Opens in a new tab
vmblog logo 2024 wht (updated)

Coviant Software 2025 Predictions: Ignoring the Biggest Security Threat of 2025

Share: 

David Marshall | Published: January 20, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By
Greg Hoffer, CEO,
Coviant Software

2025 is the
year it finally happens. 2025 is the year we no longer have to wait the five to
twenty more years the experts have perpetually told us it would take for viable
quantum computing to become a reality. That’s not the prediction, however. My
prediction for the new year is that almost everyone will be so distracted by
the hype around artificial intelligence that they fail to recognize the threat
that awaits them in a post-quantum world.

Please Pay
Attention

If you
weren’t paying attention, Google Quantum AI announced a breakthrough in qubit
processing error suppression in December. That’s a big deal because the biggest
barrier to viable quantum computing is the predictability of qubits as they run
their calculations. Google’s quantum processing chip, dubbed “Willow,”
demonstrated sustained real-time error correction. It’s hard to overstate how
important this development is and what it means for the near future of quantum
computing.

Counterintuitively,
the rate of error correction improved as code distances increased. As Phys.org reported, “Each
time the code distance is increased from 3 to 5 to 7, the logical error rate is
halved. This exponential suppression of logical errors forms the foundation for
running large scale quantum algorithms with error correction.”

We are on
the threshold of the post-quantum era. If you are a quantum nerd like me, this
is exciting. And it’s also a bit frightening. Here’s why.

Hard
Problems Easily Solved

Today’s
public key cryptography relies on algorithms that traditional computers can’t
realistically solve. Even the fastest computer today would require millennia to
break any of the flavors of public key cryptography in use today-the encryption
used to safeguard digital data and communications and on which the trust of the
public internet depends. Those same algorithms will be easily broken when
quantum computing becomes viable, and so, in the wrong hands, a quantum
computer will make quick work of deciphering any data or files that aren’t
protected by quantum-safe encryption.

Every phone
call, email, text message, medical file, and financial transaction that moves
along that infrastructure is protected by public key cryptography. What’s more,
quantum computing could be used to decipher and forge digital signatures used
for contract execution, loan agreements, credentialling, Bitcoin/cryptocurrency
wallets, and more.

No
Guarantees

Currently,
there are few ways to truly lock down sensitive data against the threat of
quantum computing. Techniques like elliptical curve cryptography take a
different mathematical approach than those used by the more common RSA and
Diffie-Hellman algorithms and, in theory, might be harder to crack. NIST recently published three new post-quantum encryption
standards
that, in theory, are resistant to the
power of quantum computing.  And that’s the rub. Until these
quantum-resistant algorithms can be tested against the power of an actual
quantum computer, there are no guarantees.

And so,
while the world is transfixed by the amazing things that can be done with
generative AI, quantum computing is sneaking up on us and threatens to
completely undermine the foundations of security we rely on in the digital age.
What’s more, according to FinTech Magazine,
transitioning industries and public infrastructure from current cryptological
standards to a truly quantum-resistant security model could take as long as
10-15 years to complete. We don’t have that much time anymore. And there’s
evidence that some threat actors are already engaged in “quantum harvesting” to
intercept and store encrypted files in anticipation of a day when they will
have the power to crack obsolete cryptography.

Don’t Do
Nothing

In 2022 the
Cybersecurity & Infrastructure Security Agency (CISA) published a paper to
help critical infrastructure operators with the transition to post-quantum
cryptography. Preparing Critical Infrastructure for Post-Quantum Cryptography
can be used as a guide by any organization to help understand and prepare for
that eventuality. Adopting support for elliptical curve cryptography and the
new NIST post-quantum standards is a good first step, and tracking new
developments will keep those interested from being taken by surprise.

This is one
prediction I hope I’m wrong about, but that would be the triumph of hope over
experience. And events such as the Y2K scare have had the unfortunate residual
effect of convincing too many people (people who should know better) that doing
nothing is the best course of action. Quantum computing will be a powerful tool
for good, but it comes with legitimate and serious security implications. Let’s
not allow ourselves to be complacent.

##

ABOUT
THE AUTHOR

Gregory-Hoffer 

Gregory Hoffer is CEO of Coviant
Software
,
makers of the award-winning and secure-by-design Diplomat MFT manage file
transfer solution.