POST QUANTUM CRYPTOGRAPHY: ACT NOW !
The G7 cybersecurity working group, which includes the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the national cybersecurity agencies of the member countries, publishes a call to action:iIn a document titled ‘Preparing for the Post-Quantum Era: A Call to Actio,’. It is urging organizations to start their transition to post-quantum cryptography, or PQC, right now.
According to the working group, ‘although the exact timeline remains uncertain, several recent advances suggest the development of quantum computers capable of breaking widely used public-key cryptography mechanisms and compromising the security of digital infrastructures.’ Moreover, an attacker doesn’t actually need a working quantum computer today to prepare a future attack. All they need to do is intercept and store encrypted data sets now, then wait until a quantum machine powerful enough can go back to the original data. This is the principle of ‘harvest now, decrypt later,’ or ‘collect now, decrypt later.’
The document recommends a practical approach rather than a cryptographic big bang. Organizations are encouraged to first take stock of their cryptographic assets, map out the dependencies between systems, and then prioritize migration, starting with the most sensitive data and assets. The integration of post-quantum cryptography should then happen gradually with the usual hardware and software refresh cycles, rather than through a costly, all-at-once replacement.
ECA COMMENT: Within the ECA cybersecurity focus group, the post-quantum and crypto-agility roadmap follows the same sequence. It starts from an outside measure of where European operators stand today, adds interviews with European vendors, researchers and users on what blocks migration in practice, and brings a first structure to the group’s September meeting. On that basis the group is preparing a European observatory of post-quantum readiness, so that members see the state of play measured rather than assumed.
IONQ CALIBRATES HOW LONG IT WOULD TAKE TO BREAK A ROBUST CRYPTOGRAPHIC ALGORITHM
On 8 September IonQ, a US Quantum computing manufacturer, published a resource estimate for breaking a 256-bit elliptic-curve signature: the secp256k1 curve behind Bitcoin, the same size as the P-256 curve behind most certificates and code signing. About 19,400 physical qubits, 1,457 logical ones, and 25.7 days of computation per key, on the trapped-ion machine the company plans for 2028. The algorithm in question is among the most robust in use today, and nothing has been broken yet: this is an estimate of what it would take. The machine does not exist yet, the largest trapped-ion computer running today holds under a hundred qubits, and the date belongs to IonQ’s investors before it belongs to us.
So why does it matter? Because it is written for signatures rather than for key exchange, and pinned to a hardware roadmap rather than left as a paper exercise. Everything we have said to boards this year was about harvest now, decrypt later: traffic collected today, read the day the machine arrives. A signature attack is a different animal. It is priced per key, and twenty-six days of quantum computation will not be spent on a web session. They will be spent on the keys worth it: a certificate root, a code-signing key, a long-lived key in a hardware security module, a wallet holding value.
For a European operator the consequence is not an algorithm question yet. It is an inventory question. Which signing keys live longest, what depends on them, how they would be rotated, and who owns that decision. Few organisations can answer all four today. For firmware and roots of trust an answer already exists: stateful hash-based signatures, standardised under SP 800-208, deployable now and resting on no new assumption.
The post-quantum roadmap the ECA cybersecurity group is building treats signatures as their own section, next to key exchange and not behind it. This estimate is the first vendor number to sit under that section. It will not be the last.
This article has been written by the animator of the ECA group on Post Quantum Cryptography, Amin Hasbini.
Want to comment? Reply to this Newsletter, or write directly to Amin Hasbini ma@mahasbini.org
QUANDELA SETS UP A PARTNERSHIP IN VIETNAM
Our pleasure to reproduce an announcement by QUANDELA, a French important actor in Quantum commuting manufacturing.:
“At the Vietnam-France Leaders Forum, held in the presence of French President Emmanuel Macron and Vietnam’s General Secretary and President Tô Lâm, we were proud to formalise a strategic partnership with Quanova.
Our ambition was shared during the event: to support Vietnam’s long-term quantum ambitions by building lasting capabilities, from trained talent and access to photonic quantum computing to concrete projects for universities, research institutions and businesses.
Combining Quanova’s local integration expertise with our full-stack photonic platform, we will develop joint offerings and relevant use cases while preparing the future next milestones. Quantum infrastructure creates lasting value only when supported by the right skills, software and local ecosystem.
Work is already underway, and the first concrete initiatives supported by this partnership is the development of a quantum training programme at Quang Trung University backed by NAM A BANK as a strategic investor. The programme aims to train students and researchers while expanding their access to quantum computing capabilities.”
Read the full announcement
AI
MISTRAL SECURES A NEW ROUND OF FUNDING
The French start-up Mistral, a champion in artificial intelligence, has completed a new funding round of three billion euros; This fifth funding round raises the company’s valuation from 12 to 21.3 billion euros. The announced amount is a record for a fundraising round, outside the stock market, for a European tech company. Among the new shareholders are SAMSUNG and the fund Scale-up Europe, launched by the European Commission. Mistral remains a European company, as investors from the Old Continent make up half of this funding round. At the end of this new round, Europe represents two-thirds of the start-up’s capital and three-quarters of the voting rights within the Board. This amount will be used to buy new chips to boost the training capabilities of Mistral’s AI models, but also to build new data centers to host more clients. The goal is also to hire salespeople to conquer new markets, especially in India and the United States. Mistral is aiming for one billion euros in revenue for the 2026 fiscal year.
THE NAVIER STOKES EQUATION SOLVED: HAS OPEN AI CHEATED ?
The Navier Stokes equation describes the behavior of a moving fluid. It’s one of the most complex mathematical problem: so far, no one could prove that the equation fully and exactly describes the behavior of the fluid. So the scientific community was impressed when OPEN AI announced, on September 8, that one of its AI systems had completely sorted out the question.However the amazement lasted a few hours only. Because it soon appeared that two researchers were just out to find the solution and had stored their works in a file hence the doubt:has the OPEN AI system simply looted the work of the two experts and finished it quicker ?
AI REGULATION: ANTHROPIC CALLS FOR VIGILANCE AND BETTER GOVERNANCE
Given the current acceleration of AI development, “I fear that within six to twelve months a group [of agents] could be able to take control of all of the Internet, which could cause hundreds of billions of dollars in damage.”. The man speaking is Dario Amodei, the CEO of ANTHROPIC. We need to “slow down” AI improvement “so that risk prevention can keep up,” wrote the CEO of Anthropic in a post on his personal website on Saturday September 12. This call comes after the warning also provided by OPEN AI after some agents illicitly took control of the HUGGING FACE AI platform.
SPACETECH
FRENCH AND SWEDISH ACTORS PARTNERS
The Swedish group Netmore, based in Stockholm and an IoT network operator (which recently bought the French company Actility), announced that it will integrate satellite connectivity offered by the French firm Kinéis, an operator of a global satellite constellation designed to manage space connectivity dedicated to IoT. The goal: to extend the reach of the LoRaWAN network beyond its terrestrial coverage, creating a hybrid solution (both terrestrial and satellite) designed to keep IoT devices connected when they move out of the range of terrestrial networks.


