White House shortens deadline to delist vulnerable crypto



The White House is shortening the deadline for federal and state agencies to adopt new anti-encryption systems that can withstand cyberattacks, as the administration seeks to protect the decades-old secrets of the military, banks, governments, and the rest of the world.

The Executive Order, called Protecting the World from Advanced Cryptographic Attacksrequires “high-value” and “high-tech” computer systems to move to post-quantum cryptographic key establishment schemes by December 31, 2030, and quantum-safe digital signature schemes by December 31, 2031.

Getting away from the big risk

The new deadline, which for many organizations is closer to five years than the previous one, comes after a recent study showing that the resources and costs of developing cryptographically compatible quantum computers are much lower than what has been previously agreed. In response, Google, Cloudflare, and other companies soon they extended their time by phasing out at-risk systems until 2029.

“The advent of more and more computers, especially in the hands of adversaries, will create a greater threat to the most widely used security systems,” he said on Monday. “The ongoing cybercrime in our country also shows the threat of adversaries collecting information about the United States now, and deleting it later when supercomputers become operational.”

Under a time The National Security Agency published in 2022, “National Security Systems” – a group that includes security and intelligence systems only under the control of the agency – were under the rules to be ready between 2030 and 2033. Many other agencies had until 2035 to complete the change. Now, many of them will need to change soon.

“Therefore, for each system that falls into this new bucket of high-value products and high-impact systems, their transition period has been shortened by 4-5 years (from 2035 to 2030/2031),” said Brian LaMacchia, a cryptography engineer who oversees Microsoft’s post-quantum transition to date. Group, he told Ars. “This is to shorten the time to update the system, and it also follows the changes from Google and Cloudflare that we saw announced in late March/early April.”



Source link

اترك ردّاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *