Live data from Hacker News

France's Anssi Will Block PQC-Free Products from Certification Starting 2027

postquantum.com

21–30 of 66 posts

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#21

Earlier quoted context omitted.

Agreed. This looks from the outside like someone read a report, got unnecessarily spooked, and now the rest of the herd is following along. But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it. However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I do…

Would anyone downvoting care to explain? I'm genuinely interested in seeing anything that suggests there's either some secret breakthrough (completely plausible, but there's no evidence that I've seen hint of) making quantum computers actually useful, or an argument that they'll be usable by (say) 2050? Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just wh…

I work as a security architect in a major European company. We're currently demanding a full cryptographic inventory of every new product purchased or service built in-house and will start demanding PQC in 2028.

Not because we expect a workable quantum computer by 2030 (current estimates are around 2035-2040), but because stuff survives for decades in large enterprises (especially if it touches hardware in any way. Think OT, think controllers for all kinds of machines).

Now that PQC is standardized, there's no gain not to demand it (it's basically a demand to use a current openSSL/libreSSL/$library), but not demanding it now will cause a major headache once/if quantum computers work.

TLS connection speed matter only for a very tiny niche of applications; those will choose according to their needs. For the general case, it just doesn't matter.

If your threat model includes store-now-decrypt-later, you should have been demanding PQC for years.

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#22
post #19

Earlier quoted context omitted.

You prepare for the 9.0 earthquake that can happen once in 500 years because it is a 9.0 earthquake and if you haven't prepared your society is dead, not because you think it will most likely happen in your lifetime.

Most countries don't prepare for earthquakes. Only countries that get earthquakes do. YAGNI - https://en.wikipedia.org/wiki/You_aren%27t_gonna_need_it

The countries that do prepare for catastrophic megaquakes do so despite the fact that the incidence frequency is quite low, because the consequence magnitude is so great.

Even regions with few quakes may have a history of large quakes. The New Madrid region (southern Illinois, southeastern Missouri, southwestern Kentucky, northwestern Tennessee, northeastern Arkansas) doesn't experience especially frequent temblors, but when they do occur, they're doozies:

https://en.wikipedia.org/wiki/1811%E2%80%931812_New_Madrid_e...>

The potential risks of PQC are large enough that preemptive countermeasures seem prudent.

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#23

Earlier quoted context omitted.

Agreed. This looks from the outside like someone read a report, got unnecessarily spooked, and now the rest of the herd is following along. But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it. However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I do…

Would anyone downvoting care to explain? I'm genuinely interested in seeing anything that suggests there's either some secret breakthrough (completely plausible, but there's no evidence that I've seen hint of) making quantum computers actually useful, or an argument that they'll be usable by (say) 2050? Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just wh…

There has been a lot of new stuff over the last few years.

For instance, breaking RSA or ECDSA is requiring much fewer logical qubits than previously thought, and thus fewer physical qubits as well. Progress in error codes, quantum processing etc. made it that in 2019, it was estimated we needed ~20 million noisy qubits to factor RSA 2048. In 2025, we know we need fewer than 1 million. [0]. Some other papers even claim the need of 1000 physical qubits but they rely on a very exotic architecture so I would not consider them feasible.

Progress on the hardware is also continuing, see [1]. Researchers managed to have functional-ish error correction for the first time last year, and experts in the topic are confident that a cryptographically relevant computer will appear in around 15 years.

I personally am less optimistic than the experts (admittedly I am not an expert either), but there is enough activity to get worried for critical infrastructure.

Regarding the factoring issue, as you point out factoring 15 and factoring 21 are two very different tasks. The first one can be used to show that your quantum computer is indeed doing quantum computation; the second will prove that you have a functional error correcting code. If you can factor 21, it is probably only a matter of months/maybe a few years until you factor RSA 2048. As Scott Aaronson said [3], "Once you understand quantum fault-tolerance, asking “so when are you going to factor 35 with Shor’s algorithm?” becomes sort of like asking the Manhattan Project physicists in 1943, “so when are you going to produce at least a small nuclear explosion?”"

[0] https://arxiv.org/abs/2505.15917

[1] https://sam-jaques.appspot.com/quantum_landscape

[2] https://globalriskinstitute.org/publication/quantum-threat-t...

[3] https://scottaaronson.blog/?p=9665#comment-2029013

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#24

I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.

I'm logging into websites using unique passwords with 44 bits of entropy, which they feed into a hash algorithm that takes 200ms to hash each attempt, then entering a TOTP code or touching my Yubikey, and they check against my geoip history and fingerprint my browser and they want me to complete a captcha and they e-mail/SMS a one-time code to me and they send me an e-mail telling me there's a new login to my account.

The security industry loves to use belt and belt and braces and braces and braces. If they add an extra belt or two, I doubt anyone will remark on it at all.

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#25

Earlier quoted context omitted.

Would anyone downvoting care to explain? I'm genuinely interested in seeing anything that suggests there's either some secret breakthrough (completely plausible, but there's no evidence that I've seen hint of) making quantum computers actually useful, or an argument that they'll be usable by (say) 2050? Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just wh…

I work as a security architect in a major European company. We're currently demanding a full cryptographic inventory of every new product purchased or service built in-house and will start demanding PQC in 2028. Not because we expect a workable quantum computer by 2030 (current estimates are around 2035-2040), but because stuff survives for decades in large enterprises (especially if it touches hardware in any way. T…

Man, the CBOM is such a pain. There is no standardised format yet (let alone efficient tools for crypto discovery), nobody knew what it was one year ago but now every client is asking ours anyway.

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#27
post #7
post #6

Earlier quoted context omitted.

Qualification is time-constrained. You are qualified for two to three years. So by 2030, all qualified products will be PQC-free.

> So by 2030, all qualified products will be PQC-free. You mean the opposite. PQC-free will be blocked, so by 2030 all products will be PQC qualified.

Yes, my bad X).

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#28

I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.

I don't think the TLS negotiation will become meaningfully slower, as there are multiple threads being pulled on for how to make post quantum happen here with minimal regression, instead it will likely become meaningfully more complex and only slightly slower, continuing a trend that has been ratcheting for quite some time now. ECH and modern certificate revocation checking schemes are also contributing to this.

The increase in complexity is a huge problem. It is arguably justifiable but simultaneously concerning. It's already quite hard to make a correct TLS implementation as it is.

(Personally though, I still like post quantum encryption. It's a nice hedge in case ECC and/or RSA do fall any time soon, whether by quantum computer or simply math.)

Re: France's Anssi Will Block PQC-Free Products from Certification Starting 2027

#30

Earlier quoted context omitted.

I work as a security architect in a major European company. We're currently demanding a full cryptographic inventory of every new product purchased or service built in-house and will start demanding PQC in 2028. Not because we expect a workable quantum computer by 2030 (current estimates are around 2035-2040), but because stuff survives for decades in large enterprises (especially if it touches hardware in any way. T…

Man, the CBOM is such a pain. There is no standardised format yet (let alone efficient tools for crypto discovery), nobody knew what it was one year ago but now every client is asking ours anyway.

Tell me about it! We've got slightly under 10'000 distinct software assets we are trying to catalogue. There are now a handful of vendors claiming to be able to scan for crypto, but they all suck.
Post reply on HN