The Y2K of the 2020s: Defusing the Quantum Threat
While Washington spends all its airtime debating the regulation of AI, there’s a multi-trillion-dollar threat silently gathering momentum that requires immediate action. QuSecure CEO and co-founder Rebecca Krauthamer, recently named to the inaugural Quantum Security 25 list, joins Techstrong TV to explain why the “harvest now, decrypt later” strategy by adversaries makes the quantum threat a problem of today, not tomorrow. Krauthamer breaks down how her company is abstracting encryption to the network level, providing a push-button solution to outmaneuver the slow crawl of enterprise migrations before the quantum “Y2K” hits us all.
Transcript
Hey everyone. Welcome back here to Techstrong TV. I am really thrilled to have my next guest on here.
You know, she's actually one of the few people we have who live in South Florida, so the last time she was on, she was nice enough to come up from Miami to our studio, and we did this in person. Unfortunately, she's not in Florida today. She's up in New York, and, so we're doing it via Zoom.
But let me introduce you to, Rebecca Krauthamer. If you... Maybe you saw or caught the last time Rebecca was on with us.
Uh, Rebecca is the CEO and co-founder of QSecure, a, post-quantum security company, and she's here today as one of the winners of our initial Quantum Security 25 list that we did in partnership with our friends at DigiCert. Rebecca was a worthy member of that list. I...
You know, as a judge, I, I was looking for her name when the nominations came in, so I was happy to see her on there. Rebecca, welcome back to Techstrong TV. It's great to have you on.
Alan, it's great to be back, although I do wish I was down in Florida with you in the, in the sun. Um, but New York- Well, I- -will have to do today. I, I heard it was warm in New York today or it was yesterday.
Maybe it got cold? I'm giving it a hard time. It's beautiful, sunny, clear, um- Yeah.
I, yeah, I spoke- It was like seventy degrees. Yeah. Yes.
I spoke to my brother. " We were up in Boston this weekend. It was really cold there visiting my, my older son.
Anyway, Rebecca, as I mentioned, you've been on the show before, but not everyone watching this saw that one. Give them a little bit of your story if you don't mind. Sure.
So my background, I came, I came out of the AI space, so I got to study AI at Stanford when, like, deep learning was the, was the buzzword. You know, now it's, now it's LLMs. Mm-hmm.
I worked in that space for several years, and then I kinda joke, in, like, twenty fifteen, twenty sixteen, I got bored with AI, and I wanted to see what was next. And so that's how I entered into the quantum world, and so we, we worked in the quantum space, like, building applications for early quantum computers. Uh, and then in about twenty-twenty, we got an initial grant from the US Air Force, and they said, "Hey, quantum computing, it's gonna do these amazing things, and can you help us out with the security side?
" And so that's what gave birth to QSecure, which is, as you mentioned, we solve that quantum threat. Excellent. " We solve the- I, I, I, I guess first we gotta define the threat, right?
Sure. What, what do you think the biggest... I mean, I know, but maybe not everyone out here knows the biggest threat that quantum, you know, supposes that, or it presents to ourselves.
So the threat is... It, it's got a lot of buzzwords, but it's pretty simple. Uh, every time we send data somewhere or data gets sent over networks and we want it to remain private, it's using encryption.
That encryption, we rely on basically one type of encryption for that... for, for our communications. That's the type of encryption that gets broken by a sufficiently powerful quantum computer.
So quantum computers at scale, and that scale is about four thousand qubits, they'll break all the stuff that keeps all of our, our communications private: emails, text messages, electronic health records, national security. So that's a big bad, right? It's coming.
It's coming fast, but it's not here yet, so why do we care? And we care because of this idea of harvest now, decrypt later, or the idea that bad actors are sitting in, listening in on those, those transmissions, harvesting that encrypted data, and stockpiling it for when that quantum computer comes online because a lot of that data will still be relevant. So there are now mandates, across US government, across the world to make this transition to quantum-safe infrastructure, and this is the thing that I find most business executives still don't know.
A lot of them know that there's a big threat, but they don't understand that it is largely a solved problem. And in twenty twenty-four, NIST, the, the National Institute of Standards and Technology, established, verified this new suite of algorithms that run on regular stuff, not on quantum computers, run on our regular devices, and these algorithms protect against quantum threats and classical threats. So when I say it's a solved problem, that means that you can adopt and should adopt these algorithms today to protect secure communications, and you do not need a quantum computer to fight against that quantum threat.
You just need to adopt those, those new encryption algorithms. Post-quantum algorithms. Exactly.
You know, to me... So we, we've solved post-quinto-post-quantum algorithms. We've come out with post-quantum algorithms.
I think the problem we have though is that, you know, you could lead the horse to water, but you can't make him drink, and that, and that to me is gonna be the biggest issue, right? We can't get people off of, you know, Windows Ten or whatever the latest version of Windows they discontinued, right? How the heck are we gonna get them to move-Into post-quantum algorithms Y- y- you know, it's...
It, it that's the, that's the, the trillion-dollar question. Um, we-- I was out in, on the Hill in DC, right? We were talking to some of the, the Senate offices.
And there, there's a lot of room, a lot of air being taken up on the Hill by AI. AGI, what are we gonna do about it? Are we gonna regulate it?
How should we regulate it? And these are big questions, right? These are things that people care about, but it's hard to find something definitive to say, "This is the path through.
" On the other hand, when it comes to the quantum threat, it's this big thing that's coming in, it's econometric modeling, right? One successful attack on one of the top five US banks could cost- cause cascading- Trillions ... financial failure.
Trillions. Two to three trillion dollars. Wow.
So this big thing coming, this big, big problem, but again, clear path through that forest, right? We have an answer. We have...
And it's not, it's not typical that we have this big of an issue that we know how to solve and yet, right, it's getting people to move because there's so much that in the cybersecurity world and beyond, there's so much that, that rightfully takes, takes up attention. So how do we get people to move? I, I, we have government mandates now.
The first timeline, the first part of that timeline falls into place at the end of twenty twenty-six. There can be no new, technology acquisitions into national security that don't support post-quantum cryptography after the end of this year. But, you know, I, I think back to Y2K and a lot of people think of Y2K as a, a anticlimactic.
Like, oh, was it over-hyped? Was it... But the truth is, the reason that, that nothing devastating really happened is because collectively there was a deadline, and collectively across the world, somewhere between six hundred billion and one point one trillion dollars in today's a- adjusted for inflation, it was spent to remediate, but they had the luxury of having that deadline, right?
And, and the reality with quantum is that we don't know and we won't know when it comes online. Right. So we need those, those government timelines, but we need, we need more, and we need this to be not just a boardroom discussion pushing it down, but we need everybody who is consuming, digital services to also be putting pressure on organizations to adopt in a timely manner.
Because I know personally, I use a lot of services and I want that data to be kept secret, not just for today but for, right, the next several years. I mean, you know, th- this is kind of an old story in security. Nothing happened.
You did your job. Yep. Right?
Exactly. Yeah. And, and, and when something happens, well, the stuff hits the fan.
But here, here is, you know, to me the, the biggest stick we have with, with forcing people to adopt post-quantum, whether it's kicking and screaming or not, is expiring certificates, right? And I know Google's moved towards this. They want to get to, what is it, a forty, like some odd number.
Was it forty-seven days or something like this? Mm. Of, of f- it wasn't like- It began ...
a thir- a, a month or thirty-one days. It was like forty-seven, every forty-seven days or something- Yeah ... the, the certificate expires.
And, you know, that's gonna force a lot of people who y- when we're talking about digital certificates like that for your websites, your SSL certificates, your, you know, your encryption that way. But so much of our PKI infrastructure doesn't necessarily run on a certificate issued by a third party that, you know, they could become the enforcement. Um, I, I just don't, you know, I wor- I honestly I worry about it because I know people procrastinate- Mm-hmm ...
by nature, right? Mm-hmm. And until there's literally a gun to their head- Right ...
they, they just don't, just don't do it. Um, let's talk about QuSecure a little bit. How are you...
How, how's QuSecure helping with that? So, well, you know, you just, you said so many things that are, that are true. And, and the procrastination is, is going to happen.
It's inevitable. It's something that we, we know people are gonna act at the last minute. The problem is, it's already the last minute, right?
So what we do, when we, when we started and we got that initial engagement with the Air Force, we understood three things I think before, before a lot of people were talking about this, just because we were in there. We were embedded. We were thinking about solving for this migration.
So one, the Air Force is a really good example of vast, often legacy infrastructure that is very hard to upgrade, a- and has taken huge investment to build out, right? So we can't ask people to rip and replace in the same way that, that past migrations have happened. So legacy, right?
Legacy compatibility. Um, two, the sprawl of like this... Everyone is still underestimating how big and how much effort needs to go into even just setting the groundwork to make this happen across all of that digital infrastructure.
So the scope, right? We need to help make the scope tractable. And three-This is not going to be the last migration.
This is probably the biggest that we've ever seen. However, this is really a forcing function for us to think about encryption management differently, right? We can't...
as, as AI, as quantum comes faster and faster, the threats to encryption similarly, right? Um, it's gonna be under attack all the time. So this is a catalyst moment for us to rethink how encrypted data security, right, is done.
And so what we do is, is we've abstracted out the encryption from the asset itself, right? And so, solving for all of these three things, making, simplifying deployment, we take it at a network level because this is where the quantum threat really is. It's, it's asymmetric encryption.
Um, so we decided to solve it at the network level. So we, we built a orchestration layer, a service mesh for managing and deploying encryption, so you can get up to date with your post-quantum cryptographic algorithms without again, rewriting any code. Um, and then should anything change, should you need to change out a library, an algorithm, you can then push a button and make that rotation happen.
Define your policies, whatever, whatever is within your organization's policy, that is, you can, you can just push a button instead of going through many years of a migration process. So that's what, that's what we do in a nutshell. And, what I'll say interestingly is that we don't always get brought into organizations to carry out the post-quantum migration proper.
Like you're saying, a lot of organizations need help with man- cert management. Um, or even just getting from, a lot of applications are stuck on TLS one dot two. You need to get onto one dot three to, to even start the migration process, right?
So this idea of cryptographic debt and management is, is a really important one. And often what we see is the, the first step, the forcing function even before post-quantum. Got it.
Rebecca, we're running low on time. I did wanna mention as I started this with you are on this inaugural list of the Quantum Security twenty-five, top twenty-five folks in quantum security. Some really big names there.
I don't know if you had a chance to look around at the rest of the list. I'm sure you probably know. One of the things I've discovered in this exercise is that it's a small world when it comes to quantum and quantum security, and a lot of these folks have worked together, know each other, you know, the whole thing.
I would imagine for you, there's a lot of familiar names on the list. Absolutely. Yeah.
I think there's only a, there's only a small few that I haven't actually met in person or worked with. But it's a, it's a, it's an honor. Um, it's an honor to be, be chosen by Dessert and by you and obviously Alan, you're a, you're a legend.
Um- No, no, please. You, you're gonna make it hard for my wife. Don't say that.
Um, but, but no, I, I will tell you, as one of the judges, you know, I, I actually used a little AI here and said, "Give me a weighting system- Mm ... " And, and, and it, it really helped to give at least the ones that I nomin- like my list that I submitted for the nominees. I, you know, I, it, it mixed it well and weighted well between, you know, pure researchers- Mm-hmm ...
business leaders, you know, business leaders, executives, you know, call them evan- e- e- evangelists. I mean, it, it, it gave me a good cross-section of the community, and that's what... I mean, we didn't want to make it all researchers.
We didn't wanna make it all CEOs. Right. We wanted a, a, a good mix of the people who are making it happen.
So I, I was really happy with the way it turned out. It was interesting, you know, we had four judges, we all submitted. I think when you took all four lists and, and, you know, did a diff- Mm ...
twenty-two or something like that of the twenty-five were the same. Wow. Wow.
It was just- And I imagine there were- The last three ... way more than twenty nominations. Oh, yeah.
There were, there were over a hundred, I think almost a hundred and fifty- Wow. Wow ... nominations in general.
But, like I said, I think we came up with the same twenty-two, and then we kind of went back and forth on the last three. I'm not gonna say who the last three were and who were the other twenty-two, but everyone on that list was deserving. Um, but and none more than you, Rebecca.
So congratulations on, on inclusion in the list. We appreciate it. Uh- Well, thank you ...
we appreciate you being in, you know, doing what you do. And look, next year you're coming back home, next time back here in the studio, okay? Back in studio.
Done. All right. Hey, enjoy New York.
Again, congratulations. Best of luck with QuSecure. We'll be in touch.
We're out here- Thank- ... though. Thank you.
Rebecca Krauthammer, CEO, co-founder, QuSecure here on Techstrong TV. We're gonna take a break. We'll be back.