Cybersecurity
Why Post-Quantum Cryptography Starts With Credentials
Cyber RTJune 29, 20263 min read

Quantum computers threaten current public-key cryptography, potentially exposing encrypted data like credentials. Experts predict a quantum computer capable of breaking such encryption could emerge within 15 years. Organizations should prioritize transitioning to quantum-resistant cryptography, focusing on credentials due to their long confidentiality lifetimes. Steps include inventorying cryptographic dependencies, prioritizing risk, adopting hybrid cryptography, and building for crypto-agility to protect against future quantum threats.
The article discusses the looming threat posed by quantum computers to current encryption methods, specifically public-key cryptography, which is used to protect sensitive data like credentials. While quantum computers today cannot yet break encryption methods like elliptic curve cryptography or RSA, advancements in quantum hardware suggest that this capability is inevitable. This poses a risk as attackers can capture encrypted data now and decrypt it in the future when quantum computing becomes more advanced.
The urgency of adopting quantum-resistant cryptography is highlighted by the Global Risk Institute’s report, which indicates that a quantum computer capable of breaking current encryption could be available within 15 years. The threat has been recognized since 1994 when Peter Shor demonstrated that quantum computers could efficiently solve problems that underpin public-key cryptography. Although symmetric encryption like AES-256 remains secure, the ability of quantum computers to break public-key cryptography could allow attackers to access protected data.
A significant concern today is the "Harvest Now, Decrypt Later" tactic, where attackers capture encrypted data with the intention of decrypting it once quantum computers become capable. This means that any data intercepted now should be considered potentially exposed. Government agencies are already setting deadlines for transitioning to quantum-resistant cryptography, with the NSA and NIST outlining timelines for phasing out vulnerable algorithms by the 2030s.
Credentials pose a major risk in a post-quantum world because they often have long confidentiality lifetimes, making them valuable targets for attackers. Non-Human Identities (NHIs), such as service accounts and API keys, are particularly vulnerable due to their longevity and lack of regular rotation. These credentials are often not inventoried for cryptographic exposure, increasing the risk of them being harvested and decrypted in the future.
To address this risk, organizations should prioritize a credentials-first approach to quantum migration. This involves inventorying existing cryptographic dependencies, particularly those related to credentials, and identifying systems that hold or broker secrets. This process may uncover forgotten or dormant accounts and secrets that need to be secured against future quantum threats.
Organizations should also prioritize risk over size by focusing on the confidentiality lifetime and exposure of credentials. This means securing small, long-lived secrets that provide access to critical systems before addressing larger but short-lived datasets. By doing so, organizations can ensure that the most vulnerable credentials are protected first.
Adopting hybrid cryptography is recommended as a transitional strategy, combining classical and quantum-resistant algorithms to protect against both current and future threats. This approach allows organizations to maintain security without relying solely on new, untested algorithms. Building for crypto-agility is also crucial, enabling organizations to adapt to future changes in cryptographic standards with minimal disruption.
Finally, organizations must act now to protect their data against quantum threats, as the transition to quantum-resistant cryptography is a lengthy process. Starting with credentials, which intersect confidentiality lifetime and potential impact, is essential. The article concludes by emphasizing the importance of proactive measures, such as the adoption of quantum-resistant cryptography in Keeper client applications, to safeguard against future quantum computing threats.


