What's in the SOSS? An OpenSSF Podcast

Racing Against Quantum: The Urgent Migration to Post-Quantum Cryptography with KeyFactor's Crypto Experts

11 snips
Sep 9, 2025
Join David Hook, VP of Software Engineering at KeyFactor, and Tomas Gustavsson, Chief PKI Officer with 30 years of cryptography experience, as they tackle the urgent migration to post-quantum cryptography. They explain the quantum threat and why the financial sector is spearheading this transition. Practical tips for assessing current systems, enhancing crypto agility, and the vital need for high entropy in secure key generation are discussed. Plus, enjoy a fun rapid-fire Q&A showcasing their chemistry and insights!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Quantum Deadline Is Real

  • Once a cryptographically relevant quantum computer exists it will be too late to switch away from vulnerable algorithms.
  • The term "post-quantum" misleads some to delay migration, so treat readiness as urgent now.
ADVICE

Start Testing Pre-Certified PQC

  • Test pre-certified implementations now to learn performance and interoperability differences with PQC.
  • Expect larger keys and signatures and adapt systems for new KEM-based key transport.
ANECDOTE

Bouncy Castle's PQC Implementation Story

  • Bouncy Castle implemented NIST round-three PQC candidates in Java and C# with university-funded validation and side-channel review.
  • They then engaged in interoperability testing with IETF and other projects to ensure encodings work across vendors.
Get the Snipd Podcast app to discover more snips from this episode
Get the app