Keyfactor on Cryptographic Discovery: Why Knowing What You Have Is Step One
By F5 DevCentral Community
Key Concepts
- Post-Quantum Cryptography (PQC): Cryptographic algorithms designed to be secure against the processing power of future quantum computers.
- Cryptographic Agility: The ability of an IT system to rapidly switch between cryptographic algorithms or protocols without significant infrastructure overhaul.
- Cryptographic Discovery: The process of identifying and cataloging all cryptographic assets (certificates, keys, SSH keys) across an enterprise environment.
- Harvest Now, Decrypt Later (HNDL): A strategy used by threat actors to intercept and store encrypted data today, with the intent of decrypting it once quantum computing technology matures.
- Q-Day: A hypothetical future point in time when quantum computers become powerful enough to break current encryption standards (e.g., RSA).
- PKI (Public Key Infrastructure): The framework of roles, policies, hardware, and software needed to create, manage, and distribute digital certificates.
1. The Necessity of Cryptographic Discovery
The speakers emphasize that before enterprises can transition to PQC, they must achieve full visibility into their cryptographic landscape.
- Scope: Discovery is not limited to SSL/TLS certificates; it must include encryption keys, SSH keys, and keys stored in repositories like GitHub or Artifactory.
- Risk: Undiscovered or unmanaged keys act as security vectors. Without a "single pane of glass" to monitor these assets, organizations cannot effectively secure their infrastructure.
2. The "Harvest Now, Decrypt Later" Threat
A major argument presented is that the threat of quantum computing is not a future event, but a current reality.
- Nation-State Actors: These entities possess the resources to store massive amounts of encrypted data today.
- Data Longevity: The urgency of the threat depends on the data's value over time. Organizations are advised to categorize data based on its sensitivity (e.g., data that must remain secure for 1, 5, or 25 years) and apply stronger PQC algorithms to long-term assets immediately.
- The "Quiet" Threshold: The speakers argue that "Q-Day" will not be a public, sudden event. It will likely be a quiet, undetected threshold crossed by sophisticated actors, leaving organizations unaware that their historical data has been compromised.
3. Operational Challenges: Certificate Lifecycles
The industry is moving toward significantly reduced certificate lifetimes (e.g., 47-day certificates).
- The Scaling Problem: Manual renewal processes are unsustainable. If an organization has 500,000 certificates, moving from annual renewals to 47-day cycles increases the workload by roughly eight times per year.
- Risk of Outages: Manual management leads to human error, which results in expired certificates, service outages, and authentication failures. Automation is presented as the only viable solution to manage these shortened lifecycles.
4. PQC Implementation and Standards
- NIST Standards: While NIST is approving new algorithms (e.g., ML-DSA, ML-KEM), the field is still nascent.
- The Risk of Flaws: Unlike RSA, which had decades of testing, new PQC algorithms may be found to have flaws shortly after deployment. This reinforces the need for cryptographic agility—the ability to swap out algorithms quickly if one is compromised.
- Vendor Readiness: Many network devices (firewalls, load balancers) do not yet support PQC. Organizations must pressure vendors to ensure their hardware is PQC-ready.
5. Strategic Recommendations
- Start Early: The transition cannot be treated like a "Y2K" event where everything is switched at once. It requires a phased, "baby-step" approach.
- Executive Buy-in: A significant barrier is the lack of resources and C-suite support. Practitioners are encouraged to advocate for the importance of forward-looking security investments.
- Resource Utilization: The speakers recommend utilizing the PQC Consortium’s roadmaps and hands-on labs (such as those provided by Keyfactor) to begin the transition process.
Synthesis
The transition to a post-quantum world is not merely a technical upgrade but a fundamental shift in how enterprises manage security. The primary takeaways are that discovery is the mandatory first step, automation is required to handle reduced certificate lifecycles, and cryptographic agility is the only defense against the uncertainty of new, untested PQC algorithms. Organizations must act now to protect long-term data from "Harvest Now, Decrypt Later" attacks, rather than waiting for a definitive "Q-Day."
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Quantum Risk And Bitcoin: Preparing For A Post-Quantum World
ARK Invest

Everything You Trust Online Could Break — F5 Labs on Q-Day
F5 DevCentral Community

Agentic Attackers, LLM Leaderboards, and Q-Day: A Conversation with F5 Labs
F5 DevCentral Community

One App at a Time: DigiCert's Practical Playbook for the Post-Quantum Transition
F5 DevCentral Community

Automating Certificate Management with Digicert
F5 DevCentral Community

What Quantum Safe Is and Why We Need It to Stay Secure
John Savill's Technical Training

Low-Latency Security for Time-Critical Grid Communication with Shabnam Saderi, Research Assistant
Canadian Institute for Cybersecurity (CIC)