logoalt Hacker News

France's Anssi Will Block PQC-Free Products from Certification Starting 2027

80 pointsby Sami_Lehtinentoday at 4:02 PM37 commentsview on HN

Comments

tsimionescutoday at 4:59 PM

I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.

show 12 replies
dylan604today at 9:39 PM

From TFA: "The policy reflects growing concern about Harvest Now, Decrypt Later (HNDL) attacks, in which adversaries intercept and store encrypted communications today with the intention of decrypting them once a cryptographically relevant quantum computer (CRQC) becomes available."

Once it gets to be "later" where the harvest data is able to be decrypted, I guess will have decent enough LLMs to summarize all of that data? Otherwise, there's going to be such a huge back log to make it not too useful

dredmorbiustoday at 7:41 PM

PQC: Post-Quantum Cryptography.

The concern is systems which won't be resistant against quantum cryptographic attacks.

The US's NIST has an explainer page, "Post-Quantum Cryptography PQC":

<https://csrc.nist.gov/projects/post-quantum-cryptography>.

colmmacctoday at 6:40 PM

I was at ANSSI headquarters last year doing a technical presentation and several of their questions were about Post-Quantum Cryptography, "Q day" (when a practical Quantum Computer is expected) and other related things. They keep a close eye on this stuff and it's to their credit. Similarly the BSI in Germany have been promoting Post-Quantum security for some time now.

I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!

cold_pizz4today at 4:27 PM

Related: https://news.ycombinator.com/item?id=48992806 (Are 128-bit symmetric keys really secure against quantum computers?)

vaadutoday at 4:31 PM

Will they decertify previously certified PQC-free products?

show 1 reply
6r17today at 8:05 PM

TBF it's the healtiest approach to it. It's just risk mitigation. Nobody cares about it - there are nice papers to implement it ; just freaking do it.

u1hcw9nxtoday at 4:32 PM

[dead]

close04today at 4:30 PM

[dead]

CurbStompertoday at 7:57 PM

[dead]