France To Stop Certifying Products Without Quantum-Safe Encryption 35
Starting in 2027, France's cybersecurity agency ANSSI will stop certifying security products that lack quantum-resistant encryption, effectively forcing government agencies and critical infrastructure operators to phase out older cryptographic systems. Reuters reports: Samih Souissi, ANSSI's chief of staff, said at the France Quantum conference that the agency would halt such certifications from 2027, and that businesses should be buying only quantum-safe products by 2030. ANSSI approval is required for use in French government agencies and critical infrastructure, making the policy a de facto phase-out of older encryption.
"It's not only a technical issue," Souissi said. "It's a matter of governance, industrial planning, regulation, and sovereignty." The move reflects concern that attackers may store encrypted data now and unlock it later when quantum computers become strong enough to crack today's protections, a risk known as "harvest now, decrypt later."
"It's not only a technical issue," Souissi said. "It's a matter of governance, industrial planning, regulation, and sovereignty." The move reflects concern that attackers may store encrypted data now and unlock it later when quantum computers become strong enough to crack today's protections, a risk known as "harvest now, decrypt later."
Quantum Resistant Encryption (Score:2)
I had no idea what that might be, so I did some checking. I think that we can all agree that everyone should use:
CRYSTALS-Kyber encryption
and
CRYSTALS-Dilithium
Wireguard in shambles.
Re: (Score:3)
Re: (Score:2)
I had no idea what that might be, so I did some checking. I think that we can all agree that everyone should use:
CRYSTALS-Kyber encryption and CRYSTALS-Dilithium
I'd recommend ML-KEM and ML-DSA instead.
Re: Quantum Resistant Encryption (Score:3)
Re: (Score:2)
These are actually the same two algorithms, renamed to be less fun.
Yes, that was the joke. Maybe too much of an inside joke, but isn't this supposed to be a nerd forum?
Re: Quantum Resistant Encryption (Score:2)
Re: They know something (Score:2)
They don't know shit, some fraud convinced some policy maker that their snake oil was real
Re: (Score:2)
They don't know shit, some fraud convinced some policy maker that their snake oil was real
Exactly my take as well. This is about making some people money, not about any real risk.
Re:They know something (Score:5, Insightful)
but they aren't telling.
A number of larger organizations have conjectured based on current progress that Q-Day (when quantum computers will be sufficiently capable of breaking classic encryption) may be as close as 2029. Due to the "harvest now, decrypt later" issue, stopping certification of new products that do not have PQC capability a few years earlier (given the time frames for acquisition, testing, and deployments) makes some sense. It is possible that the engineering challenge of building a sufficiently capable quantum computer will not be overcome, but it is just an engineering challenge, and the engineering tends to only get better over time.
Re: (Score:2)
But "harvest now, decrypt later" is a real threat quantum or not.
There are a lot pictures on politician's telephones which would be damning today or in 20 years. And no, there are no encryptions are from time.
Re: (Score:2)
They know that forcing random gubermint agencies to change their security systems arbitrarily will give a lot of new opportunities for foreign intelligence agencies to penetrate their systems, but they don't care; foreign gubermints don't vote in France, so they'll take the penalty in order to score a political talking point.
They'll probably blame America, without being willing to even pronounce it, but as an American I'm confident that this will improve our intelligence visibility.
OpenSSH (Score:3)
I wonder if OpenSSH will be acceptable. Or does this certification only apply to commercial products ? AFAIK OpenSSH would be acceptable.
https://www.openssh.org/pq.html
Re: (Score:3)
it supports ML-KEM. so yeah, openssh is fine.
Yup. Also, apparently as of OpenSSH 10.1 people who aren't using quantum-resistant key algorithms will be warned [openssh.org].
Really? (Score:3)
Re:Really? (Score:5, Informative)
They called it ANSSI?
1) It was actually DCSSI (Direction Centrale de Securite des Systemes d'information) as a branch of the Ministry of Defence until 2009 when it was elevated to the rank of an Agency.
2) Agencies in France are prefixed with AN for Agence Nationale. For example in France ANSES (environment safery), ANSP (public health), ANR (Research), ANPE (employment agency), therefore renaming it AN + SSI.
3) ANSI is unrelated (the French equivalent of ANSI is AFNOR) and therefore not ambiguous.
Re: (Score:2)
They called it ANSSI?
There is a limited number of TLAs, and FLAs. And any TLA/FLA(as in four)/FLA(F as in Five) abbreviations will eventually get overloaded and reused. I don't care would ANSSI has abbreviated itself to, what I care about is what their authorities are.
Re: (Score:3)
That's what she said.
Re: that seems (Score:2)
If it's a good idea then it isn't. You really don't want to be instituting a change like this when you find out you need to.
On the other hand there's no clear path to usefulness for quantum computers whatsoever
Re: (Score:2)
It's not premature. It's either unneeded, or "they should have done this a few years ago". And we won't know which for several years.
Remember, it's not only stuff that can be broken instantly. Coded messages can be recorded, and then broken when it's interesting/convenient.
It's about time. (Score:2)
GSM (Score:2)
Weren't the French responsible for intentionally weakening GSM security during the 80s & 90s?
Re: (Score:2)
No, that was the British. GCHQ, IIRC, actually came up with the encryption scheme GSM used.
Place your bets (Score:2)
Which will happen first crypto relevant quantum computers or compromise of new post quantum crypto algorithms? I think the latter is more likely.
Re: (Score:2)
Agreed, in fact I think that's a major reason to avoid use of non-hybrid PQC.
Re: (Score:2)
Definitively. Always insist to get the security of a known-good classical algorithm in addition. Relying on something "quantum safe" alone is pure insanity at this time.
Re: (Score:2)
My bet would be that breaking something like RSA 2048 with a QC is not possible in this universe. It is too small and has not enough remaining lifetime.
Encryption or signatures? (Score:2)
What I have been seeing when talking to bunch of customers who are anxious about the quantum computers breaking ciphers is not so much encryption (as in transmission of data without eavesdropping learning the contents). If your credit card number leaks because you sent it over TLS session that someone captured and cracked with a quantum computer, that's an inconvenience to get a new card, but still minor.
The big interest is in quantum-secure digital *signatures*. No, not the ones on website certificates. Bu
Re: (Score:2)
Do not trust "quantum safe" encryption (Score:2)
It is not old enough and may still fail with catastrophic weaknesses. The way to go for new products is to use hybrid encryption, where a successful attack requires breaking both a quantum safe algorithm and a classical (good) one. Or, if you can, stay classical, since Quantum Computers are very, very, very, very far removed from being able to break any real encryption. In fact, after more than 50 years of research, these "machines" can factor 29 currently (well, one could and that was with moderate cheatin
Re: (Score:2)
Good points. I'm no expert in the field, but I've taken master's level courses in the relevant math and physics. I particularly remember my math professor saying that no encryption has been mathematically proven safe. We only know the current schemes are safe insofar as nobody has published an attack yet.
We do know how to break certain classical encryption schemes with hypothetical quantum computers. This clearly doesn't mean other schemes will stay quantum-unbreakable forever, because people keep invent
Re: (Score:2)
In theory, your professor was right. In practice, not so much. The thing is theory requires perfect proofs. Practice only "good enough" ones. (We will ignore that the one-time-pad is mathematically proven secure, because it has little practical relevance...)
So that state of things is that ElGamal has a security proof relying on an unproven assumption that is very likely true. RSA is much weaker on the theory side and current block ciphers or crypto-hashes are even weaker on the proof side.
As to QC, the prob