{"id":1017,"date":"2025-04-17T17:37:13","date_gmt":"2025-04-18T01:37:13","guid":{"rendered":"https:\/\/unmitigatedrisk.com\/?p=1017"},"modified":"2025-04-17T21:53:56","modified_gmt":"2025-04-18T05:53:56","slug":"how-sneakers-predicted-our-quantum-security-crisis","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=1017","title":{"rendered":"How \u2018Sneakers\u2019 Predicted Our Quantum Computing Future"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cThe world isn\u2019t run by weapons anymore, or energy, or money. It\u2019s run by little ones and zeroes, little bits of data. It\u2019s all just electrons.\u201d \u2014 Martin Bishop, Sneakers (1992)<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">I was 16 when I first watched Sneakers on a VHS tape rented from my local video store. Between the popcorn and plot twists, I couldn\u2019t have known that this heist caper would one day seem less like Hollywood fantasy and more like a prophetic warning about our future. Remember that totally unassuming &#8220;little black box&#8221; \u2013 just an answering machine, right? Except this one could crack <em>any<\/em> code. The device that sent Robert Redford, Sidney Poitier, and their ragtag crew on a wild adventure. Fast forward thirty years, and that movie gadget gives those of us in cybersecurity a serious case of d\u00e9j\u00e0 vu.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"900\" src=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV.png\" alt=\"\" class=\"wp-image-1019\" style=\"width:372px;height:auto\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV.png 1600w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV-300x169.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV-1024x576.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV-768x432.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV-1536x864.png 1536w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXeoypnnTFxrrMl_RmV1e0D-TEDxyfasUt7X097qOG7Cnc0VaPhP1rmZHVyd93OyXwzWpUh5QrJTI-fmQ_c8S1HHUlBS-UoBKZ8VKg24EKRA0K8yzfVmrGKCHG1CoDoxTQMTIVsV-624x351.png 624w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Today, as quantum computing leaves the realm of theoretical physics and enters our practical reality, that fictional black box takes on new significance. What was once movie magic now represents an approaching inflection point in security \u2013 a moment when quantum algorithms like Shor&#8217;s might render our most trusted encryption methods as vulnerable as a simple padlock to a locksmith.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When Hollywood Met Quantum Reality<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve always found it deliciously ironic that Leonard Adleman \u2013 the &#8220;A&#8221; in RSA encryption \u2013 served as the technical advisor on Sneakers. Here was a man who helped create the mathematical backbone of modern digital security, consulting on a film about its theoretical downfall. What&#8217;s particularly fascinating is that Adleman took on this advisory role partly so his wife could meet Robert Redford! His expertise is one reason why the movie achieves such technical excellence. It&#8217;s like having the architect of a castle advising on a movie about the perfect siege engine. For what feels like forever \u2013 three whole decades \u2013 our world has been chugging along on a few key cryptographic assumptions. We&#8217;ve built trillion-dollar industries on the belief that certain mathematical problems\u2014factoring large numbers or solving discrete logarithms\u2014would remain practically impossible for computers to solve. Yep, our most of security is all built on these fundamental mathematical ideas. Sneakers playfully suggested that one brilliant mathematician might find a shortcut through these &#8220;unsolvable&#8221; problems. The movie&#8217;s fictional Gunter Janek discovered a mathematical breakthrough that rendered all encryption obsolete \u2013 a cinematic prediction that seemed far-fetched in 1992. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"904\" src=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q.png\" alt=\"\" class=\"wp-image-1018\" style=\"width:346px;height:auto\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q.png 1600w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q-300x170.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q-1024x579.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q-768x434.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q-1536x868.png 1536w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/04\/AD_4nXcXZCl9KpEc6FCzHPw_w1Mme2MTDVRDap6GfzxQhx65geUpzbmOsGw-7WuIWXIRi6JI1eXUWGr6D33Mx6f_1I4CaDJgFibnJ17EagMJwVot84aSvwynFt_RHrJ3M2CMo3-czWEQ7Q-624x353.png 624w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Yet here we are in the 2020s, watching quantum computing advance toward that very capability. What was once movie magic is becoming technological reality. The castle walls we&#8217;ve relied on aren&#8217;t being scaled\u2014they&#8217;re being rendered obsolete by a fundamentally different kind of siege engine.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Real Horror Movie: Our Security Track Record<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hollywood movies like Sneakers imagine scenarios where a single breakthrough device threatens our digital security. But here&#8217;s the kicker, and maybe the scarier part: the real threats haven&#8217;t been some crazy math breakthrough, but the everyday stuff \u2013 those operational hiccups in the &#8216;last mile&#8217; of software supply chain and security management. I remember the collective panic during the Heartbleed crisis of 2014. The security community scrambled to patch the vulnerability in OpenSSL, high-fiving when the code was fixed. But then came the sobering realization: patching the software wasn&#8217;t enough. The keys \u2013 those precious secrets exposed during the vulnerability&#8217;s window \u2013 remained unchanged in countless systems. It was like installing&nbsp; a new lock for your door but having it keyed the same as the old one all the while knowing copies of the key still sitting under every mat in the neighborhood. And wouldn&#8217;t you know it, this keeps happening, which is frankly a bit depressing. In 2023, the Storm-0558 incident showed how even Microsoft \u2013 with all its resources and expertise \u2013 could fall victim to pretty similar failures. A single compromised signing key allowed attackers to forge authentication tokens and breach government email systems. The digital equivalent of a master key to countless doors was somehow exposed, copied, and exploited. Perhaps most illustrative was the Internet Archive breach. After discovering the initial compromise, they thought they\u2019d secured their systems. What they missed was complete visibility into which keys had been compromised. The result? Attackers simply used the overlooked keys to walk right back into the system later. Our mathematical algorithms may be theoretically sound, but in practice, we keep stumbling at the most human part of the process: consistently managing the lifecycle of the software and cryptographic keys through theih entire lifecycle. We\u2019re brilliant at building locks but surprisingly careless with the keys.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">From Monochrome Security to a Quantum Technicolor&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Think back to when TVs went from black and white to glorious color. Well, cryptography&#8217;s facing a similar leap, except instead of just adding RGB, we&#8217;re talking about a whole rainbow of brand new, kinda wild frequencies. For decades, we&#8217;ve lived in a relatively simple cryptographic world. RSA and ECC have been the reliable workhorses \u2013 the vanilla and chocolate of the security ice cream shop. Nearly every secure website, VPN, or encrypted message relies on these algorithms. They\u2019re well-studied, and deeply embedded in our digital infrastructure. But quantum computing is forcing us to expand our menu drastically. Post-quantum cryptography introduces us to new mathematical approaches with names that sound like science fiction concepts: lattice-based cryptography, hash-based signatures, multivariate cryptography, and code-based systems. Each of these new approaches is like a different musical instrument with unique strengths and limitations. Lattice-based systems offer good all-around performance but require larger keys. Hash-based signatures provide strong security guarantees but work better for certain applications than others. Code-based systems have withstood decades of analysis but come with significant size trade-offs. That nice, simple world where one crypto algorithm could handle pretty much everything? Yeah, that&#8217;s fading fast. We&#8217;re entering an era where cryptographic diversity isn&#8217;t just nice to have \u2013 it&#8217;s essential for survival. Systems will need to support multiple algorithms simultaneously, gracefully transitioning between them as new vulnerabilities are discovered. This isn&#8217;t just a technical challenge \u2013 it&#8217;s an operational one. Imagine going from managing a small garage band to conducting a full philharmonic orchestra. The complexity doesn&#8217;t increase linearly; it explodes exponentially. Each new algorithm brings its own key sizes, generation processes, security parameters, and lifecycle requirements. The conductor of this cryptographic orchestra needs perfect knowledge of every instrument and player.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The \u201cOperational Gap\u201d in Cryptographic Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Having come of age in the late &#8217;70s and &#8217;80s, I\u2019ve witnessed the entire evolution of security firsthand \u2013 from the early days of dial-up BBSes to today\u2019s quantum computing era. The really wild thing is that even with all these fancy new mathematical tools, the core questions we&#8217;re asking about trust haven&#8217;t actually changed all that much. Back in 1995, when I landed my first tech job, key management meant having a physical key to the server room and maybe for the most sensitive keys a dedicated hardware device to keep them isolated. By the early 2000s, it meant managing SSL certificates for a handful of web servers \u2013 usually tracked in a spreadsheet if we were being diligent. These days, even a medium-sized company could easily have <em>hundreds of thousands<\/em> of cryptographic keys floating around across all sorts of places \u2013 desktops, on-premise service, cloud workloads, containers, those little IoT gadgets, and even some old legacy systems. The mathematical foundations have improved, but our operational practices often remain stuck in that spreadsheet era. This operational gap is where the next evolution of cryptographic risk management must focus. There are three critical capabilities that organizations need to develop before quantum threats become reality:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Comprehensive Cryptographic Asset Management<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a major incident hits \u2013 think Heartbleed or the discovery of a new quantum breakthrough \u2013 the first question security teams ask is: &#8220;Where are we vulnerable?&#8221; Organizations typically struggle to answer this basic question. During the Heartbleed crisis, many healthcare organizations spent weeks identifying all their vulnerable systems because they lacked a comprehensive inventory of where OpenSSL was deployed and which keys might have been exposed. What should have been a rapid response turned into an archaeological dig through their infrastructure. Modern key management must include complete visibility into:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where&#8217;s encryption being used?<\/li>\n\n\n\n<li>Which keys are locking down which assets?<\/li>\n\n\n\n<li>When were those keys last given a fresh rotation?<\/li>\n\n\n\n<li>What algorithms are they even using?<\/li>\n\n\n\n<li>Who&#8217;s got the keys to the kingdom?<\/li>\n\n\n\n<li>What are all the dependencies between these different crypto bits?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Without this baseline visibility, planning or actually pulling off a quantum-safe migration? Forget about it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Rapid Cryptographic Incident Response<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When Storm-0558 hit in 2023, the most alarming aspect wasn&#8217;t the initial compromise but the uncertainty around its scope. Which keys were affected? What systems could attackers access with those keys? How quickly could the compromised credentials be identified and rotated without breaking critical business functions? These questions highlight how cryptographic incident response differs from traditional security incidents. When a server&#8217;s compromised, you can isolate or rebuild it. When a key&#8217;s compromised, the blast radius is often unclear \u2013 the key might grant access to numerous systems, or it might be one of many keys protecting a single critical asset. Effective cryptographic incident response requires:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Being able to quickly pinpoint all the potentially affected keys when a vulnerability pops up.<\/li>\n\n\n\n<li>Having automated systems in place to generate and deploy new keys without causing everything to fall apart.<\/li>\n\n\n\n<li>A clear understanding of how all the crypto pieces fit together so you don&#8217;t cause a domino effect.<\/li>\n\n\n\n<li>Pre-planned procedures for emergency key rotation that have been thoroughly tested, so you&#8217;re not scrambling when things hit the fan.<\/li>\n\n\n\n<li>Ways to double-check that the old keys are completely gone from all systems.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Forward-thinking organizations conduct tabletop exercises for \u201ccryptographic fire drills\u201d \u2013 working through a key compromise and practicing how to swap them out under pressure. When real incidents occur, these prepared teams can rotate hundreds or thousands of critical keys in hours with minimal customer impact, while unprepared organizations might take weeks with multiple service outages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Cryptographic Lifecycle Assurance<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Perhaps the trickiest question in key management is: &#8220;How confident are we that this key has been properly protected throughout its <em>entire<\/em> lifespan?&#8221; Back in the early days of security, keys would be generated on secure, air-gapped systems, carefully transferred via physical media (think floppy disks!), and installed on production systems with really tight controls. These days, keys might be generated in various cloud environments, passed through CI\/CD pipelines, backed up automatically, and accessed by dozens of microservices. Modern cryptographic lifecycle assurance needs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Making sure keys are generated securely, with good randomness.<\/li>\n\n\n\n<li>Storing keys safely, maybe even using special hardware security modules.<\/li>\n\n\n\n<li>Automating key rotation so humans don&#8217;t have to remember (and potentially mess up).<\/li>\n\n\n\n<li>Keeping a close eye on who can access keys and logging everything that happens to them.<\/li>\n\n\n\n<li>Securely getting rid of old keys and verifying they&#8217;re really gone.<\/li>\n\n\n\n<li>Planning and testing that you can actually switch to new crypto algorithms smoothly.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When getting ready for post-quantum migration, organizations often discover keys in use that were generated years ago under who-knows-what conditions, leading to them discovering that they need to do a complete overhaul of their key management practices.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Business Continuity in the Age of Cryptographic Change<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If there&#8217;s one tough lesson I&#8217;ve learned in all my years in tech, it&#8217;s that security and keeping the business running smoothly are constantly pulling in opposite directions. This tension is especially noticeable when we&#8217;re talking about cryptographic key management. A seemingly simple crypto maintenance task can also turn into a business disaster because you have not properly tested things ahead of time, leaving you in a state where you do not understand the potential impact if these tasks if things go wrong. Post-quantum migration magnifies these risks <em>exponentially<\/em>. You&#8217;re not just updating a certificate or rotating a key \u2013 you&#8217;re potentially changing the fundamental ways systems interoperate all at once. Without serious planning, the business impacts could be\u2026 well, catastrophic. The organizations that successfully navigate this transition share several characteristics:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>They treat keeping crypto operations running as a core business concern, not just a security afterthought.<\/li>\n\n\n\n<li>They use &#8220;cryptographic parallel pathing&#8221; \u2013 basically running the old and new crypto methods side-by-side during the switch.<\/li>\n\n\n\n<li>They put new crypto systems through really rigorous testing under realistic conditions <em>before<\/em> they go live.<\/li>\n\n\n\n<li>They roll out crypto changes gradually, with clear ways to measure if things are going well.<\/li>\n\n\n\n<li>They have solid backup plans in case the new crypto causes unexpected problems.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Some global payment processors have developed what some might call \u201ccryptographic shadow deployments\u201d \u2013 they run the new crypto alongside the old for a while, processing the same transactions both ways but only relying on the old, proven method for actual operations. This lets them gather real-world performance data and catch any issues before customers are affected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">From Janek&#8217;s Black Box to Your Security Strategy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As we&#8217;ve journeyed from that fictional universal codebreaker in Sneakers to the very real quantum computers being developed today, it strikes me how much the core ideas of security haven&#8217;t actually changed. Back in the 1970s security was mostly physical \u2013 locks, safes, and vaults. The digital revolution just moved our valuables into the realm of ones and zeros, but the basic rules are still the same: figure out what needs protecting, control who can get to it, and make sure your defenses are actually working. Post-quantum cryptography doesn&#8217;t change these fundamentals, but it does force us to apply them with a whole new level of seriousness and sophistication. The organizations that suceed in this new world&nbsp; will be the ones that use the quantum transition as a chance to make their cryptographic operations a key strategic function, not just something they do because they have to. The most successful will:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Get really good at seeing all their crypto stuff and how it&#8217;s being used.<\/li>\n\n\n\n<li>Build strong incident response plans specifically for when crypto gets compromised.<\/li>\n\n\n\n<li>Make sure they&#8217;re managing the entire lifecycle of all their keys and credentials properly.<\/li>\n\n\n\n<li>Treat crypto changes like major business events that need careful planning.<\/li>\n\n\n\n<li>Use automation to cut down on human errors in key management.<\/li>\n\n\n\n<li>Build a culture where doing crypto right is something people value and get rewarded for.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The future of security is quantum-resistant organizations.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Gunter Janek&#8217;s fictional breakthrough in Sneakers wasn&#8217;t just about being a math whiz \u2013 it was driven by very human wants. Similarly, our response to quantum computing threats won&#8217;t succeed on algorithms alone; we&#8217;ve got to tackle the human and organizational sides of managing crypto risk. As someone who&#8217;s seen the whole evolution of security since the &#8217;70s, I&#8217;m convinced that this quantum transition is our best shot at really changing how we handle cryptographic key management and the associated business risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By getting serious about visibility, being ready for incidents, managing lifecycles properly, and planning for business continuity, we can turn this challenge into a chance to make some much-needed improvements. The black box from Sneakers is coming \u2013 not as a device that instantly breaks all encryption, but as a new kind of computing that changes the whole game.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organizations that come out on top won&#8217;t just have the fanciest algorithms, but the ones that have the discipline to actually use and manage those algorithms and associated keys and credentials effectively.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, let&#8217;s use this moment to build security systems that respect both the elegant math of post-quantum cryptography and the wonderfully messy reality of human organizations.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve adapted before, and we\u2019ll adapt again \u2013 not just with better math, but with better operations, processes, and people. The future of security isn&#8217;t just quantum-resistant algorithms; it&#8217;s quantum-resistant organizations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cThe world isn\u2019t run by weapons anymore, or energy, or money. It\u2019s run by little ones and zeroes, little bits of data. It\u2019s all just electrons.\u201d \u2014 Martin Bishop, Sneakers (1992) I was 16 when I first watched Sneakers on a VHS tape rented from my local video store. Between the popcorn and plot twists, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,4,1],"tags":[],"class_list":["post-1017","post","type-post","status-publish","format-standard","hentry","category-security","category-thoughts","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/1017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1017"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/1017\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}