The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Security Cryptography Whatever
Security Cryptography Whatever artwork

Trump's Golden Post-Quantum EO(s)

Security Cryptography Whatever · 2026-07-02 · 57 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality12 / 20
Guest Caliber13 / 20
Specificity & Evidence14 / 20
Conversational Craft9 / 20

Trump's new executive order accelerates the U.S. government's post-quantum cryptography migration deadline from 2035 to 2030 - 2031, triggered by March 2024 breakthroughs in quantum computing efficiency and attacks against elliptic curve cryptography. Google and Cloudflare had already announced moves to full post-quantum migration by end of 2029 in response to research showing quantum computers could threaten P-256 ECDSA signatures far sooner than previously expected. This episode unpacks the EO's technical requirements: federal systems must adopt NIST-approved post-quantum FIPS standards, with national security systems (NSA, DoD, SCI) moving to the stricter CNSA 2.0 suite by 2031. Deirdre and David break down the distinctions between general federal IT (transitioning by 2030 - 2031) and high-security systems, explain the practical mess of FIPS certification via CMVP versus CAVP, and discuss implications for critical infrastructure operators. Essential for security architects, government IT procurement officials, and anyone responsible for cryptographic systems facing imminent compliance pressure.

Key takeaways

  • →The U.S. government is moving its post-quantum cryptography migration deadline from 2035 to 2030-2031, with national security systems potentially needing compliance even earlier under CNSA 2.0.
  • →Google and Cloudflare announced end of 2029 migration targets after publishing research showing more efficient quantum attacks against P-256 ECDSA and advances in neutral atom quantum computers.
  • →The executive order applies different requirements to federal information systems (using NIST FIPS standards) versus national security systems (using more constrained CNSA 2.0 algorithms), with new procurements required to be CNSA 2.0 compliant starting in 2027.
  • →FIPS certification processes including CMVP and CAVP have significant delays and bureaucratic requirements that will impact how quickly cryptographic modules can be deployed government-wide.
  • →The 'store now, decrypt later' threat model is the primary justification for the accelerated timeline, where adversaries collect encrypted data today to decrypt once quantum computers become operational.

In this episode

  1. 1Opening and Episode Context
  2. 2March Quantum Attacks and Google/Cloudflare Response
  3. 3Trump Executive Order on Post-Quantum Cryptography
  4. 4Executive Order Language and Store-Now-Decrypt-Later Threat
  5. 5FIPS Standards and Federal System Requirements
  6. 6High-Value Assets and National Security Systems Definitions
  7. 7CMVP and FIPS Certification Process
  8. 8PQC Transition Coordination and Government Leadership

Mentioned

GoogleCloudflareNISTNSATrumpDeirdreDavidEinsteinChromeKyberFIPSCMVP

Topics in this episode

Post-Quantum Cryptography (PQC)NIST FIPS standardsCNSA 2.0Elliptic curve discrete logarithm problemP-256 ECDSANeutral atom quantum computersCMVP (Cryptographic Module Validation Program)CAVP (Cryptographic Algorithm Validation Program)Store now decrypt later threatGoogle quantum computing research

Questions this episode answers

What is the store-now-decrypt-later threat mentioned in Trump's executive order?

Adversaries are collecting encrypted U.S. government data today with the expectation of decrypting it once quantum computers become operational, making historical encrypted data vulnerable to future quantum attacks - a live threat if quantum computers arrive sooner than expected.

What triggered the U.S. government to accelerate post-quantum migration from 2035 to 2030 - 2031?

March 2024 research results, primarily from Google, demonstrated more efficient quantum attacks against elliptic curve discrete logarithm problems (especially P-256 ECDSA) and advances in building quantum computers using neutral atoms, moving the projected timeline for cryptographically relevant quantum computers significantly closer.

What is the difference between CNSA 2.0 and general federal FIPS post-quantum standards?

CNSA 2.0 is a stricter, more constrained suite of algorithms used only by national security systems (DoD, NSA, SCI) with parameters set to the highest security levels and post-quantum-only compliance; general federal IT can use the broader NIST FIPS standards with hybrid approaches combining classical and post-quantum cryptography.

What is the difference between CMVP and CAVP certification in FIPS standards?

CAVP (Cryptographic Algorithm Validation) simply verifies correct algorithm implementation against test vectors, while CMVP (Cryptographic Module Validation Program) requires meeting arbitrary additional requirements including module boundaries, self-tests with fixed randomness, and platform-specific certification, making CMVP far more onerous and time-consuming.

When will Chrome support post-quantum cryptography for private PKI certificates?

Chrome 150, releasing June 30, 2024, will enable support for post-quantum cryptography in private PKI environments, though publicly trusted HTTPS certificates won't support post-quantum algorithms for several more years.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode is genuinely dense with technically non-obvious content - distinguishing CMVP from CAVP, explaining why signature migration is harder than key establishment, clarifying that AES-128 is quantum-sufficient against Grover's, and detailing CT log scaling problems for PQ certs. Diluted somewhat by World Cup banter, Facebook asides, and production meta-talk at the open.

doing key establishment is basically just update your OpenSSL
AES-128 is, is fine. You do not need to upgrade. The only reason you need to upgrade is if you need to be compliant with CNSA 2.0, and that's just because they, they put all the parameter sets to 11, not because they actually are protecting against Grover's attack.

Originality

12 / 20

Several genuinely fresh framings: the argument for abolishing CMVP entirely, the insider account that CNSA 2.0 new-procurement language really means 'you better not charge us an update fee,' and the behind-the-scenes characterization of the Google quantum paper as a physics-vs-security culture clash rather than NSA suppression. Core is still expert news reaction, not first-principles reconstruction.

what it really means is you better not be charging us an extra update for it
my feedback is to just simply get rid of CMVP entirely

Guest Caliber

13 / 20

No external guest - both are co-hosts who are active practitioners. David Adrian is co-discoverer of the DROWN attack with documented operational FIPS/CMVP experience; Deirdre Connolly has deep working knowledge of TLS implementation and PQ standards. High practitioner floor, but the no-guest format caps the ceiling for this dimension.

when DROWN happened, like the way we got involved at Michigan was we heard there was a rumor that like there was something wrong with SSLv2
I've, you know, worked with teams that I've had to make changes so that it can go through CMVP, but I've not been the point person to like, take something to a lab, get it tested, submit that to NIST

Specificity & Evidence

14 / 20

Concrete and accurate throughout: the Google quantum paper figures (2.1M gates, 1,425 qubits), crowdsourced improvement numbers (25-30% fewer gates, 45% fewer qubits), Chrome 150 June 30th ML-KEM support, OpenSSL 3.5 hybrid default, ML-DSA final standard July/August 2024, 18-month CMVP pipeline, and specific algorithm identifiers (ML-KEM 768, ML-DSA 44, CNSA 2.0). Minor vagueness on qubit counts mid-discussion.

The Google publication was 2.1 million gates and 1,425 qubits
Or excuse me, 25% or 30% less gates and like 45% less qubits

Conversational Craft

9 / 20

No traditional host/guest interview structure - both are co-hosts doing joint analysis. They do correct each other in real time and build meaningfully on each other's points, but there are no probing follow-up questions, no productive disagreement, and no pressure applied to unsupported claims. The format is collegial co-analysis, not adversarial craft.

Start of 2029 actually is what Google -
Oh, did they say that?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

david109deirdre106quantum49security27cryptography24fips22sure18attack18government15section15national15post14google14cryptographic14blah14algorithm13

Episode notes

The dear leader has actually bleated out some not-dumb executive orders (EOs) to accelerate adoption of post-quantum crypto for the US government! This looks to be in response to a flurry of advancements in quantum computing and quantum attack algorithms a few months ago. We cram legalize into our eyeballs - plus, ECDSA.fail! Watch on YouTube: Transcript: Links: - The EO - CNSA2 - - - - - - - - - "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

Full transcript

57 min

Transcribed and scored by The B2B Podcast Index.

1 - > David - Recording earlier because like, I don't want to do 2 - > cold opens anymore. 3 - > I just want to have something from before we actually start 4 - > talking to edit it because I hate copy pasting things in. 5 - > Deirdre - Okay. 6 - > David - For example, this.

7 - > Deirdre - Hello, welcome to Security Cryptography Whatever. 8 - > I'm Deirdre. 9 - > David - I'm David. 10 - > Thomas is on a plane or something like that.

11 - > He's either buying a bandsaw or on a plane or both. 12 - > He has a bandsaw on a plane. 13 - > It's a whole thing. 14 - > What do you say?

15 - > Deirdre - And I hope he doesn't get arrested. 16 - > Um, we have a special emergency pod where we're hopping on to 17 - > take advantage of the news that there is a new executive order 18 - > about post-quantum cryptography specifically. 19 - > It's not just buried in like 100 pages of a Kyber EO, um, and 20 - > the, the top line headline is the U.S.

government is moving up 21 - > its post-quantum migration from approximately 2035 to 2030 and 22 - > 2031. 23 - > Uh, so it is ordered, so it shall be done. 24 - > Because Golden - because Trump signed it with the big pen. 25 - > Um, and so this is our excuse to finally catch up on a bunch of 26 - > news about quantum attacks and post-quantum cryptography and a 27 - > whole bunch of other little thingies that have happened in 28 - > basically the last 3 months that we just never really hopped on 29 - > the pod and talked about, even though they happened.

30 - > Um, David, what do you think? 31 - > David - Which had the EO on it because I hit this fun bug where 32 - > if you set your window height at the exact right spot, the, the 33 - > dropdown on the Trump White House site would just bounce up 34 - > and down and up and down and up and down like a Jack Russell 35 - > Terrier. 36 - > Um, but as soon as I started streaming, it adjusted the 37 - > window size and now you can't see the funny bug. 38 - > Anyway, great, great technology, bleeding edge cryptography here.

39 - > Okay, so I figured let's just go through the EO. 40 - > Deirdre - Sure. 41 - > Um, the context for this EO, this executive order from our 42 - > dear leader, President Trump. 43 - > Also, we did not - we do not have a crystal ball.

44 - > We have produced multiple episodes, and by we I mean David 45 - > produced multiple episodes featuring, um, some, you know, 46 - > fictional presidents. 47 - > Yes, the AI Gamer presidents, who, including, including our 48 - > dear leader, a fake version of our - of President Trump, talking 49 - > about post-quantum cryptography and quantum cryptography and 50 - > things like that. 51 - > And we do - do not ask us for KALSHI bets. 52 - > Do not ask us what the spreads should be for anything else.

53 - > We, we were doing satire and unfortunately it became real. 54 - > That seems to be a current risk of doing satire. 55 - > David - However, the official stance of this podcast is that 56 - > insider trading makes markets more efficient. 57 - > Deirdre - Sure, sure, why not?

58 - > Sure. 59 - > Anyway, so the context is in, in March, um, there were some 60 - > results for both improving quantum attacks against 61 - > especially elliptic curve Diffie-Hellman, or elliptic 62 - > curve, sorry, the elliptic curve discrete logarithm problem, um, 63 - > and there were improvements, uh, in, uh, in different ways of 64 - > producing a quantum computer, specifically about building 65 - > quantum computers using neutral atoms. 66 - > And basically, um, we've - we had multiple results that were kind 67 - > of percolating amongst, you know, the, the Whisper network, 68 - > uh, and then got published by Google, uh, predominantly.

69 - > They put - I think they published both things, the, the neutral 70 - > atom stuff and this, uh, this improved attack efficient, more 71 - > efficient attack against, uh, the elliptic curve discrete 72 - > logarithm problem. 73 - > And they specifically were trying to be like, this is, uh, 74 - > we think this will make attacking P-256, um, especially 75 - > EC, the ECDSA signature scheme over P-256, uh, much easier. 76 - > And then you put those things together, you - it's much more 77 - > efficient, uh, to get a, a cryptographically relevant 78 - > quantum computer, and you get a much more efficient attack 79 - > algorithm.

80 - > And basically the projection of where you get a scary quantum 81 - > computer that can run a scary, very fast for what we've had 82 - > before, quantum attack algorithm, especially against 83 - > elliptic curves, brought that reality, projected reality, a 84 - > lot closer. 85 - > And in response to that, Google and Cloudflare announced that 86 - > they were gonna be moving their targeted, their target dates to 87 - > be quantum fully migrated to quantum-resistant cryptography.

88 - > Up to the end of 2029. 89 - > And then I think a lot of people in the industry like really 90 - > stood up and started paying attention because that's moving 91 - > up target dates that people have been working against up by at 92 - > least 5 years. 93 - > It was more 5 or 6 years. 94 - > David - Start of 2029 actually is what Google - .

95 - > Deirdre - Oh, did they say that? 96 - > Oh gosh. 97 - > Um, so, but that happened in March-ish, and we'll have links 98 - > to those in the, in the show notes. 99 - > We - some people have been saying there might be a, another Kyber 100 - > EO, executive order, or a cryptography EO or something 101 - > like that.

102 - > But like, you know, you never know what the fuck's going on, 103 - > uh, in, uh, our dear leader's, uh, house. 104 - > Uh, so this just showed up yesterday, and there's some 105 - > lovely video of, of Trump just talking, learning the phrase 106 - > quantum cryptography for the very first time and uttering it. 107 - > The result is Um, but it's a lot of fun. 108 - > David - And pointing out that no one cares when, when Einstein - 109 - > what year Einstein published some paper about quantum 110 - > something or other, apparently.

111 - > Deirdre - So here it is. 112 - > This is, uh, Securing the Nation Against Advanced Cryptographic 113 - > Attacks. 114 - > And yeah, there's a - there's several things in here actually, 115 - > because I thought it was just about cryptography, and it's not 116 - > just about the, the cryptography, uh, of the, uh, 117 - > the U.S.

government. 118 - > David - Um, so for the sake of the like 8 readers that, um, 119 - > take audio only, what we'll do is we'll read through, I think, 120 - > most of this. 121 - > Deirdre - Okay. 122 - > David - And then pause and talk through it instead of relying on 123 - > everybody to simply read the screen.

124 - > Um, so section 1, the advent of large-scale quantum computers, 125 - > particularly in the hands of adversaries, will pose a 126 - > significant threat to widely used cryptographic security 127 - > systems. 128 - > Ongoing Kyber activity against our nation also presents the 129 - > risk of adversaries collecting United States information now 130 - > and decrypting it once the large-scale quantum computers 131 - > are operational. 132 - > Deirdre - I agree. 133 - > David - So right off the bat, we have a reference to the store 134 - > now, decrypt later threat, which we have talked on and on and on 135 - > about.

136 - > I mean, it's still not clear, like, who this risk acts like in 137 - > the grand scheme of risks. 138 - > Where does this apply to you? 139 - > But this is sort of the main risk of quantum computers now. 140 - > Deirdre - It is the live threat, if that is within your threat 141 - > model.

142 - > David - Um, in light of these threats, the United States must 143 - > take steps to strengthen cryptographic protection, 144 - > protections for the nation's sensitive data, critical 145 - > infrastructure, and digital economy. 146 - > Uh, it is the policy of the United States to safeguard 147 - > national security and maintain technological leadership by 148 - > responsibly and effectively executing the transition of 149 - > federal information systems to the NIST-approved Federal 150 - > Information Processing Standards, FIPS, for 151 - > post-quantum cryptography, PQC, and to assist critical 152 - > infrastructure owners and operators with their 153 - > transitions.

154 - > Um, so, um, unfortunately, unlike AI Gamer Obama, who said 155 - > that he would become a Republican if Doge got rid FIPS. 156 - > Um, well, we still have FIPS. 157 - > Section 2 is just a bunch of definitions, so we'll skip all 158 - > of that. 159 - > Deirdre - Although the one thing that I will not skip is the term 160 - > high-value asset, or HVA, um, which has a specific definition 161 - > and an OMB memo, blah blah blah blah blah.

162 - > And this is - and the, uh, another definition that follows, 163 - > the term national security systems, or NSS. 164 - > So Up until about recently, until this memo actually, the 165 - > U.S. government has been targeting, um, FIPS standards 166 - > that includes post-quantum cryptography, uh, to be rolled 167 - > out and in use by any of these applied systems.

168 - > So this is like any system that the U.S. government is using. 169 - > This includes like the Department of Education to, you 170 - > know, this freaking website that we're looking at.

171 - > I'm pretty sure this has to be served with NIST curves or 172 - > something like that at the moment. 173 - > Um, that's all U.S. federal government, uh, from very boring 174 - > stuff to less boring stuff.

175 - > For national security systems like Department of Defense stuff 176 - > or NSA stuff or top secret SCI, no foreign system stuff like 177 - > that, they have their own suite of more constrained algorithms 178 - > that are basically a subset of the FIS FIPS stuff, and they are 179 - > using PQ only, no hybrid, except for, you know, if you're doing 180 - > IPsec or something like that, you're doing some VPN stuff, 181 - > they trust elliptic curves a little bit. 182 - > Um, they just have a much more constrained set, and they have 183 - > all of the parameter sets pegged to the most tippy-top parameter 184 - > set possible.

185 - > Um, those were all trying to get migrated by the end of 2035, 186 - > although I think there were different targets for different 187 - > systems for CNSA 2.0. 188 - > They were trying to get some stuff migrated earlier. 189 - > David - For CNSA 2.

0, it's really vague, but it was kind of 190 - > already closer to 2031 for most things. 191 - > And there's a statement that's very vague about like new 192 - > systems, new, new procurements should be like CNSA 2.0 193 - > compliant in starting in 2027, which like is just on one hand, 194 - > just like not gonna happen at all. 195 - > On the other hand, like, um, talking with the people that 196 - > wrote that, what it really means is you better not be charging us 197 - > an extra update for it.

198 - > Deirdre - Right. 199 - > David - Uh, okay. 200 - > Deirdre - Yeah. 201 - > David - So, um, they should be doing as much CNSA 2 things as 202 - > are reasonable.

203 - > Deirdre - Yeah. 204 - > David - So for example, like you're not gonna have, uh, um, 205 - > an HTTPS certificate that's CNSA 2 compliant for like a number of 206 - > years. 207 - > Deirdre - Yeah. 208 - > Bye.

209 - > That's publicly trusted. 210 - > Yes. 211 - > David - That's publicly trusted. 212 - > Deirdre - Yeah.

213 - > David - For private PKIs, you can do whatever you want. 214 - > Starting - . 215 - > Deirdre - You can basically do it now, depending - . 216 - > David - In Chrome 150, which releases on June 30th.

217 - > So 7 days from now. 218 - > Deirdre - That's nice. 219 - > David - You'll be - . 220 - > Deirdre - Breaking news.

221 - > Breaking news on the podcast. 222 - > David - I don't know that it's breaking. 223 - > It's like on a public site describing Chrome releases. 224 - > Deirdre - This is a scoops.

225 - > We're doing scoops. 226 - > Scoops. 227 - > Who cares where the information came from? 228 - > It's an exclusive.

229 - > David - It's been discussed on IETF threads by other 230 - > implementers. 231 - > Uh-huh. 232 - > Breaking news. 233 - > Deirdre - One of the only other definitions in the section is 234 - > the Cryptographic Module Validation Program, the CMVP 235 - > program, which is part of getting FIPS certified.

236 - > So if anyone has ever mentioned anything about being FIPS 237 - > certified, This is the program that basically does it. 238 - > It started with hardware and firmware implementations and 239 - > then they just said also we'll, we'll certify software 240 - > implementations of FIPS stuff in a module, in a module boundary. 241 - > And it's, you know, it's a whole thing. 242 - > And unfortunately it leads to kind of, you know, reading the 243 - > tea leaves to try and predict what will be FIPS certifiable or 244 - > not in the program, the lab that does the program.

245 - > And a lot of that is wrong. 246 - > But that's what that is. 247 - > And we'll talk about that later. 248 - > David - There's, there's two types of FIPS certification 249 - > actually.

250 - > There's the, well, there's a bunch of types, but relevant to 251 - > this, there's, there's the CMVP, the Cryptographic Module 252 - > Validation Program, which is the really annoying one to get. 253 - > Deirdre - Yeah. 254 - > David - That a lot of things require. 255 - > And then there is Cryptographic Algorithm Validation, CAVP.

256 - > Deirdre - True. 257 - > David - Yes. 258 - > Which is more straightforward to get. 259 - > 'Cause CAVP is like, did you implement this algorithm 260 - > correctly based on like some test vectors.

261 - > Mm-hmm. 262 - > Deirdre - And CMVP is like, do you meet all of these arbitrary 263 - > other like, um, requirements that make it very difficult to 264 - > test in like, like how do you, like, everything has to be 265 - > within a module boundary and it has to be started up a certain 266 - > way. 267 - > David - And this is why it needs to be able to do a self-test 268 - > with fixed random. 269 - > So you have to build in like a backdoor to your system to prove 270 - > that it operates correctly.

271 - > Basically it's a pain in the ass. 272 - > Deirdre - Yeah. 273 - > David - Um, and then you have to certify it on every, uh, uh, 274 - > well, depending you, in theory, it, the certification only 275 - > applies to specific environments. 276 - > So for example, like Arch Linux 4.

0 on a Chromebook. 277 - > Deirdre - Yeah. 278 - > David - Or like Debian in Google Cloud. 279 - > Deirdre - Yeah.

280 - > David - Um, and in practice what you do is you get some bullshit 281 - > certified for some platform and then you convince your auditor 282 - > that that's what everything is. 283 - > Deirdre - Yep. 284 - > But you still have to like juggle all of those like certs 285 - > in case you, your compliance auditor is like, is your cert 286 - > for this module on this platform is still up to date? 287 - > And you have to keep it alive.

288 - > And that's a lot of juggling and, you know, bookkeeping for 289 - > questionable amounts of additional security. 290 - > David - So, and then NIST will take like 6 to 18 months to 291 - > actually issue your certificate once you pass the testing. 292 - > Deirdre - That too. 293 - > Okay.

294 - > Section 3, Coordinating the PQC Transition. 295 - > The Director of OMB and the National Kyber Director, in 296 - > consultation with the Assistant to the President of National 297 - > Security Affairs and the Administrator of the Office of 298 - > Electronic Government - I didn't know that that was a thing - OMB 299 - > shall lead the strategic coordination oversight of the 300 - > national PQC migration policy and strategy set forth in this 301 - > order, ensuring its alignment with broader cybersecurity 302 - > goals.

303 - > B, the Secretary of Commerce, Blutnick, through the Director 304 - > of NIST and in consultation with the Director of National 305 - > Security Agency, NSA, and the Secretary of Homeland Security. 306 - > Is that still known? 307 - > Do we have an acting secretary? 308 - > David - We - I don't remember who it is, but it's not known 309 - > anymore.

310 - > Deirdre - I think we need - . 311 - > David - I think it's an acting secretary at the moment, but 312 - > they have to be approved. 313 - > Yeah. 314 - > Deirdre - Oh gosh.

315 - > Uh, through the Director of the Cybersecurity Infrastructure 316 - > Security Agency, CISA, and the Department of Redundancy 317 - > Department. 318 - > Shall provide agencies on ongoing basis with comprehensive 319 - > technical guidance on PQC implementation, including best 320 - > practices, implementation, and risk management strategies. 321 - > David - Cool. 322 - > Just what we needed, more guidance from CISA.

323 - > Deirdre - Section 4, Accelerating the PQC Transition. 324 - > Within 30 days of the date of this order, which is yesterday, 325 - > uh, June 22nd, each agency head shall identify its PQC migration 326 - > lead and provide the name and contact details of the PQC 327 - > migration lead to the Director of OMB and the National Kyber 328 - > Director within 90 days. 329 - > Yes. 330 - > David - Yeah.

331 - > So this is like fairly standard stuff for like how a government, 332 - > like the executive branch, tells agencies to do things. 333 - > There's like a similar, um, guidance around like doing 334 - > inventory a while ago that's like, yes, define a point 335 - > person, and then that person has to submit a report to these 336 - > other people that contains these things. 337 - > Blah, blah, blah, blah, blah. 338 - > And then you need to do this other thing by this other time.

339 - > And then that all goes through the point person back to 340 - > whoever, as deemed by the authority stated at the top, 341 - > which in this case is like NSA plus Secretary of Commerce. 342 - > Deirdre - Yep. 343 - > And we explored a lot of that when we talked about the, the 344 - > big Kyber EO that came down just before the end of the Biden 345 - > administration. 346 - > And it's like a lot of similar stuff.

347 - > David - Um, I think the big takeaway in this section is that 348 - > like, we've included the HVAs, the high impact systems and 349 - > national security systems. 350 - > And given this like, timeline for both key establishment at 351 - > the end of 2030 and then digital signatures by the end of 2031, 352 - > which, you know, very nice that these have actually been split 353 - > out because it's much, much, much, much easier to do key 354 - > establishment that it is to do signatures in most cases.

355 - > And you can actually just like, doing key establishment is 356 - > basically just update your OpenSSL. 357 - > Mm-hmm. 358 - > At this point. 359 - > Deirdre - And, or, you know, your Go, you like, you can 360 - > upgrade Go, you can upgrade, uh, I think it's in Java 25 or JDK 361 - > 25, um, that you get it as well.

362 - > Like a lot of the places where you just update, uh, and you are 363 - > serving TLS, for example, Um, you will get your post-quantum 364 - > FIPS interoperable, uh, key agreement and it just works. 365 - > Uh, it's not that easy if you're using, uh, signatures and you 366 - > need to share, uh, a public key or rotate keys or certs or have 367 - > any sorts of roots of trust or anything like that. 368 - > David - Yeah. 369 - > Fundamentally, like independent of any of the like struggles 370 - > with size that we've discussed with PQC in the past, um, like 371 - > you are going to have a new trust hier - like a PKI hierarchy 372 - > for PQCE.

373 - > Deirdre - Yeah. 374 - > David - Which means that like, in some way you're going to have 375 - > to get a certificate from like something vaguely new. 376 - > And like, even if that certificate is done in such a 377 - > way that it looks like this looks like the old stuff to old 378 - > things, like at some point your ACME client's gonna have to 379 - > either be pointed at a new endpoint or have that endpoint 380 - > just like do some sort of, uh, you know, Indiana Jonesing to a 381 - > new hierarchy when you're not looking.

, um, uh, and actually 382 - > have like certificates issued. 383 - > Deirdre - Yeah. 384 - > David - Which is just fundamentally like more work, 385 - > hopefully marginally more work, and hopefully mostly handled, 386 - > um, automatically still, but like not as straightforward as, 387 - > oh, I've just updated my, my SSL/TLS implementation and now 388 - > there's a new cipher suite available and you just use that 389 - > with new things. 390 - > Deirdre - And now - .

391 - > David - Because it involves a long-lived credential instead of 392 - > just an ephemeral credential. 393 - > Deirdre - Yep. 394 - > And not even like long-lived, but just like someone needs to 395 - > trust it in some way. 396 - > It needs to be sort of like, have some sort of like, where 397 - > does this come from?

398 - > Did like, is this real? 399 - > Is this like not expired and things like that? 400 - > Um, and we, and we haven't even gotten an update to, uh, SSH or 401 - > OpenSSH for, uh, keys, the actual keys that do the signing 402 - > for you. 403 - > We have gotten an update, uh, for the key agreement of your 404 - > SSH session in OpenSSH.

405 - > So that's cool. 406 - > But we still aren't sure what SSH, uh, pub keys, PQ pub keys 407 - > are gonna look like yet. 408 - > Um, there's still discussion going on about that. 409 - > Um, yay.

410 - > Um, but one, one of the huge things is like, okay, 2030 for 411 - > key agreement, like that's kind of on par, but the fact that 412 - > they're moving up signatures to be done by the end of 2031 is 413 - > pretty big because we, that is a short runway for things that 414 - > don't have solved solutions ready to go yet. 415 - > And it's like aggressive. 416 - > So that, that was a big thing that caught my eye. 417 - > David - Yeah.

418 - > I mean, Chrome's expecting to be able to accept, um, 419 - > post-quantum, uh, Merkle tree certificate CAs in 2027. 420 - > Um, cool. 421 - > Uh, but the first round of those will not have key strengths 422 - > suitable for CNSA 2. 423 - > Oh, you're right.

424 - > Um, but it will be, yeah, they'll get there eventually, 425 - > but they'll at least be PQC. 426 - > And this actually doesn't say anything about key strength. 427 - > Deirdre - Correct. 428 - > I think it's just, it needs to be FIPS, which means if it 429 - > supports ML-DSA 44, you're good.

430 - > And I think a lot of people will be perfectly well suited to use 431 - > ML-DSA 44. 432 - > David - Um, Yeah, it's really complicated to decide what's, 433 - > um, like a national security system. 434 - > If you talk to most people from like NSA, they'll be like, oh, 435 - > you know, that's like the DOD servers running in like a DOD 436 - > data center or whatever, like on a private DOD network. 437 - > And it's like, yes, that's definitely true.

438 - > Um, but like what, like more and more of the government uses like 439 - > public clouds and SaaS. 440 - > And then you have the question of like, is your cloud console 441 - > considered a national security system? 442 - > Deirdre - Yeah. 443 - > David - You are deploying using that cloud console to deploy, 444 - > uh, you know, a national security system on some cloud.

445 - > Deirdre - Yeah. 446 - > David - Um, and then like now you have like a whole host of 447 - > basically publicly accessible websites that become in scope 448 - > for rules that were written to be for like, uh, basically a DoD 449 - > network. 450 - > Which is where all of this gets complicated. 451 - > Deirdre - It's like, do I really need - does like AWS have to 452 - > serve me, uh, an mldsA87 cert and everything in that chain and 453 - > an MLKEM1024, uh, key exchange just to like, you know, load up 454 - > the console?

455 - > Like, I don't - maybe, I don't know, I don't work for them. 456 - > David - MLKEM1024 is like not that bad in the grand scheme of 457 - > things compared to - whereas like mldsA87 is It's just like, you 458 - > really gonna send me 35 kilobytes of certs? 459 - > Like, come on. 460 - > Deirdre - Yeah.

461 - > Like, when you're sort of thinking about like, well, yes, 462 - > if you are like doing X-keystore crap, like the stuff that 463 - > Snowden leaked, you know, sure. 464 - > I give me the fat, you know, NIST Level 5 certs and like, 465 - > sure, gimme ML-KEM 1024. 466 - > But when you're just like, well, you know, if you're trying to 467 - > twiddle something in the like, defense cloud that is being 468 - > served by, you know, AWS, like, do you need it there too? 469 - > And like, it, the answer might be yes.

470 - > And then you're just like, oh, goddammit. 471 - > Like, to just serve me a website, a regular website, um, 472 - > you need to support this stuff is like, oh boy. 473 - > Okay. 474 - > David - The struggle is if you can't split your domain, like 475 - > split your users by domain, because it's easy to make one 476 - > domain that only uses the high strength stuff and another 477 - > domain that uses like the normal strength stuff.

478 - > To be clear, the normal strength stuff is like strong enough to 479 - > survive like a Dyson sphere built around the sun being used 480 - > to like brute force it. 481 - > But, um, like if you say you're on a search engine, if that 482 - > somehow becomes in scope for a national security system, like 483 - > you probably don't actually want to pay, um, the cost of the 484 - > cryptography for, you know, a few billion users. 485 - > Deirdre - Yeah. 486 - > Um, all right.

487 - > Well, the last rest of the section, advancing to Section 6. 488 - > David - Procurement, um, because I think everything else is more 489 - > just like reporting details on timing and reporting. 490 - > Yeah, Section 6 procurement is where it gets exciting. 491 - > Deirdre - Hold on, hold on, at the end of Section 5, uh, uh, 492 - > um, Homeland Security shall release public guidance 493 - > regarding cryptographic bill of materials and they should enable 494 - > the automated assessment of assets utilized by hardware 495 - > software element.

496 - > I'm like Great, we're just gonna keep doing that. 497 - > We're gonna keep doing C-bombs. 498 - > Okay, sure, we're moving the timelines up super aggressively, 499 - > but first we gotta get that bill of materials. 500 - > Oh, okay, sure, maybe you gotta do that.

501 - > David - I don't remember this for sure, but I feel like some 502 - > of the like S-bomb stuff got revoked by an earlier Trump EO, 503 - > but maybe - . 504 - > Deirdre - Oh, that - yeah, that might have been in the Kyber EO, 505 - > and he wrote like a few months after he came into office, he 506 - > basically had a short one that was like, revoke all that except 507 - > for this, this, this, and this. 508 - > It might - that might have been it. 509 - > But, uh, uh, 6.

510 - > David - So moving on to Section 6, procurement, Section B - 511 - > Within 180 days of the date of this order, the Secretary of 512 - > Commerce, through the Director of NIST, shall, to the extent 513 - > appropriate and consistent with applicable law, revise the 514 - > processes used by the Cryptographic Module Validation 515 - > Program to accelerate validations of cryptographic 516 - > modules. 517 - > Um, now what does it mean to revise these processes? 518 - > I don't know.

519 - > Um, I also, like, I'm gonna be pessimistic about this cuz I 520 - > don't really know how you fix these things. 521 - > I think you just get rid of, like, in my opinion, we 522 - > shouldn't have CMVP at all. 523 - > We should just have CAVP, if that. 524 - > Really, we should just have the FIPS list of algorithms and say 525 - > like, these are the ones that you have to use.

526 - > And like, you don't, you know, we, we expect that like software 527 - > works correctly and like that's part of, you know, the 528 - > purchasing agreement is that like software works correctly. 529 - > Right. 530 - > Mm-hmm. 531 - > If it doesn't, it gets fixed.

532 - > This is kind of how all software works, but somehow it becomes 533 - > like just the cryptographic algorithm part and not the 534 - > network part. 535 - > It's like, oh, well we have to do all this additional testing. 536 - > It's like, yeah, you should, you know, make sure that you're 537 - > procuring software that works for your use case and works 538 - > well. 539 - > But like, do we really need this like additional testing versus 540 - > saying, you know, Yes, this, this software complies with the 541 - > guidelines in the sense of it uses the algorithms that the NSA 542 - > wants to use for the national security systems.

543 - > It like meets the product requirements that are required 544 - > to do the government thing. 545 - > So I don't know. 546 - > I suspect that we will not get rid of CMVP. 547 - > And as a result, I don't really know like how to improve CMVP 548 - > very well.

549 - > Yeah. 550 - > I haven't specifically taken something through CMVP. 551 - > I've, you know, worked with teams that I've had to make 552 - > changes so that it can go through CMVP, but I've not been 553 - > the point person to like, take something to a lab, get it 554 - > tested, submit that to NIST, and so on. 555 - > Deirdre - I bet, I bet we know some people who do have 556 - > opinions, but I am quite - the way this, this is written, I'm a 557 - > little bit worried now because it's like within 180 days, the 558 - > revise the processes, like you have 6 months to revise the 559 - > processes, not come up with a plan, give to go up the chain 560 - > about how you're going to revise the processes.

561 - > Like, no, you're going to change them. 562 - > David - So I'm, I mean, I think 6 months is more than enough 563 - > time to change the processes, but like, you know, government, 564 - > government, it's, it's also tough to do because like in 565 - > practice, like at least for, for, uh, like CNSA too, a bunch 566 - > of this also goes through NIAP where then like NIAP has a 567 - > protection profile that is like in theory above and beyond just 568 - > the CMVP. 569 - > That's like, oh, you know, you have this broader set of 570 - > requirements and NIAP is supposed to check that all of 571 - > that complies with those requirements.

572 - > But in practice, like, NIAP just writes requirements that are 573 - > impossible to comply with and, like, make no sense, and, like, 574 - > combine requirements for clients and servers and then say that 575 - > you have to follow all of them, but in ways that just don't make 576 - > sense. 577 - > And so getting any, like, NIAP protection profile for a 578 - > product, which again is also done through, like, a third 579 - > party, so you, like, take it to a tester, like, Booze Allen 580 - > Hamilton, and then they like, well, that's a thing, and send 581 - > it to NIAP.

582 - > Um, and then just like, nope, nobody, like the testers don't 583 - > understand the product. 584 - > NIAP doesn't understand TLS. 585 - > And then everybody's just trying to get it through. 586 - > But also like you're, it's just a bunch of people like 587 - > bullshitting and lying each other to each other until 588 - > eventually you get the stamp.

589 - > And then what is used in practice is not at all what was 590 - > tested because the requirements were like literally impossible 591 - > to comply with. 592 - > Even though like the requirements from CNSA 2 are 593 - > actually very straightforward. 594 - > Deirdre - Oh gosh. 595 - > I keep forgetting about NIAM and yeah, I don't, I've looked at it 596 - > once and I'm just sort of like, okay, sure.

597 - > David - Yeah. 598 - > Like the NIAM protection profiles don't like correctly 599 - > discern between like must offer something and must negotiate 600 - > something when a client or a server, so it'll be like, you 601 - > TLS client, like you must offer You must use Extended Master 602 - > Secret with TLS 1.2. 603 - > And it's like, well, if you're like a web browser, like, you 604 - > know, what, what happens if like the server, like we offer it in 605 - > Chrome, but like not every server speaks that.

606 - > I think most do, but like, are we just supposed to reject it? 607 - > And then they're like, oh, well you must use, you know, AES-256, 608 - > cuz that's what's in CNSA2. 609 - > It's like, well, here's the incantation you can put in to 610 - > make it so you get AES-256 with Google. 611 - > But like, if we just turn off AES-256 in like Chrome, for 612 - > example, then you just can't load most The internet.

613 - > Deirdre - Yep. 614 - > David - Because it's all using AES-128. 615 - > Deirdre - Yep. 616 - > Which is fine, by the way.

617 - > Uh, I don't know. 618 - > There was a, a lovely blog post that went around recently 619 - > because people were like, oh, so to be post-quantum, we need to 620 - > go to AES-256. 621 - > And it's like, no, actually you don't. 622 - > And I guess people don't, don't know this.

623 - > Basically Grover's is not efficient against, uh, against 624 - > thing, especially things like AES, but even hash functions. 625 - > AES-128 is, is fine. 626 - > You do not need to upgrade. 627 - > The only reason you need to upgrade is if you need to be 628 - > compliant with CNSA 2.

0, and that's just because they, they 629 - > put all the parameter sets to 11, not because they actually 630 - > are protecting against Grover's attack. 631 - > Anyway, sidebar. 632 - > David - Anyway, so my feedback is to just simply get rid of 633 - > CMVP entirely. 634 - > Deirdre - Who knows?

635 - > Like, we've already had Doge come, come through our 636 - > government. 637 - > You - who knows? 638 - > Maybe that will actually happen. 639 - > It'd be very, very interesting.

640 - > Uh, anything else? 641 - > Oh, uh, contractor vulnerability disclosure programs. 642 - > Cool. 643 - > That VDPs incorporate reports of cryptographic vulnerabilities 644 - > including testing for lack of encryption, the use of non-FIPS 645 - > approved algorithms.

646 - > Cool, that's neat. 647 - > What's FAR? 648 - > David - It was probably the Federal Acquisition Regulatory 649 - > Council. 650 - > Deirdre - Oh, okay.

651 - > David - Uh, I think this is probably going to be a net 652 - > negative. 653 - > Um, well, I don't know, like, what do they mean by, I guess 654 - > it's probably in the definitions up above, but like contractor, 655 - > if contractor means like labs, like, I hope they don't, aren't 656 - > like having the labs check for vulnerabilities. 657 - > If they're just saying like people that we're buying 658 - > cryptography from should have a vulnerability disclosure 659 - > program, then like, sure.

660 - > Deirdre - Yeah, I guess that sounds good. 661 - > David - Everyone should have a vulnerability disclosure policy. 662 - > Most people should not have a bug bounty. 663 - > Yeah, that is my stance.

664 - > Uh, and, uh, I think, and then Section 7 is the none of this is 665 - > illegal section. 666 - > Deirdre - Hopefully the costs for the public issue of the 667 - > source shall be borne by the Department of Commerce. 668 - > Of course, poor, poor them. 669 - > Poor Litnik.

670 - > Cool. 671 - > Yeah, so that's, uh, that's it. 672 - > That's, uh, that's the EO. 673 - > It's very exciting.

674 - > David - Yeah. 675 - > So I think takeaways for most people should just be to update 676 - > your TLS server software or, um, which if you're like using a VM, 677 - > you can just like do now and you should be getting TLS Quantum 678 - > Key Exchange out of the box, probably hybrid, um, 25519 with 679 - > MLKEM768. 680 - > That's enabled by default in, yep. 681 - > I believe like OpenSSL 3.

5 and newer and boringSSL and all the 682 - > other SSLs. 683 - > Deirdre - Yep. 684 - > David - If you're using a, like, TLS load balancer from a cloud, 685 - > it probably supports all of those now as well. 686 - > And if not, it will very soon.

687 - > And like, again, the step there will just be to like, roll your 688 - > config to the new version, enable it, or just let it update 689 - > itself depending on, you know, how you're configured. 690 - > And all of that should be pretty straightforward. 691 - > And then for publicly accessible websites, like, you're just 692 - > gonna need to wait until the certificates are available. 693 - > Deirdre - Yeah.

694 - > David - And then you have just a certificate management problem, 695 - > you know? 696 - > Deirdre - Yep. 697 - > Uh, and you know, Modulo Chrome trusting, Modulo Chrome having 698 - > a, a trust store beyond Merkle tree certs. 699 - > Um, I'm pretty sure that a lot of publicly trusted CAs, um, 700 - > either already have ML-DSA support, um, like operational, 701 - > they just don't have an ML-DSA root, uh, in other root stores, 702 - > trust stores out in the world.

703 - > It's kind of a little bit of a chicken and an egg issue with 704 - > them. 705 - > Um, and this is regular schmegular ML-DSA certificates, 706 - > not the fancy new, new gen Merkle tree certs. 707 - > David - Um, no, those are like not gonna end up being an option 708 - > for publicly trusted sites. 709 - > Like at this point, like all but like a lot of the browsers have 710 - > signaled in various forums, not to speak on behalf of any of 711 - > them.

712 - > Um, yeah. 713 - > That like the, because of the need for transparency for public 714 - > PKIs, meaning like the full set of certificates is publicly 715 - > disclosed. 716 - > Deirdre - Yeah. 717 - > David - Um, uh, the, if there was a, a non-Merkle tree 718 - > certificate, which we haven't really defined, but we've been 719 - > talking around, but if there was an old style ButML DSA, like 720 - > root store, that would require old style certificate 721 - > transparency and that system would fall over, um, in a 722 - > post-quantum world for a number of reasons.

723 - > Deirdre - And so in a post-quantum world, or you could 724 - > just do something, a terrible bridge where you have your 725 - > ML-DSA cert, but you have, uh, ECDSA, uh, transparency 726 - > statements. 727 - > David - That would still fall over publicly in a sense, 728 - > because like the full certificate contents are logged. 729 - > And so if you like drastically increase the size of the 730 - > certificate, the set of people that are currently basically 731 - > running CT logs out of the goodness of their heart,, would 732 - > probably not be super happy about, you know, um, these 733 - > things that are just like basically a net negative to run 734 - > suddenly, like doubling, quadrupling, 10x-ing in storage 735 - > costs.

736 - > Deirdre - Yeah. 737 - > I, I was thinking of literally all the SIGs and, and key public 738 - > keys that you're downloading. 739 - > Yeah. 740 - > Those would be smaller if you did a little bit of mix and 741 - > match and relied on and just kind of, you know, crossed your 742 - > fingers that the transparency benefits, uh, be given by ECDSA 743 - > would give you a little bit longer.

744 - > But you're right, for the log operators, there still gets 745 - > They'll still get fucked. 746 - > David - Yeah, but there are definitely a number of companies 747 - > that offer like private PKI ML-DSA products right now. 748 - > Yeah, I think I've done it for a while. 749 - > There are many HSMs that support it, although none of them have a 750 - > CMVP yet, um, because NIST is just behind on, uh, on approving 751 - > them.

752 - > Yes, they have CAVPs but not CMVPs. 753 - > Deirdre - Was it the first, uh, validated implementation of 754 - > ML-DSA was only like this year, 2026 or something like that, 755 - > that finally got through. 756 - > And it was in the pipeline for like 18 months or something like 757 - > that. 758 - > David - It took so long.

759 - > The final standard was released in like July of 2024. 760 - > Deirdre - Yeah, I think that's correct. 761 - > Yeah, or August, I forget. 762 - > David - Yeah, July or August.

763 - > Deirdre - Yeah, and it took that long. 764 - > They, they had it ready to go and they, they shoved it in 765 - > there and it took that long to get validated or whatever. 766 - > David - Yeah, it was an extremely minor change in the 767 - > final standard from the last draft standard. 768 - > Deirdre - And so yeah, Yep.

769 - > It just takes so long. 770 - > So yeah, we'll see if, uh, they literally just chuck CMVP out 771 - > the window. 772 - > That's a way to update procedures or what they do, 773 - > because this may be possibly the best opportunity to overhaul 774 - > that program since it's come into existence, I think. 775 - > But, uh, we'll see.

776 - > We'll see how that goes. 777 - > David - Earlier in the year, um, I saw this talk. 778 - > And it was, it was kind of like the scene in The Big Short where 779 - > Steve Carell's character comes and meets the guy in Vegas who's 780 - > like on the other side of the trade, like selling stuff. 781 - > Deirdre - And they're eating sushi.

782 - > David - Yeah. 783 - > And they're eating sushi. 784 - > And Steve Carell's getting angrier and angrier at this guy 785 - > who's basically just like taking money off the top of the trade 786 - > and like fucking over his customers. 787 - > But you're just like, oh, like this person like actually 788 - > exists.

789 - > And for me earlier this year, I was at this talk and there was 790 - > someone who was like, just giving this talk about how 791 - > important it is that when you're in a sys - system where like you 792 - > need FIPS cryptography, you make sure that you're like, actually 793 - > using all of the FIPS stuff everywhere, because otherwise 794 - > who knows what kind of cryptography you're getting. 795 - > And like, it's not just enough to like get OpenSSL that lists 796 - > FIPS, like other stuff might be used.

797 - > And the only way to know that you have like high assurance 798 - > cryptography is to like make sure you have the thing that 799 - > actually got like FIPS verified. 800 - > And I was like, oh shit, man. 801 - > Like, I got bad news for you about like most products you've 802 - > ever used, right? 803 - > Like, not, not that like everyone's out here doing fraud, 804 - > but just like in practice, it's not possible to get these 805 - > validations, um, at a rate or reflective of every environment 806 - > in the way that like all of this stuff is actually used.

807 - > And that's, that's why I think like CAVP makes much more sense 808 - > because it's just like, let's make sure we're using the right 809 - > algorithms. 810 - > But like the chance of you actually being able to verify to 811 - > the letter of the law of how you're supposed to verify a 812 - > cryptographic module is basically zero when it comes to 813 - > actually distributing software. 814 - > Deirdre - And the argument of like, and even if you are able 815 - > to do it, like the value to security, uh, is very debatable, 816 - > um, about that procedure for actually like validation, um, is 817 - > debatable.

818 - > David - And there's a they're supposed to have like a 819 - > self-test of them as well, which requires like a hash of itself 820 - > in it, basically. 821 - > Yeah. 822 - > Yeah. 823 - > Yeah.

824 - > Um, which then gets submitted in the cert. 825 - > And so like your, your, your validation only applies to like 826 - > the specific, like hash of your thing, technically. 827 - > Um, but that is a problem of like, well, if it takes 18 828 - > fucking months to like get one of these things verified, like 829 - > you're gonna make changes underneath. 830 - > Deirdre - Yeah.

831 - > Um, and so it's also, uh, you can't, you can't change like a 832 - > doc comment. 833 - > You can't like, there's, well, depending on how you, in theory. 834 - > David - Yeah. 835 - > Deirdre - Well, that, that's not technically basically, you know, 836 - > FIPS approved.

837 - > David - Now, most of the downstream requirements that 838 - > like you don't need specifically to have that FIPS thing. 839 - > So like FedRAMP, for example, now lets you update, like be 840 - > like, as long as you are regularly getting your 841 - > cryptographic module validated whenever you make a large 842 - > change, then it's fine for you to update it in between because 843 - > like, you know, bug fixes are good and new features or 844 - > whatever are good. 845 - > But like at some point, like, like what are we doing here?

846 - > Deirdre - Yeah, I got, I totally forgot about FedRAMP. 847 - > So this, this is going to impact FedRAMP, but it's not 848 - > specifically named in here. 849 - > David - So like, I guess there's nothing specific, but yeah, 850 - > well, that's just going to be downstream of like FedRAMP says 851 - > you need things that are like FIPS 140-3 validated. 852 - > And then that now involves covering these other things.

853 - > So I don't think FedRAMP itself really needs to change. 854 - > Deirdre - Yeah. 855 - > David - Like, I don't know, maybe they make a, post-quantum 856 - > secure statement at some point, but it'll kind of fall out of 857 - > the FIPS validation. 858 - > Oh, personally, I like it better when there aren't a bunch of 859 - > executive orders around, like my non-government job.

860 - > Deirdre - Yeah. 861 - > David - Yeah. 862 - > I don't know about your experience. 863 - > Deirdre - Yeah.

864 - > I don't, I, part of me is like, this could be good. 865 - > And part of me is just like, what, what are we doing? 866 - > I mean, I - yeah, I don't know. 867 - > We'll see.

868 - > Especially because it's like high-impact systems, which, for 869 - > example, those might be things like the IRS's computers and the 870 - > State Department systems that let it issue passports and 871 - > things like that, and like help maintain consular security, 872 - > stuff like that. 873 - > Um, so important stuff, but definitely there's going to be 874 - > whole - a whole bunch of parts of the federal government that may 875 - > not be PQ, um, even if everything in this EO is like, 876 - > um, fulfilled all the way down to the, down to the letter.

877 - > Um, we'll see, we'll see how it goes. 878 - > I don't hate it. 879 - > I'm kind of amazed it does not say quantum cryptography in 880 - > there. 881 - > David - Also, I heard someone, I heard someone references the 882 - > quantum key distribution or anything like that, quantum 883 - > randomness.

884 - > Deirdre - Thank God, like The Little Mercies, because there's 885 - > been chatter, more chatter about that, I think because there's 886 - > funding coming out of like the EU or something for EU-based 887 - > businesses. 888 - > And it's just like, no, no, no, we don't want none of that. 889 - > I was having to - you - . 890 - > David - Is a great place to take vacation.

891 - > Deirdre - There's nothing about - . 892 - > David - This is a great place to host a World Cup, apparently. 893 - > Deirdre - Um, Boston is a great place to host any Scotland 894 - > matches. 895 - > Um, I am sad that I was not spending as much time in Boston 896 - > while, you know, every Scots person, Scottish person, um, 897 - > that could ambulate made it to my hometown for a week.

898 - > But, uh, I want them to come back. 899 - > Now the English are over there and everyone's like, boo, we 900 - > want the Scottish back. 901 - > David - English historically haven't had a great time in 902 - > Boston. 903 - > Deirdre - No, it was - yeah.

904 - > Um, I swear someone said that there was a mention of 905 - > investment in quantum computing, but it's definitely not in this 906 - > EO. 907 - > Did I miss another one? 908 - > Or maybe, maybe Trump was saying the wrong things out of his 909 - > mouth again. 910 - > David - So, um, there is about that as well.

911 - > Deirdre - Hold on, I'm pasting it in here. 912 - > Yes, there was another one, another presidential action. 913 - > Um, gosh, ushering in - I'm sharing - ushering in the next 914 - > frontier of quantum innovation. 915 - > David - How long?

916 - > Deirdre - It's not this one. 917 - > This is on - it's not that long either. 918 - > David - No, so there's a second EO. 919 - > Deirdre - Yeah.

920 - > David - Um, oh God, two EOs in one show. 921 - > I think that, that might be a bit much. 922 - > Deirdre - I'm scanning, scanning, scanning. 923 - > Updating quantum strategy.

924 - > Harnessing quantum computing for science. 925 - > Secretary of War and a bunch of other secretaries shall ensure 926 - > that capabilities, manufacturing infrastructure, and expertise 927 - > are made available to support this QC effort. 928 - > David - Exploration. 929 - > Deirdre - Coordinate with the NASA administrator, the director 930 - > of NSA.

931 - > David - Uh, to attempt to like keep track of the relative 932 - > capabilities of different quantum computing systems in 933 - > order to accurately assess the performance. 934 - > That's interesting because it's really hard to assess relative 935 - > capabilities of them cuz they all work different ways and 936 - > basically none of them do anything useful until one day. 937 - > One of them will do many things useful. 938 - > Deirdre - All of a sudden they do a whole bunch of - a whole 939 - > bunch of useful, uh, Secretary of Energy shall, uh, basically 940 - > price out and scope out delivery for one QC.

941 - > Cool. 942 - > Um, develop a plan to encourage contributions to the effort from 943 - > commercial quantum computing companies. 944 - > Secretary of War, national security applications of quantum 945 - > computing, establish a center for such a purpose. 946 - > David - Thought, thought, thought.

947 - > I previously heard of NSA saying that they like to be 948 - > approximately 7 years ahead in terms of the, like, general 949 - > public in terms of cryptanalysis, which I know some 950 - > people have taken to, well, that means they clearly have a 951 - > quantum computer now. 952 - > I think that's a load of crap. 953 - > There's like no way. 954 - > Yeah, that anyone has a quantum computer now.

955 - > Um, like, we would - there would be downstream effects of that. 956 - > Deirdre - Yes, it's, it's sort of like when, um, all the 957 - > nuclear scientists just stopped publishing for a while when, 958 - > like, most of them were either working at the - at Los Alamos, 959 - > uh, or, you know, some of them were working in Germany. 960 - > Um, it's just like the absence, uh, is a signal, and we we don't 961 - > have anything close to that, or, or the inverse of sort of like, 962 - > um, we would see evidence, uh, even, even if it's not direct 963 - > evidence.

964 - > David - We would also need like technological advances that 965 - > would probably see like effects of an industry that like don't 966 - > seem to have happened, like, you know, improvements in 967 - > superconducting and things like that. 968 - > Deirdre - Yep. 969 - > David - Um, but speaking of building quantum computers, do 970 - > you want - should we talk about ECDSA.fail?

971 - > Deirdre - Oh my goodness. 972 - > David - I love a good.fail domain. 973 - > Deirdre - Yeah.

974 - > Um, yeah, that's good before, uh, we, yeah, you get the gist 975 - > of the rest of the CEO. 976 - > They're actually kind of like trying to tell people to do 977 - > stuff regarding quantum computing, which is pretty cool. 978 - > Um, we'll see where that goes. 979 - > Um, so we, we discussed how, um, there were published, uh, 980 - > improvements, uh, to attacking Elliptic curve discrete 981 - > logarithm problem, uh, with quantum attack algorithms, which 982 - > are basically like iterations around Shor's algorithm or 983 - > improving parts of some of these like broad class attack 984 - > algorithms.

985 - > And specifically, the Google, uh, Google folks published a 986 - > paper that claimed they had a quantum attack circuit for one 987 - > of the, uh, slowest parts of, uh, running Shor's algorithm to 988 - > attack, uh, this discrete - elliptic curve discrete 989 - > logarithm problem, which I think it was literally like the 990 - > elliptic curve point operations itself, which is like funny 991 - > because that's the classical part. 992 - > And it turns out running it on the quantum computer is actually 993 - > kind of like the slow bottleneck of using Shor's algorithm to 994 - > attack the thing, to find that like the periodicity of your, 995 - > you know, elliptic curve group or whatever it may be.

996 - > Um, so they claim - they published a paper that claimed 997 - > that they were able to do this in, you know, n million Toffoli - 998 - > I think it was like a million and change Toffoli, um, gates, 999 - > which is like a way to measure the circuit depth of the, uh, 1000 - > quantum circuit that you're actually going to use. 1001 - > It's kind of like measuring the number of multiplies or divides 1002 - > or whatever you might have in a certain attack algorithm or 1003 - > another, another algorithm on a classical computer.

1004 - > It's just a way to kind of like measure. 1005 - > And then, um, I think they claimed that they needed like, 1006 - > you know, a 1024, some, some small number of logical qubits 1007 - > or whatever. 1008 - > Not - they didn't, they didn't require like 10 million or a 1009 - > million logical qubits to run this. 1010 - > It was some, some small number or something like that.

1011 - > Um, but they did not publish the circuit. 1012 - > They published a zero-knowledge proof of the circuit statement 1013 - > and they published the proof and they published their claims 1014 - > about the size and the speed that this should take to attack, 1015 - > you know, elliptic curve, uh, sorry, uh, elliptic curve DSA, 1016 - > uh, algorithm, uh, based on P-256 curve. 1017 - > Yeah. 1018 - > Um, yeah.

1019 - > David - The Google publication was 2.1 million gates and 1,425 1020 - > qubits. 1021 - > Deirdre - Nice. 1022 - > I was pretty close.

1023 - > David - In March, late March. 1024 - > Deirdre - 2024. 1025 - > David - Um, excuse me, 2026. 1026 - > Deirdre - And this, this was kind of interesting because two 1027 - > people have been following quantum attack algorithms and, 1028 - > and sort of like, this is part of a, um, lineage of like, 1029 - > here's our improvement and here's like our tweak on how, 1030 - > how many resources, how fast can we get some of these attack 1031 - > algorithms to be.

1032 - > Even though we don't have a quantum computer yet to really, 1033 - > you know, test them. 1034 - > Like, this is - I'm going to write it up or whatever. 1035 - > But this was new in that the authors claimed that their 1036 - > results were too dangerous to publish. 1037 - > So that is why they published a zero-knowledge proof of them, 1038 - > and they directly compared it to, um, uh, to - I think it was 1039 - > literally like the Manhattan Project or whatever.

1040 - > Like, they didn't want to, like, publish the ingredient, like, 1041 - > the specific ingredients of how to make an atomic bomb or 1042 - > something like that. 1043 - > And it's just like, uh, like, I don't know, like, we can't run 1044 - > it yet, can we? 1045 - > Like, it's gonna be several years until we can - until we can 1046 - > run it. 1047 - > So like, all right, whatever.

1048 - > But that's not the funny part. 1049 - > That, that was an interesting kind of - it, it caused a little 1050 - > bit of a debate of like, oh my goodness, if we make any more 1051 - > improvements of attack algorithms, do we have to - is 1052 - > this the way we disclose them now? 1053 - > Is this a new form of responsible disclosure? 1054 - > Like, blah, blah, blah, blah.

1055 - > That didn't matter. 1056 - > People saw this result and they're like, ooh, you're trying 1057 - > to attack the, the signing algorithm of Bitcoin. 1058 - > Hmm, let's try if we can like really run this down. 1059 - > And someone set up ECDSA.

fail, and they were basically - they 1060 - > basically started crowdsourcing, um, attempts to improve this, 1061 - > uh, theoretical construction, uh, you know, this construction 1062 - > published by Google, but without publishing the actual circuit, 1063 - > and tried to beat their claimed, um, uh, costs and speed and 1064 - > resource requirements. 1065 - > And people were using ChatGPT and Claude and Opus and all this 1066 - > stuff to try and incrementally try to improve and improve and 1067 - > improve and improve and submit it.

1068 - > And the zero-knowledge proof turned out to be a great way to 1069 - > like cross-test your results or something like that. 1070 - > I think that's what it was. 1071 - > One, there was also a bug in it. 1072 - > The Trail of Bits people were able to find that, like, you, 1073 - > they were able to get it to validate things that it was not 1074 - > supposed to validate.

1075 - > Was that it? 1076 - > And that, that's what they were using to, to validate other 1077 - > things. 1078 - > I don't remember. 1079 - > David - Um, no, they're, they're using the, just the same, like, 1080 - > sim circuit simulators that, um, were in the Google paper, but 1081 - > then like Uh, the Google paper didn't include like the actual 1082 - > circuit that just had like a proof about the circuit.

1083 - > Yeah. 1084 - > But like the circuit simulator is basically just code. 1085 - > And so you can have a coding agent, you know? 1086 - > Deirdre - Yeah.

1087 - > Okay. 1088 - > That was, that was it. 1089 - > David - Optimize this circuit, make no mistakes. 1090 - > Deirdre - Yep.

1091 - > And it took 3 days. 1092 - > Let me see if I can find, if I can cross-reference. 1093 - > I think this was the 30th and the first result that beat it 1094 - > was June 2nd. 1095 - > So I think it was 3-ish days before the entire point of this 1096 - > thing is too dangerous to publish, so we're just going to 1097 - > publish a zero-knowledge proof on it, which is completely blown 1098 - > out of the water by people crowdsourcing competing results 1099 - > on the internet.

1100 - > And they're still going, and they've been able to drive it 1101 - > down. 1102 - > It's like not quite twice as fast or twice as efficient in 1103 - > terms of gates as the Google, uh, results. 1104 - > But it's very - it - people have been able to get a very good, 1105 - > um, much better, like 45% less gates and like, yeah, uh, 25% 1106 - > less - . 1107 - > David - Or excuse me, 25% or 30% less gates and like 45% less 1108 - > qubits.

1109 - > Yeah. 1110 - > Deirdre - And, uh, uh, it's, it's a lot of fun. 1111 - > It, it's a, it's a lot of fun. 1112 - > David - So, um, power of telling people, it's, it's telling 1113 - > people that like something can be done and then trying to 1114 - > figure it out.

1115 - > Like, uh, when, when DROWN happened, like the way we got 1116 - > involved at Michigan was we heard there was a rumor that 1117 - > like there was something wrong with SSLv2. 1118 - > And so because we heard that, myself and my advisor like 1119 - > opened up the OpenSSL source code and just looked at the 1120 - > SSLv2 handshake for a while, like on a projector screen. 1121 - > And then we were like, ah, that pointer's wrong after a while. 1122 - > And that was like our contribution.

1123 - > That turned out a bunch of people much smarter than us had 1124 - > come up with like a cryptographic vulnerability. 1125 - > And we were just like, no, that pointer's wrong. 1126 - > And those two combined are what like led to the fan - the 1127 - > fanciest version of Ground. 1128 - > But like the only reason that we thought to look there was 1129 - > someone said, well, someone said, the rumor was there was 1130 - > something there.

1131 - > Same with this. 1132 - > Once you know something can be beaten, well, let's go, let's go 1133 - > try it. 1134 - > Deirdre - Yeah. 1135 - > David - Or just the same as like, uh, Nicholas Carlini, you 1136 - > know, saying the vulnerability is probably in this function.

1137 - > Yeah. 1138 - > Go, go find it. 1139 - > No, it's in this function. 1140 - > Like, once you know the vulnerability is in the 1141 - > function, then you can find it.

1142 - > But yeah, otherwise you'd never find it. 1143 - > Deirdre - Gosh, I love it. 1144 - > Um, I'm amused. 1145 - > I kind of hope that, like, this is, this is a great way to get 1146 - > improvements.

1147 - > Like, their attack algorithms, like, okay, but like, that's 1148 - > how, that's how defenses get better because the attacks get 1149 - > better and then we get better at defending. 1150 - > So that means you migrate off of ECDSA. 1151 - > David - Spoiler alert, but, um, or, you know, a little culture 1152 - > clash between the physicists and the software security people. 1153 - > Deirdre - Yes.

1154 - > Um, that, that was a thing that may not be obvious from just 1155 - > looking at the papers and the blog posts was that those 1156 - > results for that attack algorithm actually came out of 1157 - > like a different part of Google than say cryptography and 1158 - > security. 1159 - > And only the cryptography and security people found out about 1160 - > this thing that was coming, like very last minute, as far as I 1161 - > know. 1162 - > And like, they're just like, what?

1163 - > Like, wait, what? 1164 - > Like, what do you - and then it was a whole negotiation of 1165 - > trying to get it out of Google. 1166 - > There's no NSA or US government meddling, being like, no, no, 1167 - > you can't publish this, it's too dangerous. 1168 - > Like, none of that, as far as - that's everything I've learned.

1169 - > It's just like people, these physicists spooked themselves 1170 - > And instead of working with security people and cryptography 1171 - > people who are used to publishing, you know, things 1172 - > that affect security postures out in the world, they just 1173 - > spooked themselves. 1174 - > They said, I don't know if we should publish this. 1175 - > Oh, let's go get a zero-knowledge proof to slap on 1176 - > it. 1177 - > That, that'll let us get it out the door.

1178 - > David - So, um, yeah, I mean, Scott Aaronson even had a blog 1179 - > post kind of about this where he was like, you know, maybe like 1180 - > we shouldn't publish some of this stuff cuz we're close. 1181 - > And then he was like, Nadia Henninger talked me out of it on 1182 - > Facebook. 1183 - > And I thought that was interesting. 1184 - > Because I didn't realize Nadia was still on Facebook.

1185 - > Deirdre - Oh my goodness. 1186 - > I, I didn't - . 1187 - > David - But you know, thank you to Nadia for keeping your 1188 - > Facebook so that you can like tell Scott Aaronson when he's 1189 - > wrong. 1190 - > Yes.

1191 - > Deirdre - Uh, thank you very much because I'm not going on 1192 - > Facebook. 1193 - > And what I wonder - oh, I wonder, I think his blog posts are, or 1194 - > the, the comment section are, are cross-synchronized, uh, 1195 - > with, with Facebook. 1196 - > That might be why. 1197 - > I don't know.

1198 - > David - I don't know. 1199 - > Deirdre - Well, I haven't logged into Facebook in many years. 1200 - > David - Thank you to Nadia Henninger for discussing this 1201 - > with Scott Aaronson. 1202 - > Deirdre - Yeah.

1203 - > But yeah, easy to say it's fun. 1204 - > Uh, go, go fork the, the circuit simulator and see if you can do 1205 - > better with your favorite, uh, on your own or with your 1206 - > favorite, uh, large language model or something, because 1207 - > apparently they're good at it. 1208 - > Seems fun. 1209 - > Cool.

1210 - > Did we miss anything? 1211 - > David - I think that's enough, uh, executive orders for 10 PM 1212 - > on a Tuesday. 1213 - > Deirdre - Yeah, I don't want to discover any new, uh, Trump EOs 1214 - > that involve quantum or cryptography or security. 1215 - > Um, cool.

1216 - > Yay, emergency pod done. 1217 - > Security cryptography whatever is a side project from Deirdre 1218 - > Connolly, Thomas Ptacek, and David Adrian. 1219 - > Our editor is Nettie Smith. 1220 - > You can't - oh my God, I need - .

1221 - > David - Fuck, is our editor Nettie Smith? 1222 - > Like, we keep editing ours. 1223 - > Deirdre - Uh, yeah, I need the fucking - . 1224 - > David - I need to find this online.

1225 - > Yes, @tqbf, um, @durumcrustulum or @dadrian. 1226 - > Yes, that's right, I ponied up the money to change my handle. 1227 - > Deirdre - Oh, it's not David C. 1228 - > Adrian no more.

1229 - > David - All right, don't forget to like us, rate us, smash that 1230 - > like and subscribe, follow us on whatever preferred format you 1231 - > get your podcasts or video podcasts. 1232 - > Deirdre - Yes. 1233 - > David - And thank you for listening. 1234 - > Deirdre - And also you can get merch at merch dot 1235 - > securitycryptographywhatever dot com.

1236 - > Thank you for listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Episode 128: Post Quantum CryptographyThe Azure Security Podcast · on Post-Quantum Cryptography (PQC)87 / 100
  • What CISOs Must Do Now About Quantum? | Interview with Andrew GaultSecure & Simple · on Post-Quantum Cryptography (PQC)83 / 100
  • Building a browser-based sandbox for quantum-safe migrationShielded · on Post-Quantum Cryptography (PQC)75 / 100
  • Cyber News: Iranian Hacker, Quantum Ransomware and Rogue AIThe Audit · on Post-Quantum Cryptography (PQC)75 / 100
  • Ep1171: Fernando Dominguez Pinuaga: Quantum Meets AI20MinuteLeaders · on Post-Quantum Cryptography (PQC)70 / 100
  • Cybersecurity Awesomeness Podcast - Episode 163Cybersecurity Awesomeness Podcast · on Post-Quantum Cryptography (PQC)60 / 100

More from Security Cryptography Whatever

All episodes →
  • Facing the Vulnpocalypse with lcamtuf95 / 100
  • AI Finds Vulns You Can't With Nicholas Carlini100 / 100
  • Standardizing Pure PQC27 / 100
  • Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor100 / 100
  • The IACR Can't Decrypt with Matt Bernhard90 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Security Cryptography Whatever episodes →