryption, uh, in a lot of cases we think of it in the terms of, let's say a certificate, a public facing certificate. And even those things as, as tri as it might be to issue and revoke them, it takes time to sort of understand how many you have and then sort of create a program and a capability that discovers 'em, you know, then drives the revocation and the automatic renewal of them.
Things get very complicated when you think of cryptography in code and what, by code I mean software that companies build, as well as the crypto that lives on various endpoints, machines, containers. And so when you start to look at companies that are stake taking this seriously, so again, I think of some of the big banks here domestically and in Europe and Asia, they believe it's gonna take the three to five years that NIST is sort of guiding as a, as a point of guidance for 2030 readiness to actually sort of discover all the crypto, which is step number one, understand the context of it, um, understand what it might break in their applications as they move through shorter to longer algorithms. And then being able to work with the business to start to sort of create a program for, uh, the proper sort of revocation and lifecycle management of, of the various forms of cryptography.
Sue, should I start picking different applications to maybe the more mission critical ones and focus on those first? And I, 'cause I don't think I can do everything all at once, right? Yeah, I, I think, um, you know, you've got this post quantum movement and you also have Apple and Google, um, who are now sort of driving their public facing starts to become much more shorter in duration.
And so, you know, between the broader threat that you mentioned on post quantum, you know, some of the external certificate authorities and, uh, crypto infrastructure, that is gonna be likely the first jump point for an attack. I think in this instance you probably start outside in with a lens to mission criticality of applications. That's at least what we are guiding our customers for when we look at their sort of post quantum readiness journey, which is a multi-step journey, uh, which starts with discovery.
But I think that that the cab forum, um, which is, uh, one of the, the most, uh, I'd say powerful authorities as it relates to all things cryptography, certainly as it relates to public certificate authorities, is, is sort of, I think driving an awareness for the industry and a and a validation point that, you know, outside in approach on this is probably where organizations are gonna have to start. Not only due to the threat, but just due to the fact that the validity of certificates is shrinking at, you know, at a, at a pretty rapid pace. Also, we hear in reports that nation states are harvesting encrypted data and the assumption that they will be able to encrypt it or decrypt it later.
Sorry. Um, and so what do I have to be more careful about my existing data? Because, well, I mean, three years from now, some of that data may no longer be relevant, but others might be deeply embarrassing.
Yep. Yeah, I think this, uh, the concept we talk about is harvest. Now, deep plater, to your point, that is a, that is a threat that we have not seen come to life.
But as you know, uh, from your experience and, and even my past experience in cyber, unfortunately, once we know it's come to life, the attackers have, you know, got a very strong foothold in these enterprises. They've exiled whatever data have gotten whatever jump point to, let's say, uh, another organization. You'll think way back to the target breach that was actually this sort of motive for the original attack.
So the unfortunate reality is we don't know yet, Michael, what that world will look like. There have been no confirmed attacks that we were aware of on, uh, organizations from a a public cryptography perspective where that, uh, that's been used. But I think the challenge will be, the good news is organizations that takes post quantum readiness, uh, seriously, even if their information's been completely harvested, uh, as they start to rotate, you know, for, um, for a better, no better term, you know, rotate their cryptography to quantum ready, even if the adversaries then try to use that against them, they'll actually be in a point of stronger posture.
So there is a little bit like everything in cyber and arms race, um, but the good news is if they move to that posture, even if all their information has been harvested, that information to your point, would in theory be rendered useless. So I think this is why you're seeing the banking sector try to move so quickly due to the potential financial impact, business impact of, of these types of attacks. You mentioned the speed at which we're seeing certificates renewed, that seems to be putting a lot of stress on IT teams, and I think it's only gonna get faster because people are starting to realize, well, even at 45 days, a lot of damage can be done.
Right? Yep. I think what you're seeing is, uh, the word automation, uh, even just in the last two months is starting to become much, much more of a point of, uh, of interest concern for, for customers to the point that even internally at app ux we're talking about, you know, autonomous, uh, automation, meaning we're going to have to go to a place where we almost treat all of this cryptography as ephemeral.
It doesn't mean that it's gonna be ephemeral day one, but from a design standpoint, I think we have to think of a world which we're already starting to see in, in containers as an example, because those by proxy are ephemeral that we as the provider have to be extremely agile, not only in discovery, but in the ability to sort of pro provide context prioritization and then work at the speed of, of which the attack surface is moving. Um, but also the duration of this cryptography will likely be in the next 5, 10, 15 years. 'cause it is, to your point, such a painful part of the infrastructure to replace.
We're trying to do our best ultimately to future proof, you know, how we design products from that perspective. How will I manage all of this when in the age of ai there's gonna be more code, more services, more tiny little things that all have APIs and interfaces that need certificates. I mean, the level of scale at which we're looking at might be a little overwhelming.
Yeah, we, um, I mean there is already information in the market, you know, that, um, that we published even some of our, our, uh, peers in the industry that say there's anywhere from 40 to a hundred machine identities. Uh, and a certificate would be an example of one. An SSHG would be an example of one, uh, an API token, you know, that's authenticating one API to another would be another, uh, as would your iPhone, right?
Or your laptop. And so there's about 50 to a hundred of these for every human being on the planet. And that's today.
And so when you think of the fact that, uh, for the baseball fans out there, we are maybe in the top of the first sitting as it relates to artificial intelligence and how companies are using it, we do expect this geometric explosion of machine identities to, um, to occur and it's already occurring. So I think for, for us, we as an industry, I think standards become, uh, ridiculously important. Like how do we, even our competitors, how do we speak, uh, in an efficient manner with our platforms together so that we can drive a level of consistency and understanding what cryptography is out there, what machine identities are out there.
Then I think how we design technology for a hundred 1,010 XA billion x scale, I think becomes the next challenge for our engineering team as we think about the problem space, uh, and the volume of information we will have to be able to process, calculate, and triage. And then ultimately, going back to it, you, there's no way people will be able to handle this without automation and without thinking longer term about how their partners, uh, and vendors are driving autonomy on managing this with some, obviously some lens of oversight. Um, and the ability to drive, you know, detailed reporting on who's using what, where.
Because to your point, the biggest challenge we're all faced with is that size of it. It's going to be just massively, um, more volumous than what we've seen, uh, up until now. Who's taken the lead on this then?
Because historically certificates were more or less managed by security people, but now I need it people to go in and change the schemes and the developers' gotta get involved. So it clearly requires a village, but who's at the front of this effort? Uh, yeah, I think it depends on the organization.
So the maturity of the organization up to today, uh, to till today, let's say sort of predicates who believes that they're taking lead. I think when you think of the world of other categories like application security, cloud security, it is going to be more and more of a joint effort. 'cause to your point, it's been reasonably a siloed capability that either the PKI teams, identity teams or security have taken lead on.
Now it's gonna require DevOps in many cases. In some cases DevSecOps should absolutely be at the table, and it requires some level of oversight from your chief technology officer, CIO ciso. So we view this as a multi-stakeholder problem for sure.
And there has to be an understanding that, yeah, while cryptography is, you know, that weird thing that keeps all your applications secure, at the end of the day, it can also break your applications, which is why the, you know, the CTO and the app owners are gonna have to sort of partake in this journey, much like we saw with application security, where you had to bring security and application developers together to solve this problem. We view this as, as a different problem, but a similar sort of construct of needing, um, you know, a program around crypto agility, which is sort of the term that the, the, some of the industry is using. Um, and it's gonna look a lot like developer relations did, I think, as to how organizations started to build more and more secure codes.
So that's something again, our more, um, mature customers are starting to either think about or build inside of the four walls of their organization to tackle this issue. As you kind of figure all these things out, what ultimately will differentiate somebody who says that they have a post quantum encryption scheme versus somebody else? 'cause this is, seems like every time I turn around lately, everybody's kind of standing up and saying, we have one.
So which one you using? Yeah, I think, um, unfortunately if you think of a, a pre quantum world that we're living in, and we have lived, lived in, certainly on the public certificate authority side, there's been many, uh, distrust situations, which is an industry term that we use. Uh, we're from various re reasons, the certificate authority itself becomes distrusted and in some cases, and there's validity to that.
Um, and I think that it was right for the various forums to, uh, to sort of flag that these vendors weren't keeping up their end of the bargain on, on how the cryptography was working and the other standards they needed to adhere to. But in this new world, I think because of how agile things become, it's, I mentioned it earlier, standards in general I think become just sort of a table stakes thing that all vendors are gonna have to lean into. And again, I think of the, of a world of, of discovery integrations and automation is what I think our customers will need to solve this problem.
And they're going to need a level of agility probably in order to handle distrust situations where they will be able to maybe change from one certificate authority to another or one crypto authority to another, just based on how fast and agile, um, the industry is moving. But also, you know, the threats and the compliance standards are moving not only for our customers, but for us as the vendors. So this world of agility, that crypto agility concept really speaks to it for me, not just on the customer side, but being able to manage even the vendors that you have to deal with and having some level of agility and not being locked in, if you will, to, uh, only one or two, let's say of your, uh, your currently trusted certificate authority advisors or partners.
Are we gonna be able to maintain the level of interoperability that we've historically seen in this space, especially among certificates across all these different post quantum implementations? Or are the standards gonna be so loose that maybe we'll have more friction than we're encountering or thinking we are gonna recount? Yeah, well, if you know the answer to that, let me know.
I think if that's a big question mark for us, um, because I think the problem we've had is, look, if you think of PKI, the original instantiation of on-premise PKI, um, you know, and, and many of of us out there of seeing you, whether it's entrust or Microsoft certificate authority inside the four walls of our organization, you had in many cases, years, if not decades to sort of manage the revocation or reissuance. And as we've talked about, you're not going, you know, from years to days as far as that speed. And you're now, to your point, injecting a whole bunch of new standards in the crypto itself, uh, the length of the algorithms, um, who, who is going to validate those.
So we are definitely, when I talk about integrations to my team, it's really to make sure that we do the best we can to stay on top of all the different standards that, um, that are gonna be pushed down or pushed into the industry. And I do think we're gonna see, uh, some issues because of the speed at which we have to move between now and 2030, which is sort of the NIST guideline date for post quantum readiness. Um, and I think it's really early days we'll be, you know, happy to update, you know, you and, um, your organization as far as like what we're seeing out there so we can cascade that to the market.
'cause I think you're right, the speed at which everything's moving, I think standards are the right thing to do. There's gonna be harder and harder to execute as a collective, um, community going forward. A lot of folks may be hoping that some magical AI pill will emerge that will help us migrate these things faster.
I mean, what work is being done to kinda improve that rate of migration? Migration? Yeah, I think, um, I think customers are, are okay to be pushing us to think about it in that respect, because I do think, um, you know, it's very hard to have a human oriented approach to manage a machine oriented problem, if that makes sense.
So especially one that's driven by, uh, a very, very extremely intelligent ai in many cases, the Gentech ai. And so when we think about how we design technology, again, it's very much trying to keep up with, um, with the way probably our adversaries are gonna use artificial intelligence as well as how our customers will. So AI, I think for any modern organization has to be sort of the crux of how you think of solving a lot of these challenges.
And we're no different. So we're having a lot of conversations specifically around how agentic AI starts to take some of the human workload off of our customers, starts to make some of the, the medium to sophisticated decisions that currently today the product, uh, wouldn't be trusted to do. Not because it's not a trustful product, but because we might break a business process, you know, do some of that testing that you see when certificates break, things that we can sort of offload on the customer.
And so I actually think AI becomes this, this extremely powerful, uh, capability for us. Um, and it may not be the magic pill to solve this problem, but I, I do. And I think our engineering teams absolutely believe it becomes a very big part of how we start to, to scale and match.
So the speed and sophistication of, of the problem space that we're in. So ultimately, what's your best advice to folks then about how to approach this whole issue is as they, we look at it, 'cause it's twofold, right? One is the pace is getting faster, and then two is I kind of need a major upgrade.
I think for me it, it's, uh, it doesn't start with technology, it starts with people and process. So, you know, if I were on the other side of the wall, and I guess at this point I am because I'm accountable to my own customers cybersecurity programs, we are starting to talk internally about a crypto agility, uh, committee within our company. And as I mentioned earlier, that's a combination of our product and engineering organizations.
Security, admittedly is the coordinator of it, uh, as well as, you know, downstream it. And, um, you know, making sure that we start to have the conversations of number one, understanding baselining, like where are we today? You know, where and what do we have?
So think of posture as sort of step one of your crypto footprint, um, understanding the potential impacts both to your business as it relates to your homegrown applications, you know, your off the shelf applications, your cloud applications, cloud workloads. Um, and then starting to prioritize based on I think two lenses for me, sort of threat, uh, as well as, you know, compliance and compliance. I would view, you know, things like the 47 day TLS cert, uh, movement that we're seeing.
Like that's something we just have to do so that we'll have to get prioritized and creating that roadmap that allows us to comfortably achieve, you know, that post quantum readiness by 2030. So in many cases what's exciting being a CEO is you can almost use your own, you know, your own test case, even though we're not the size of a, a very large bank, but the concepts are, are very similar as to how we think we should set it up. So this sort of crypto agility committee is, is to how we're thinking of sort establishing, understanding credibility to then start the technology, um, migration, if you will, to a world where we're hopefully significantly more agile than, uh, the world is today as it relates to crypto.
All right, folks, you heard it here. This whole area that many of us have taken for granted for years. Well, we need a better plan than just crossing our fingers and hoping for the best from here because bad things can happen.
Hey Dino, thanks for being on the show. Yeah, thanks Michael. It's always good talking.
I'm back to you guys in the studio.