Industry executives and experts share their predictions for 2023. Read them in this 15th annual VMblog.com series exclusive.
Setting the Stage for Quantum Computing and a Passwordless Future
By Tim Callan, Chief Experience Officer at Sectigo
From advancements in quantum to the actualization of passwordless technologies, there was no shortage of innovation that came to life in 2022. With this innovation, unfortunately, also comes a new wave of risks and considerations for enterprises to consider in the new year and beyond. 2023 will thus challenge enterprises to redefine what it means to truly be secure in a world where sensitive data that has been protected for decades will find itself vulnerable to bad actors with the advent of new technology.
The Year of Quantum-Readiness
There’s been a lot of discussion about the looming “quantum apocalypse”-the point at which quantum computers will be able to readily break the cryptographic foundation that secures the world’s data.
With the standardization of new quantum-safe algorithms expected to be in place by 2024, I anticipate that 2023 will be a year of action for government bodies, technology vendors, and enterprise IT leaders alike to prepare for fast, efficient, and error-free deployment of new cryptographic standards that will ensure preparedness and usher in a safe and secure post-quantum future.
In 2022 the US National Institute of Standards and Technologies (NIST) selected a set of post-quantum algorithms for the industry to standardize on as we move toward our quantum-safe future. Looking ahead to 2023, standards bodies like the IETF and many others must work to incorporate these algorithms into their own guidelines to enable secure functional interoperability across broad sets of software, hardware, and digital services. Providers of these hardware, software, and service products must follow the relevant guidelines as they are developed and begin preparing their technology, manufacturing, delivery, and service models to accommodate updated standards and the new algorithms.
Enterprises will begin preparations on backend systems by taking inventory of all encrypted systems and preparing deployment strategies for the new cryptography to ensure that systems are post-quantum ready. Enterprises will audit their cryptography, vendors, and compliance requirements, as well as their system patches and upgrades. We will see enterprises prioritize crypto agility in preparation for the quantum era, meaning they will implement X.509 hybrid certificates that use quantum-safe encryption algorithms. This will ease the eventual transition from traditional public key infrastructure (PKI) cryptography to post-quantum cryptography.
We also see the quantum computing arms race between nation-states heating up in 2023 as governments seek to gain a competitive advantage in the digital age. We already know about government and corporate espionage between countries, but the country that first unlocks the power of quantum will set itself and its allies up to decrypt classified intelligence for a political, technological, and financial advantage.
Making Online Passwords a Thing of the Past
As we embrace the future of quantum and other new age technologies like Web3 and the Metaverse, enterprises will begin to understand that passwords are no longer enough to authenticate and secure the influx of digital identities traversing the digital realm.
Apple, Google and Microsoft are already in the early stages of eliminating the password – this year, all three companies unveiled their Passkeys technology based on the FIDO Alliance’s new authentication standard. But to fully realize a passwordless digital world, websites and enterprises that use usernames and passwords for authentication must add support for new and emerging authentication methods.
In 2023, we’ll see a lot more organizations enabling FIDO authentication on websites to ensure that mobile site visitors have a convenient, enhanced online experience. Of course, individuals who want to login the old-fashioned way will still have the ability to do so. But any person, business or enterprise that has felt burdened by absurd amounts of logins or worried about protecting sensitive data will be motivated to support this shift to passwordless authentication.
And what’s great about the WebAuthn standard, a core component of FIDO’s authentication specifications, is that it ensures compliant users will be able to switch between mobile devices and even platforms with ease, which is great for preventing lock-in to a single device provider.
Preparing for the New Digital Normal
As the future of computing and the internet continues to come into focus, organizations will be well served by taking the steps necessary today to truly secure the technologies of tomorrow.
##
ABOUT THE AUTHOR
As Chief Experience Officer, Tim Callan leads efforts to optimize the customer journey across all aspects of the business. Tim has more than 20 years of experience as a strategic marketing and product leader for successful B2B software and SaaS companies, with 15 years of experience in the SSL and PKI technology spaces.






