Google’s PQC roadmap puts traditional digital certificates under pressure

https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-2560-80.jpg

In March, Google moved its own post-quantum cryptography (PQC) migration deadline forward to 2029, a full six years ahead of NIST's guidance, and two ahead of the NSA's requirement for national security systems. It was a terrific bit of security signaling, but now it is backed up by a new product-by-product roadmap organized around three risk domains, with milestones attached to named services.

Jason Soroko is the SVP of Product at Sectigo.

For anyone whose job touches digital trust, the most significant of those three domains is Google’s attempt at enhancing foundational capabilities for cryptographic agility: building flexible systems that can adopt new cryptographic standards with minimal engineering effort as those standards evolve.

The message is that organizations should prepare for a future in which standards, certificate formats, and operational requirements continue to evolve, and evolve regularly, requiring cryptographic agility.

Why quantum risk is already a digital trust problem

Adversaries...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more