Quantum Security & PQC
Post-quantum cryptography, PQC migration, crypto-agility, cryptographic inventory, CBOM, and practical quantum readiness.
-
Post-Quantum, PQC, Quantum Security
Proving Your Crypto Inventory Is Complete Without Handing Over the Map
Four research teams have built privacy-preserving validation systems for bills of materials. Each can prove something about a committed record, and none establishes that the record describes the estate it claims to cover.
Read More » -
Post-Quantum, PQC, Quantum Security
Guarding the CBOM: The Most Sensitive Document Your Security Program Produces
Cryptographic discovery finds weaknesses that matter today, not only after a quantum computer. The resulting inventory ranks them, stays useful to attackers for years, and almost nobody has said to guard it.
Read More » -
Post-Quantum, PQC, Quantum Security
Six Teams Shipped the Same ZK Verifier Bug. Quantum Doesn’t Get a Patch.
Zcash closed a 3.66 million ZEC pool to new deposits after a soundness bug surfaced in a Shielded Labs audit. A quantum verifier migration is harder, and no regulator can schedule the fork.
Read More » -
Post-Quantum, PQC, Quantum Security
When Two Cryptographers Independently Confirm a Break, Ask Which Model They Used
Two proofs of the same result landed three hours apart from the same model, and Simon's DCP claim is now being taken apart by humans and models working together. Separate names no longer establish separate failure modes.
Read More » -
Post-Quantum, PQC, Quantum Security
Two QFT Records in Four Months. Neither Gets You Closer to Breaking RSA.
Two compilation teams claimed the largest quantum Fourier transform ever run, four months apart, on the same IBM chip. Their circuits and metrics are not comparable, and the gate counts explain why.
Read More » -
AI Security
AI Governance Is Repeating Cybersecurity’s Mistakes
Cybersecurity never eliminated conflicts over testing, disclosure, and oversight. It built mechanisms to expose and manage them. July's AI evaluation failures show which of those mechanisms frontier labs still lack.
Read More » -
AI Security
AI Hacking Theater and the Crypto-Agility Wake-Up Call
OpenAI and Anthropic spent two weeks one-upping each other's AI hacking disclosures. Buried beneath the competitive theater are three developments CISOs can no longer ignore, and the defense for all three is the same.
Read More » -
AI Security
AI Can Hack Everything? Do the Math First
Everyone is selling protection from AI hackers. Almost nobody is asking whether AI attacks can actually scale, or whether the answer was sitting in their security budget the whole time.
Read More » -
Quantum Sovereignty
Why the OpenAI Breach Matters for Quantum Strategy
Everyone is covering the OpenAI/Hugging Face breach as an AI scare. The real lesson is in the forensics: US models blocked defenders, a Chinese model did the job, and the same flawed control logic governs quantum.
Read More » -
Post-Quantum, PQC, Quantum Security
Why Europe Is Industrialising CV-QKD
QUARTERNEXT places CV-QKD at the centre of one European industrialisation track. EuroQCI remains deliberately multi-protocol. The real story is how telecom integration, certification, and supply-chain control shape the portfolio.
Read More » -
Post-Quantum, PQC, Quantum Security
How Much Can AI Help With PQC Migration?
AI is already part of PQC migration, and it helps. But the claim that frontier models compress enterprise timelines from 15 years to four confuses which part of the program AI accelerates and which part it cannot touch.
Read More » -
Post-Quantum, PQC, Quantum Security
You Cannot Detect Harvest Now, Decrypt Later (HNDL)
Vendors are beginning to sell HNDL detection. Boards are asking for proof of HNDL targeting. Neither is possible. Passive collection leaves no observable event inside your network. The defense is encryption, not detection.
Read More » -
Post-Quantum, PQC, Quantum Security
Is Harvest Now, Decrypt Later (HNDL) Real? What I Can and Can’t Prove
No question comes up more often in my consulting and board sessions. For years I could only point to what spy agencies say. Here is the full answer: the written record, and the physics of collection.
Read More » -
Post-Quantum, PQC, Quantum Security
The Coming CRQC Blackout: Why the Papers Will Stop Before the Progress Does
The field ran three disclosure experiments in 2026: full openness, cryptographic secrecy, and silence. Only one is stable, and it ends our ability to track CRQC progress through published research.
Read More » -
Post-Quantum, PQC, Quantum Security
The Shannon Hustle: How Vendors Abuse Perfect Secrecy to Sell You Less Than You Think
Vendors drop "Shannon" into pitch decks to imply information-theoretic security. The math says otherwise. A five-question framework for evaluating any claim of perfect secrecy with practical key sizes.
Read More »