What Quantum Safe Is and Why We Need It to Stay Secure
By John Savill's Technical Training
Quantum Safe Cryptography: A Detailed Summary
Key Concepts:
- Quantum Computing: A new paradigm of computation leveraging quantum-mechanical phenomena like superposition and entanglement.
- Qubit: The basic unit of information in quantum computing, existing in multiple states simultaneously.
- Bit: The basic unit of information in classical computing, representing either 0 or 1.
- Post-Quantum Cryptography (PQC): Cryptographic algorithms designed to be secure against attacks from both classical and quantum computers.
- Shor’s Algorithm: A quantum algorithm capable of efficiently factoring large numbers, breaking many current encryption schemes.
- Grover’s Algorithm: A quantum algorithm that can speed up searches, reducing the effective key length of symmetric encryption.
- Kyber/ML-KEM: A lattice-based key encapsulation mechanism considered quantum-safe.
- Dilithium/ML-DSA: A lattice-based digital signature scheme considered quantum-safe.
- Lattice-based Cryptography: A PQC approach based on the difficulty of solving problems on mathematical lattices.
- Harvest Now, Decrypt Later: A potential attack scenario where encrypted data is intercepted and stored for future decryption with quantum computers.
1. The Threat of Quantum Computing to Current Cryptography
The video begins by outlining the potential threat posed by quantum computing to existing cryptographic systems. While classical computers operate using bits representing either 0 or 1, quantum computers utilize qubits. Qubits leverage superposition, allowing them to represent multiple states simultaneously, and entanglement, enabling interconnectedness between qubits. This fundamentally changes computational capabilities.
Classical cryptography relies on the computational difficulty of certain mathematical problems, such as factoring large numbers (used in RSA encryption). The video emphasizes that breaking these problems with classical computers would take longer than the age of the universe, providing current security. However, Shor’s algorithm, a quantum algorithm, can efficiently factor large numbers, rendering RSA and other similar algorithms vulnerable. This vulnerability extends to Diffie-Hellman key exchange and Elliptic Curve Cryptography (ECC).
2. Classical vs. Quantum Computing: A Comparative Analysis
The video contrasts classical and quantum computing. Classical computers perform operations sequentially, testing one possibility at a time. Quantum computers, due to superposition, can explore multiple possibilities concurrently, significantly accelerating certain calculations. The analogy of waves interfering – amplifying correct answers and canceling out incorrect ones – illustrates how quantum algorithms work.
The video highlights the limitations of classical computers in modeling complex systems like molecules. A caffeine molecule, with 102 electrons, requires 2<sup>102</sup> bits to fully model classically, an impossible task given the estimated number of atoms in the universe (approximately 2<sup>300</sup>). Quantum computers, by leveraging quantum phenomena, are better suited to simulating such systems.
3. Post-Quantum Cryptography: The Solution
The core of the video focuses on Post-Quantum Cryptography (PQC), the development of cryptographic algorithms resistant to attacks from both classical and quantum computers. The key is to move away from mathematical problems vulnerable to Shor’s algorithm.
The video specifically details two promising PQC candidates standardized by NIST:
- Kyber (ML-KEM): A lattice-based key encapsulation mechanism used for key exchange. It relies on the Learning With Errors (LWE) problem, which is believed to be hard for quantum computers to solve. The public key contains controlled noise, and only the private key holder can remove it to decrypt.
- Dilithium (ML-DSA): A lattice-based digital signature scheme used for authentication and code signing. Like Kyber, it’s based on lattice structures and the LWE problem. An alternative hash-based signature scheme, XMSS, is also mentioned.
The video playfully notes the naming convention of these algorithms (Kyber and Dilithium) referencing Star Wars and Star Trek crystals, acknowledging the nerdy origins of the field.
4. Implementation and Timelines
The video discusses the practical implementation of PQC and associated timelines. Microsoft is actively integrating PQC algorithms into its core products, including Windows 11, Windows Server 2025, Azure, and M365.
Key milestones include:
- 2023: Initial work began on integrating PQC into core components.
- 2026: Core infrastructure services (authentication, signing) will be updated.
- 2027: All services and endpoints (Windows, Azure, M365, Copilot) are targeted for full PQC readiness.
- US Government Mandates: The US CNSS policy 15 mandates quantum-safe algorithms in new national security systems by January 2027.
Microsoft’s SimCrypt cryptographic library is being updated to include these new algorithms.
5. Symmetric vs. Asymmetric Cryptography & the "Harvest Now, Decrypt Later" Threat
The video clarifies that symmetric encryption algorithms (like AES-256) are less vulnerable to quantum attacks than asymmetric algorithms (like RSA). Grover’s algorithm can reduce the effective key length of symmetric algorithms, but a 256-bit key remains secure.
A significant concern is the “harvest now, decrypt later” attack. Malicious actors can intercept and store encrypted data today, anticipating the availability of quantum computers capable of decrypting it in the future. This is particularly relevant for data requiring long-term confidentiality.
6. Mitigation Strategies & Best Practices
The video outlines several mitigation strategies:
- Reduce Attack Surface: Minimize the amount of data that can be intercepted by using private networking (e.g., Azure Private Endpoints, Managed Virtual Networks).
- Secure Data in Transit: Ensure data is encrypted using strong symmetric encryption (AES-256) during transmission.
- Avoid Shadow AI: Use integrated AI solutions to prevent sensitive data from being sent to public AI services.
- Inventory & Update: Identify cryptographic algorithms used within applications and plan for updates to PQC alternatives.
- Leverage Vendor Solutions: Utilize PQC implementations provided by vendors like Microsoft.
- Code Analysis: Use tools like GitHub CodeQL to identify vulnerable cryptographic algorithms in codebases.
7. Notable Quotes:
- “If people can capture the traffic now, then maybe in a few years when the quantum computers do have thousands of cubits and can now run those algorithms and crack it that be usable.” – Emphasizing the urgency of addressing the "harvest now, decrypt later" threat.
- “Security is never a function. We don't just have a moat. We always think defense in depth.” – Highlighting the importance of layered security measures.
Conclusion:
The video provides a comprehensive overview of the quantum threat to cryptography and the emerging solutions in PQC. The transition to quantum-safe algorithms is not merely a theoretical concern; it’s a practical necessity driven by the potential for future decryption of currently encrypted data. Organizations should proactively assess their cryptographic posture, implement mitigation strategies, and prepare for the adoption of PQC algorithms to ensure long-term data security. The ongoing efforts of vendors like Microsoft to integrate PQC into their products will significantly ease this transition.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Is there a Chinese cyber threat to EU solar energy? | DW News
DW News

i f**k'd up
Meet Kevin

3 AI Stocks Insiders Are Selling. Most Aren't Ready for What Happens Next.
MarketBeat

From Know Your Customer to Know Your Reality in the Age of AI | Mr. Smarak Swain | TEDxKPRCAS
TEDx Talks

OpenAI's New GPT Cyber Beats Mythos 5
AI Revolution

Top Stocks I'm Buying For Huge Growth In July 2026
Ticker Symbol: YOU

THE FED’S FATAL MISTAKE: Why Gold is About to EXPLODE Higher!
Steven Van Metre