Showing posts with label quantumcomputer. Show all posts
Showing posts with label quantumcomputer. Show all posts

2025-11-07

Digging holes

Image from Pixabay

"Trenchless technology," it said on the company van. That instantly had my full attention—if you advertise your business with something you don’t do, I immediately wonder: what else don’t they do? But more importantly: what do they actually do?

It was a van from VLTT, short for Van Leeuwen Trenchless Technology. A company founded in 1969 by two brothers. Their craft is drilling. They drill under roads, railways, waterways, and underground infrastructure to install pipes and conduits underground. And they do it without digging trenches. The street doesn’t need to be opened when VLTT lays a pipe.

If it were my company, I’d include something in the name about what I *do* do. Something like Van Leeuwen Drilling (VLD). Because, well, I also use a lot of trenchless technology. In fact, I hardly do anything else. Right now, I’m trenchlessly typing a blog, and when I looked at security incidents yesterday, I did dig through the available data—figuratively—but no actual digging was involved. Anyway, you get my point: tell me what you do, not what you don’t do. By the way, I think Elon Musk’s tunnel-digging company has a brilliant name: The Boring Company. Although I wonder if the employees enjoy telling people at parties that they work for a “boring” company.

In my field, we also use tunnels. These come into existence without digging, even without drilling. All you need is some math. Or more specifically: cryptography. Those tunnels are secure connections over a public network. That public network is often the internet. If you use it to connect to your company—like I’m doing now, working from home and connected to our data center via the internet—you don’t want your data traffic to be intercepted along the way. That’s what a VPN, a Virtual Private Network, is for: a cryptographic tunnel. It’s even a single-person tunnel; only you use that specific tunnel. Reminds me of that time we traveled through the U.S. in a camper. In Zion National Park, we had to go through a tunnel, but due to its round shape, the camper wouldn’t fit. Rangers stopped traffic on the other side and urged me to drive exactly along the center line. Only then would the camper fit through. But I digress.

Because only you use that tunnel, the confidentiality of the data traffic is ensured. But those tunnels can do more: during setup, it can be checked whether you’re even allowed to establish a tunnel to that destination, and whether the destination is actually legitimate. Both endpoints of the tunnel are authenticated: their identities are verified. Setting up the tunnel involves digital certificates—think of them as passports. And you need a protocol, an agreement on the “language” you speak. Examples include TLS/SSL, IPSec, and OpenVPN.

If you use digital certificates, you’re using so-called asymmetric cryptography. This form of cryptography is especially threatened by the quantum computer. If, in a few years, a quantum computer powerful enough emerges, it will be able to break asymmetric cryptography. Your VPN tunnel will then be compromised. Unless the protocol is made quantum-proof in time. That’s being worked on worldwide with great urgency, but organizations must take action themselves to implement everything. That takes a lot of time—probably more time than we have. So there’s urgency.

Still, that term keeps nagging at me. And what do you know? “Trenchless technology” has a Wikipedia page in six languages! My surprise was simply due to ignorance. It’s not uncommon for a field to invent a term that’s not understood outside of it. Back in the day, there were computer terminals that didn’t use a screen but a printer; they were essentially printers with a keyboard. Some fellow students called them “write-printers.” It didn’t make much sense, but we knew what they meant. And that’s what matters.


And in the big bad world…

 

2025-05-09

Meeting the stars

Image from Pixabay
 

I've met stars. Bruce Schneier gave a speech, Adi Shamir and Whitfield Diffie were on a panel, Ron Rivest was an arm's length away and Dave Maasland was sitting next to me in the pub.

You probably only know these names if you are in my line of business – although Dutch readers might know Dave Maasland from his tv appearances. Keep reading anyway, because even without knowing these people you can learn something here.

Ron Rivest and Adi Shamir are the 'R' and the 'S' in RSA. You may know that name from your two-factor authentication, the extra security step you sometimes have to take to log in somewhere. RSA is now a company that makes these (and other) kinds of tools, but originally RSA is a cryptographic algorithm that is important for the encryption of our data exchange. The 'A' is for Len Adleman, by the way, but I didn't see him at this conference – the RSA Conference! Whitfield Diffie, who was on the same panel as Adi Shamir, is known for another cryptographic algorithm (Diffie-Hellman).

In that panel, a number of cryptographers gave their view of the world. Shamir sneered at bitcoin and its ilk: the world would be better off without cryptocurrencies. Diffie noted that consumer products are apparently considered good enough for high-security applications – Signalgate, the affair in which high-ranking American officials were using Signal, was still fresh in the memory. Incidentally, Diffie agreed that Signal's security is well put together. The panel also discussed the threat of quantum computing, which in short means that the security offered by RSA, among others, can be cracked in the future. Moreover, foreign regimes are already stealing our data, in order to run it through the quantum computer in due course. That is why it is important to develop replacement crypto algorithms as quickly as possible, but that is not easy. Diffie: "It's like having to develop an algorithm in 1945 that still works today." Shamir advised, in line with a European recommendation, to use double encryption for the time being.

Bruce Schneier is also famous in our world. He has been distributing his free newsletter all over the world for years, providing insights and opinions on new developments. His speech was about trusting artificial intelligence. Trust is a complicated concept, he argued, especially when it comes to trusting strangers ('social trust'). We tend to considering AI as a friend, but it is a service. Moreover, it is a double agent: it serves both you and its provider. But we have no choice; we have to entrust ourselves to AI. The era of agentic AI is dawning: you’ll have a personal assistant who arranges things for you. The AI agent has access to your email and your calendar and knows everything about you. You do want this, because that way it can support you best. Schneier used a dining reservation as an example. In the past, you called the restaurant, nowadays you make a reservation via their website and soon you let the AI agent find a restaurant and make a reservation. It knows what food you like and when you have time.

So we need trustworthy AI. Integrity will be the main issue, according to Schneier, because most attacks on AI are about the correctness of data. He gave the example of stickers placed on lampposts to trick self-driving cars. Legislation is needed to achieve trustworthy AI, but current legislation (such as the European AI Act) regulates the AI itself instead of the people behind the AI, and that is the wrong way to go, Schneier says. He advocates a public AI model with political accountability, as a counterbalance to corporate AI.

Information security officers are only human, which is why the organization also brought a number of 'real' stars on stage. Such as filmmaker Ron Howard (Apollo 13 and A beautiful mind (two Oscars), just to name two), who was interviewed by his daughter and colleague. Or basketball legend Earvin “Magic” Johnson, who won over the audience with his openness and a motivating story. And finally there was actor/singer/comedian Jamie Foxx, who provided a comical closing note. But he also gave us a pat on the back: “What you do is perhaps the most important job in the history of mankind.” According to him, community is the magic word.

After that, my three colleagues and I, and 44 thousand other conference attendees, returned to our own time zone. Together we made it an interesting and fun week. And the bond between our team and the SOC has also become closer. You did a good job there, JW.

 

And in the big bad world…

2023-12-04

Quantum pathfinder

 

Photo Petra Wevers

The Dutch word ‘kwantum’ easily translates into the English quantum, meaning quantity, although I mainly think of large quantity. This is probably due to the term quantity discount: buy a lot of something and it becomes cheaper. There is also something orange in my mind's eye, and that is due to that Dutch home furnishings store chain with its orange logo, which once started under the name Kwantum Hallen (‘Quantum Halls’).

For some time now, the word has been buzzing around the international IT community in its English spelling. It's all about the quantum computer, that strange machine that came straight from the film set of Back to the future, with its system of elegant pipes that provide cooling. Because the quantum computer likes it cold: in the heart of the machine the temperature is only ten milliKelvin (a tiny bit colder, 0 K or rounded off -273 °C, is absolute zero: it can't get any colder). 'Quantum' in this context depicts not at lot, but rather revolves around minimal quantities.

In addition to its bizarre appearance and the conditions required to function, the quantum computer has another peculiar property. As long as computers have existed, we have been used to the bit: a value that can be 0 or 1 and with which the computer can do calculations. But that crazy quantum computer works with qbits, which can be 0 and 1 at the same time, and everything in between. Until you look at it, because then the qbit has to show its colour. Sort of like Schrödinger's cat, which is in a closed box and is therefore simultaneously dead and alive to an observer, until the moment he opens the box and determines the state of the animal. With those qbits you can perform some calculations very quickly, because you can follow multiple paths at the same time. While ordinary computers work according to the pattern 'if this is true, then do this, else do that', the quantum computer simply does both and ultimately sees where it ends up. As a result, it makes many mistakes, but because it performs the calculations very often, a winning outcome emerges.

I talked about this with our brand new team member Petra Wevers, who calls herself a pathfinder in the field of quantum security. Quantum computers threaten the current way we protect our data which is, to a very important extent, based on a complex mathematical problem. To encrypt files you need keys, which are created by multiplying very large prime numbers. An attacker who wants to obtain the key does have the outcome of that calculation, but finding the two prime numbers (factorization) is extremely difficult. At least, for regular computers. For quantum computers, however, it is a piece of cake. The quantum computer therefore poses a major threat to the confidentiality of our data.

Current quantum computers cannot yet do that. Predictions vary widely, but you often hear that it will take somewhere between 7 and 10 years. Elsewhere I learned that from 2030 there is a real but small chance of breaking cryptography. Breaking RSA 2048 (a certain cryptographic algorithm, with a key length of 2048 bits) is expected to require a quantum computer with a million qbits, while the most powerful known (!) computer has only 433. Oh, you think, so we're not in a hurry. Think again. A lot of information that is confidential now will still be confidential in ten years. Long-term attackers, such as certain countries, are already stealing that information, even though they can't do anything with it yet. But if they can read that information a decade later, it will still be useful to them. Steal now, decrypt later, is their motto. Petra calls the situation we are in now the quantum squeeze. Others talk about Qday or even the Quantum Apocalypse, but it all comes down to the same thing: we have to do something before it's too late. And we have to act now.

We do not yet have quantum-safe cryptography, and the route to it has not yet been crystallized, says Petra. There are stopgap measures. Making keys longer, for example, so that even it will even take a quantum computer a while to figure them out. And – allow me to get specific for a moment – switching to TLS 1.3, because previous versions, which are still in full use, cannot handle hybrid algorithms (an accumulation of different algorithms). In addition, we can also be quantum annoying by frequently changing keys, so that the quantum computers choke in a tremendous workload. And if you as an organization purchase items, include quantum safety in your requirements. Ask your suppliers about their plans in this area.

Governments and science are serious about our safety, says Petra. Such as in the Dutch Quantum secure Cryptography Gov program. Next year, NIST (the American Standards Institute) will publish standards in this area, which are expected to be incorporated into commercial products three years later. According to Petra, it is generally overlooked that soon everyone will be able to work on quantum computers via some website, including criminals. Just as we can now all use artificial intelligence. It is not all doom and gloom: quantum computers, for example, will also help in the development of new medicines and batteries, it is expected. Let's fight to ensure that the positive use of this groundbreaking technology wins.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Getting hosed

Photo: author Summer is my favourite time of year to gather stories for this blog. You travel to other countries and get a taste of other cu...