Back to News
quantum-computing

Why Your Digital Certificates Are Quantum Computing’s First Casualty - CDOTrends

Google News – Quantum Computing
Loading...
8 min read
0 likes
⚡ Quantum Brief
Digital Security Data Security Why Your Digital Certificates Are Quantum Computing’s First Casualty By Winston Thomas December 01, 2025 While you've been reading this sentence, somewhere in a data center not far from you, tens of thousands of new virtual machine instances have spun up and vanished. Each one needed a digital identity. Each one became a potential security gap. And most security teams have absolutely no visibility into this shadow population.“We, as humans, can count our colleagues, team members, and the workforce,” says Kevin Bocek, senior vice president of innovation at CyberArk, speaking from Singapore.
AI Audio Summary
0:00 / 0:00
Click to play
generated-image (59).png
Quantum News · Media Library

Digital Security Data Security Why Your Digital Certificates Are Quantum Computing’s First Casualty By Winston Thomas December 01, 2025 While you've been reading this sentence, somewhere in a data center not far from you, tens of thousands of new virtual machine instances have spun up and vanished. Each one needed a digital identity. Each one became a potential security gap. And most security teams have absolutely no visibility into this shadow population.“We, as humans, can count our colleagues, team members, and the workforce,” says Kevin Bocek, senior vice president of innovation at CyberArk, speaking from Singapore. “But machines, especially those that are running businesses today in the cloud or virtual services, we can’t see them. That creates a blind spot by default.”We are already living in an enterprise world where machines outnumber us: 69% of companies now manage more machine identities than human ones, and half of them are deploying 10 times as many. If you’re a CISO, that statistic should make your eyes twitch. But wait, there’s also quantum computing. And it’s about to turn this manageable disaster into a full-blown apocalypse.(Quantum) Apocalypse, Now Related The Quantum Paradox: Why Big Banks Can’t Do What Small Banks Already Should Facing the Quantum Horizon: How to Secure, Automate, and Innovate amidst IT Chaos The cybersecurity industry likes to debate when quantum computers will break RSA-2048 encryption, with the estimates ranging from 17% to 34% by 2034 to 79% by 2044. Sophisticated adversaries aren’t waiting around. They’re executing what’s known as “Harvest Now, Decrypt Later” (HNDL) attacks: intercepting and stockpiling encrypted data today, patiently waiting for quantum computers to mature enough to crack it open like a digital piñata.“The threat that we face today is mostly the harvest now, decrypt later,” Bocek explains. “Most of that focus is on the network. But I’m actually concerned too about databases — data at rest, when it’s stored, being harvested and then being decrypted later.”It’s the ultimate long game. Nation-state actors and APT groups are already collecting encrypted traffic from financial transactions, intellectual property, and military communications. They know that in 10 or 15 years, when quantum computing catches up, today’s “secure” data becomes tomorrow’s open book. As Bocek points out, “This won't be a problem coming from a basement in Minsk. This will first come from the most sophisticated nation-states.”And they won’t announce their breakthrough with a press release, either.28 (+19) Days LaterBut quantum isn’t the most immediate crisis for CISOs. Right now, before quantum computers break anything, organizations are drowning in certificate chaos. In Singapore alone, 77% of IT respondents report monthly certificate outages.And it’s about to get worse. Starting in March 2026, the CA/Browser Forum will begin enforcing dramatically shorter certificate lifespans, dropping from the current 398 days to 200 days in 2026, then 100 days in 2027, and finally settling at a breathtaking 47 days by March 2029.“That’s basically twice the amount of work,” Bocek notes. “We’ll get down to 47 days in the coming years. That’s 12 times the amount of work.”Here’s where the certification chaos becomes something truly nightmarish: IoT devices. Consider smart factory sensors or medical devices with operational lifetimes of 10-20 years. Many are being deployed today with digital certificates set never to expire — or with 20-30 year validity periods.“That’s a problem,” Bocek warns, “because probably within that time, it will be broken. My concern is that it leaves an opportunity for the adversary sometime down the road to take over networks of devices.”Imagine connected medical devices in hospitals, industrial control systems, or smart city infrastructure rendered vulnerable because someone decided “set it and forget it” was a good certificate management strategy.(Certificate) Imitation GameThe solution to the quantum threat lies in post-quantum cryptography (PQC), a new suite of algorithms designed to be secure against both classical and quantum computers. The U.S. National Institute of Standards and Technology (NIST) has led a global standardization process, recently selecting algorithms based primarily on Lattice-Based Cryptography, a fortress built on high-dimensional vector math. The problem: it is not efficiently solvable even by the most advanced quantum machines.The two most critical new standards are CRYSTALS-Kyber, which replaces Diffie-Hellman and RSA for secure key exchange, and CRYSTALS-Dilithium, which replaces current algorithms like ECDSA for digital signatures (certificates).The challenge of PQC is not just algorithmic; it’s actually operational. These new algorithms generally have significantly larger key and signature sizes than their predecessors. This affects network bandwidth, memory, and performance, especially IoT devices that are essentially resource-constrained devices.So, organizations must adopt a “crypto-agile” strategy, transitioning to hybrid certificates that use both a classical and a PQC key pair in parallel to maintain backward compatibility while ensuring quantum-safe protection. This involves a massive, multi-year overhaul across every piece of infrastructure that uses public-key cryptography.Machine Identity’s Unholy TrinityEven if you have gotten the certification chaos under control and are ready to manage machine identities, you face another issue. Machine identities aren’t just numerous; they're fundamentally different from human identities in ways that break traditional security models. Bocek frames it as three vectors: volume, velocity, and variety.Volume: Machine identities now outnumber human identities 45-to-1. And 79% of organizations predict increases over the next year, with 16% expecting radical growth of 50-150%.Velocity: Machines are created and destroyed in seconds. That credential management spreadsheet you’re using? That’s not going to cut it at machine speed. “Unfortunately, we’ve applied things like spreadsheets, whether that’s spreadsheets kept for API keys, spreadsheets kept for digital certificates,” Bocek says. “That’s not a recipe for success.”Variety: The identity of an IoT device is fundamentally different from that of a cloud function or a hybrid, virtualised workload. Each uses various types of identities for authentication. So if you think you are looking to scale human identity management, you’re wrong. It’s really about managing entirely different species of credentials while continuing your human identity work in parallel.But, isn’t quantum computing still some time away? Not really, and current progress shows we are inching toward a quantum world — whether we’re ready for it or not. For example, Chinese researchers already demonstrated breaking 50-bit RSA encryption using D-Wave’s quantum annealing computer—a completely different approach than expected. 50-bit is a toy, a triviality against today’s 2048-bit keys. But the test proved that the quantum threat is no longer a theoretical physics problem. It’s an engineering problem, and the engineers are already at work.The Right Stuff (Nearly)To their credit, some vendors aren’t waiting for standards bodies to finish deliberating. CyberArk has been experimenting with post-quantum cryptography since 2021—testing algorithms that wouldn’t become standards, just to learn.“In 2022, working with different startups, we were able to already issue a hybrid post-quantum safe digital certificate,” Bocek explains. “Could you use that anywhere? No. Is it the standards that we even have today? No. But did we learn something from that? Absolutely yes.”They’ve also gone all-in on open source, acquiring and then donating cert-manager — the standard certificate management tool in Kubernetes — to the Cloud Native Computing Foundation. It’s a radical departure from the traditional security vendor playbook of proprietary everything.The strategy reflects a fundamental shift: security teams need to meet developers where they are, not force them into security tools. “Forward-looking is saying, you know what, we’ll govern your use of the secrets manager,” Bocek says. “We'll make sure policy is followed, but keep on using it.”The Day After TomorrowBut here’s what keeps me up at night after talking to Bocek and reviewing the research: we’re not ready. Not even close.Only 41% of organizations globally were actively preparing for post-quantum cryptography in 2024. Meanwhile, 90% of organizations experienced at least one identity-related incident in the past year, and 83% reported machine account takeovers.“The awareness around ‘can we do something about post-quantum readiness’ is still low,” Bocek observes from his conversations with teams in Singapore. “These were teams that were responsible.”We’re also facing a generational change in cryptography with the first major overhaul since Diffie-Hellman and RSA were developed nearly 50 years ago. But unlike Y2K, which had a specific deadline, this is a rolling threat that’s already begun. The adversaries are harvesting now. The certificate crisis is happening now. The machine identity blind spots exist now.“This is not a one-year, two-year process, but a many-year process of change,” Bocek warns. “This is a generational change, not an overnight change.”And yet, most organizations are treating it like a project they can schedule for Q3 2027. They’re not just sleepwalking into a nightmare; they're actively hitting the snooze button, believing they have more pressing security concerns.It’s true, quantum apocalypse might not arrive today. But your next certificate outage? That could be tomorrow. And somewhere, right now, an adversary is patiently archiving your “secure” communications, waiting for the day quantum computing makes them readable.When it arrives, the digital world will fracture, leaving all our secrets exposed.

Read Original

Tags

quantum-computing

Source Information

Source: Google News – Quantum Computing

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.