| ▲ | alphager a day ago | ||||||||||||||||||||||
I work as a security architect in a major European company. We're currently demanding a full cryptographic inventory of every new product purchased or service built in-house and will start demanding PQC in 2028. Not because we expect a workable quantum computer by 2030 (current estimates are around 2035-2040), but because stuff survives for decades in large enterprises (especially if it touches hardware in any way. Think OT, think controllers for all kinds of machines). Now that PQC is standardized, there's no gain not to demand it (it's basically a demand to use a current openSSL/libreSSL/$library), but not demanding it now will cause a major headache once/if quantum computers work. TLS connection speed matter only for a very tiny niche of applications; those will choose according to their needs. For the general case, it just doesn't matter. If your threat model includes store-now-decrypt-later, you should have been demanding PQC for years. | |||||||||||||||||||||||
| ▲ | plopilop a day ago | parent [-] | ||||||||||||||||||||||
Man, the CBOM is such a pain. There is no standardised format yet (let alone efficient tools for crypto discovery), nobody knew what it was one year ago but now every client is asking ours anyway. | |||||||||||||||||||||||
| |||||||||||||||||||||||