
HN842: How Network Engineers Can Prepare for a Post-Quantum World
Get every episode summarized
Each time The Everything Feed - All Packet Pushers Pods publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
“If you hear the song ABC by the Jackson Five and you mentally substitute BGP in your head, you found the right podcast. I'm Drew Connry Murray, Ethan Banks is away, so Scott Raban is joining as guest co-host.”From the transcript
Get every episode summarized
Each time The Everything Feed - All Packet Pushers Pods publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
486 searchable segments. Every word is indexed and playable.
Full transcript
The Everything Feed - All Packet Pushers Pods — HN842: How Network Engineers Can Prepare for a Post-Quantum World. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Welcome to Heavy Networking. If you hear the song ABC by the Jackson Five and you mentally substitute BGP in your head, you found the right podcast. I'm Drew Connry Murray, Ethan Banks is away, so Scott Raban is joining as guest co-host. You can hear Scott on the Total Network Operations Podcast right here on the Pack of Pursures Podcast Network. On today's show, we're going to dig into post-quantum readiness. Now you may have heard of Q-Day, Q-Day signals the emergence of a cryptographically relevant quantum computer that can break public key encryption. Q-Day itself is actually unknown the date, but the tech industry is making preparations now. Network and security vendors, the big browser providers, cloud companies, they're all rolling out support for post-quantum algorithms. So on today's show, we're going to dig into post-quantum cryptography or PQC. We'll talk about what network engineers need to know to test and integrate post-quantum algorithms into their infrastructure. Why organizations might want to think more broadly about things like crypto agility and more. Our guest is Bill Dockery. He is consulting Solutions Architect at WWT. He's been thinking, writing and talking about post-quantum cryptography for network engineers.
He's here to share what he's learned. We're going to spend the first part of the podcast on level setting and then move into what's relevant specifically for network engineers. No, we'll wrap up with some big idea kind of questions. Fonser Itentials Flow AI delivers agentic operations for infrastructure, meaning easily build AI agents that actually work the way engineers need them to governed, terministic and built for production. Add intelligent automations to your network operations without the usual AI chaos, find out more at itential.com slash flow AI. That is itential.com slash flow AI. So Bill, welcome to the podcast. Just to kick us off, how does quantum computing put classical cryptography at risk and one of those risks mean for organizations? Yeah, well, thank you for having me here and answer those kind of questions. So quantum computing is going to basically crack what we call classical cryptography. This as RSA is at risk. And so with that, you can basically take a encrypted communication that you would typically use today and determine what the private key was and in doing so, we work through the entire conversation itself and pull all the data out from between it.
And what it takes there is it's a different mindset. The reason why cryptography today classical cryptography, we're going to be calling that correct classical from here on out. The reason why it's so viable is that data has a life cycle. And for RSA with traditional computers, the way they operate the way they act, the way the operating systems are built and the way GPUs work in general, it took a lot of time. It really was a time thing, right? It was it could be as long 100 years, 1000 years before someone could crack the encryption on a particular communication. And that all changes because quantum computers are very different in how they work. And because of that, they could do a little bit of different math. And the one math is, you know, a little more powerful than the other one and they can take this now to classical cryptography could be cracked and they're saying minutes, right? You know, within within a very reasonable amount of time for a hacker wanted to do something malicious, very reasonable amount of time for them to do that stuff. And so now when you consider the length of data viability, the life cycle of the data itself, that's not good.
So can you explain at a high level why quantum safe algorithms aren't susceptible to attack by quantum computers? Yeah, I'm coming back to them. Honestly, the Plank Spoked Cryptographer Yublin, tell me how used to prime numbers as the basis for the foundation for how the math became hard for a GPU to crack. And it just would take in the like that's right. I mean, they didn't have an algorithm that just to do that algorithm would have taken forever. And the new PQ, like let's say ML, the math in there, when you look at RSA, which is the classical side of things, it was basically multiplying prime numbers together. And it really hard to factor backwards. And the new one ML, the best way I could describe it, you know, to make it layman's kind of terms is the way it was explained to me, because I am a lamb is that, you know, the ML, it actually introduces noise. Right. So it's not the same foundation right. It's just a bit of noise that can be taken out on the far end, right. So you can actually have the conversation with another host.
And that complete different process is difficult for a quantum computer, because I think maybe one good misconception that people have is that, you know, quantum computers is not just the computer you have on steroids. Right. There are things that GPUs are really good at the kind of math that they do, right. And that's why we came came out with GPUs and all sorts of other co processing. You can kind of think of a quantum in the same layer that it does a lot of overlap, right. You can get the new analyses, right. We used CPUs and GPUs to do analysis. The new quantum stuff is going to be able to do different types of analysis. And so where it's strong. This is just one of the areas that it's really strong when cracking the RSA prime numbers, kind of things. So just we stay away from it now. New math has to come about. Right. I'm sure we'll talk about that in a minute like, you know, new ciphers. That's the thing that's going to be coming out. These new ciphers are basically built on different techniques, you know, mathematical techniques.
So let me some some of for another layman, you know, not primarily a security person, but it's not just bigger prime numbers. It's not just bigger crypto keys. It's inserting techniques that mess with the math, the quantum computers are good at. Yeah, it's a quick analogy for that is, you know, ML chem is it's adding noise. The one of the ones that's out there, the SLA DSA. It's it's using a bunch of hashes. So it's the methodologies are completely this can. And I did that on purpose. We need more ciphers to keep doing different things because the expectation is that the quantum. Well, maybe someone like sure some of the smartest Peter can come out and find the new algorithm inside of that to break that new that's life right there today. So you shouldn't expect ciphers to live quite as long as they have today. That's one of the big discussions will have. You're referencing sure who develops shores algorithm, which like mathematically prove that these classical cryptography was vulnerable to quantum computing.
Right. And you know, to that point, you met a Q day. The Q day is a cryptographically relevant quantum computer. Right. So it needs a bunch of qubits. They don't have enough. They don't think they have enough to implement shores algorithm. And that's where Q day comes from because there are quantum computers today, right. And they are doing things with them. They're they're making advances in science and medicine all sorts of great things. But the cryptographically relevant version of it is what's coming and that's the big point of it all is that it's going to it's going to keep adapting and building and it's honestly. If you look at cryptography, just you know, take a step back for a second. Cryptography is really is arms, right. It's literally you're not allowed to send cryptography to another country that you're not copacetic with, right. We've got a couple were an odds with right and you would never send them that piece of that. So it will be an arms race and they are developing their own and we're developing ours and they're attacking ours and we're attacking theirs.
And you know, it really is that piece there. So for most of us who aren't in a antagonistic situation, right. Most people trying to serve businesses, you have to go along with it, right. You have to follow along with it because that's that's the other part of it. The other people are in scent of a little different way. I very much remember when because versions of software with those ciphers, you know, we're on export restriction lists. I was attack engineer, you know, what a major router manufacturer and it's like, yeah, customers in this country or this region of the world couldn't get this version of software because it had had those export restricted ciphers and it's seriously. Yeah, it's dead on people forget sometimes that cryptography is how we stay well confidentiality integrity and availability of the CIA thing, right. If you're security guy, but I know we're talking about a network guys, but security first thing they teach you is CIA confidentiality integrity and availability and we care about that as network guys, of course, right.
We actually want to implement most of that the fun part of this. And that's why I wrote this discussion. Why I have this discussion a lot with the network engineers is the. The C so and his team are recognizing the issue confidentiality. How to make concrete conversations private, but it's cat it's writing a check that the network guys have to cash right. We we are the ones that do things like they'll be always that way. It's all it's not just security thing. Well, sorry, sorry, you touched. I'm sure we got a lot of heads nodding when if they're hearing that yeah, definitely right we were the Cape as network guys, I should say my background is really CCI and but I became more of a security guy later on. I'm a network head. And it's always been we are expected to the where the Cape and where the application might not be inconsiderate us right. When we talk about how fast people can move we're talking about agility and there's agility of all the places we need to be agile because you know what if we're not the most nimble ones the applications are likely to fall behind. And it's always been the expectation in my right experience and then life right to put the bidding cryptors online and cryptors, you know, to make sure that even if the application failed its job, we were still making sure the confidentiality was there.
And I think those expectations are probably going to be even a little more intense. When you consider everyone trying to bring up the tail right we just talked about the arms race and a new cipher and a new cipher and I guess we'll expand upon it. But you know, I think that the first place that it really does have to happen is legitimately the network because again, the business partner connectivity, you know, what's going out of our DMC's right when we do them because a lot of network guys actually tend to own the firewalls and the low balancer. To at least in the sense of, you know, we manage them and you know they they love the one the policy, but they love to make us do the work for getting yourself certified and implement it right. And so you kind of get my draft right where I think we're all smiling on that one there. So how for folks who have a lot of their plates already lots of projects, maybe lots of long term projects with Q day being an unknown date how pressing is this issue of quantum readiness. So the indicators are definitely pretty pretty broad. I'm sorry, actually very discreet that's probably better way to say it. So you have things like Google Google has challenged themselves to 2029 and and not that they have.
I mean, obviously I'm more information. They're big information. I'm worried, but I'm sure that that's but that's something you should assess in your own mind because this is going to come to how do I sell this to my organization. How do I get the funding and things in there. So one of the places you can quite do is definitely there, but the Google is anticipating Q day emerging in in sometime in 2029. Yeah, exactly. And I think that they're expecting it to be a little later. They want to be ahead of it. So I think they're being very responsible. So look at that. Right. Here's a very responsible organization. And that is looking at 29 is like a very very viable day for us to get things in place. The two new executive orders came out in June. I think it was June 22nd. They doesn't matter, but 14 412 and 14 413 were the two that the government themselves just sent out. In fact, we have the 23rd today. Why that's relevant is yesterday. I think was the deadline for all of the little three letter organizations and every organization in the government to a point they lead for PC implementation across the entire government.
And that's not that was the 30 day one. That's in the first of first one of the executive orders and they're taking very seriously and they say in there that we want to see you doing signatures by 31. So that's that's the end goal. There's some little things in between but the end goal. So basically you can say the government themselves is pretty much put a line in the sand that they within the government you had by 2031. Why is that super relevant, especially if you're like a bank and you're clearing your transactions. I come from global finance, right? I've had a lot of banking stuff. I worked for some banks for a long time longer than I want to admit. But you know, the government and is going to be implementing it. It's not like we're maybe V6 like they are going to implement this by 31. If you're not doing it by then and Q day maybe hasn't happened. We'll talk about what Q day really means. But if Q day hasn't happened publicly, then you're a bad way because how are you going to transact with the government that order is going to see that right away. And I can tell you now 2031 is is depending on your organization. It might be considered aggressive. And it's not a small task. This is a very, very large task. This is why again, I've been prepping a lot of the clients that we work with, especially the ones I know the most because I'm working with friends at this point around global five worked in banking for a long time.
I'm working with friends like, hey guys, we got to get on got on the hook on this one. But a quick one less mention on that moment and close this is the second executive order basically says that the government themselves is highly interested in quantum computing. Like they they really see that quantum computing again is another arms race itself. Right. We talk about AI a lot. AI takes all the air out of the room. Right. And then you get in the quantum quantum takes all the air out of the room. Now we have the mythos thing. And take it all the air. Me, even more air out of the room. Yeah. Right. I was in the stratosphere trying to breathe. And then there's PC in the bottom of this. But yeah, the government is looking at quantum computers because they they realize they're going to need that to do the same. We talked about the cipher. The cipher is being elevated and changed and moved around to keep confidentiality. That's that's the reality. What's going on. So again, start by 31 is a. So the thing is even if Q day doesn't emerge by 2031 there is a line in the sand from the government saying we need to support.
PC for digital signatures. So if you do any kind of business with the government. So do you. Yeah. Hello exactly. Right. And at that point, the expectation beyond everywhere. Right. The, not just the government. I mean, well, the government makes me do this. Why are you not doing this? Are you afraid that why are you not right? So there's, there is a little bit of the. You got to get on the bandwagon and I mean, maybe there's a little bit of faster. But this is not V6. Don't consider that right? I actually had a little back and stuff on that internally. Yeah. Yeah. Right. You know, this is not this is not easy. V6. Things to work with out V6 and the government made that. And the reason why this comes to mind is. You know, the government had some eDix about V6 and you know, you know, eight of your old amount of remember some coding stuff. They make a lot of eDix sometimes. But this one. This one's no joke. And I hope to make that serious enough enough for persons to realize that this is truth.
I mean, eventually we're going to. You need to do this everywhere. When I say everywhere, we'll talk a little more. I guess like, a lot of you asked more questions before I just run this one long bill speaks. So just just a couple comments on the dates. So you know, nothing nothing motivates action like a deadline, right? So having deadlines, whether it's 2031 or 2029, you know, at least there's something. There's a line in the sand. There's a target to go after. You know, I would I would argue that, you know, we are dealing with probabilities here, you know, because Q day is unknown. And we may not know that it's Q day when it arrives. Right. You hinted at that a little bit. There's a quantum joke in here somewhere about the probabilities and the unknowns. But well, the quantum joke is both funny and unfunny at the same time. So. But so I don't think we could be too aggressive. Whether it's 29 or 2031. You know, where if we can move those things up, great. But implementation adds another wrinkle to this. And we'll see where we go on the front for the rest of the conversation today.
Oh, yeah, especially with large organizations. But you know, the thing about Q day not being known. If you know some mystery, you know about the enigma machine, right? You get into security classes. They always talk about the enigma machine, right? And what was it, you know, the the the access had a device that could keep their confidentiality. And they didn't know we hacked. Right. And that was what happened there. So when I say Q day publicly, we have adversarial persons in the world. And the world in the globe, right? That may not be copacetic with us right now. And we can leave it out names and trying to stay very far away from politics. But note that we're not friends with everyone. And some of those persons are trying to build quantum machines. The same thing that the second executive order to keep that right. They you think they're going to tell us when they get there before we do. Q day could have happened. And we wouldn't know depending on who who reaches that right. Yeah. The only reason why I think they're confident on that right now is the technology. The number of cubits is not quite there. But I'll give you the give me another maybe a little scare. And again, I don't want to scare people on here. I think the purpose of this meeting is a really good people aware. So they act correctly.
Yes. Yes. Or appropriately. And is that AI is helping a lot of things advance. So I went to this quantum tech world in Boston just in June time frame. And again, short was actually there. A lot of people who stood in line to get pictures with them. Diffie home and the different the gentleman. Diffie was there. I did get a picture with him. I'm a little bit of a geek to security side. But AI does seem to be advancing quantum. And I saw the three things that that that made me feel confident that that's a true statement is that there are more and more cubits showing up right. The road maps of the OEMs are going to add more more and more cubits. And that's what we need to be to be a cryptographer cryptographically relevant was that was a big one. Right. Then I saw all the things they're using quantum even more efficiently there. They're learning how to get the standard algorithms that run on CPUs and stuff like that. But now the work in the quantum world. They're doing more with less. So what we expect cryptograph cryptographically relevant thing to need might shrink. That's just my intuition. I want you to take that is a bill ism.
So they're doing more with the less that they have. And lastly, the big one is on the error corrections are getting better. And what that really means is I won't say that they're more accurate. I mean, accuracy is about algorithms and running math. But what they are, they're probably more reliable. Right. That when it's an item, right, when you do it, you do it the same way comes out the same way. That's the error correction part of it. So they're getting more. Is that efficient? So I want to say accurate. I don't know reliable. We'll leave it on reliable in the sense of the math that the computation that it did is becoming more reliable. You factored these three things in and 29 and 31 should be definitely hard held lines in the sand. So just to make sure we're all understanding when we talk about post quantum cryptography, what aspects or elements of classical cryptography are affected? Are we talking? Is it all public key based? Is it symmetric key based? And that will inform how we need to think about what to do in our infrastructure. Yes. Yeah, you hit it on the head. So I'm sure when after RSA, right, the public in private key, everyone was kind of familiar with that. That's called asymmetric encryption. Right. I, you see my public key. You can send things to me that only I can undo. That's not the same as symmetric. So AES, the world were familiar with us as never engineers. Right.
That is a symmetric encryption where the keys are on both are known on both sides. That's where our PSK's are pre-share keys all come from, you know, in TLS and in a lot of other methodologies for building an encrypted tunnel. Like if you know, if that kind of stuff like that, they are using that prime number based math. So sometimes if you human, they call it a lift to curve here, you're lift to curve, right, that's part of the the math on building to feed home and sharing over an open line. How do I, how do we both derive the secret that we're going to use on that encryption. Right now, sure is algorithm takes care of the front part. So in like TLS, what's the first thing I do? We see these packets, you know, you say, okay, I'm a client. I would, I would like to do these algorithms. This is what I'm capable of. And, you know, let, let's set this up. And I have real summer like stats. Sorry. I'm boiling this down to be quick. Right. Here on the client. Here's what I can do because, you know, you don't know the client cannot, cannot do every site for yet. Right. Here's as a client. Here's what I'm capable of. Here's what I like to do. Mubba boss. Then the server comes back with let's come back with. Okay. Well, here's what I would then here's what we're going to do. And here's my serve. Right. That's served as a tool.
And here's what I would say is that the public key portion of things and of course that's based off of pkis of the client. Trust the route, the CA, right. The certificate authority that this certain was given to, you know, as kind of the third party to build the true to trust here. Okay, great. I accept that. Let me take it over here. And let's start negotiating what that what the key is for our symmetric encryption. That's where a a a a a s comes from now. Hopefully with short algorithm attack the asymmetric the pkis stuff where the actual key is established for the other. But even a s has been under attack to there's an algorithm that has weakened it significantly. And when I say, okay, it's kind of funny. It's just awkward the way they do this. They say you have a thousand might keep. But it's a strength is only like, you know, 500. And that's really what it's done. The algorithms that are following right now have not cracked a yes. They don't think it math. I'm okay. Crack it. But it does. It makes it. It reduces the time by saying a thousand by key of 500 by kids really. It all comes down to how long can it be kept private. It's it's like how long before your friend tells on you, right. That kind of thing is is really where cryptography gets its confidentiality from.
So we have attacked it. But that is a yes is still viable. So and that's a really good thing when we consider that, you know, we're not really not changing the flow of the transactions. We're not modifying things that are really modifying just the first aspect of it is setting up the encryption in there. Okay. So we're talking about when I'm thinking about where post quantum cryptography is going to come in to my life. It's around things like digital certificates digital signatures that kind of stuff. Things related to asymmetric encryption and public key infrastructure. Right. Because if you think about signatures, which is a huge part of just validation. So identity. I mean, most of the identity is basis way. It was secure boots, right. We're looking at certificates to acknowledge that a router's part. My SD win environment, right. So all those things come in there in signatures, right. That I have my private key. I you can I can, you know, math and I can encrypt technically I think it can encrypt a cipher text give it to you. You can unencrypt it and go, yep, that has to be him because he's the only one we have the private key. That's its signed, right.
Our entire, you know, trust infrastructure relies on certs and signatures. Yeah. Thank you for the words I couldn't find you said it so well. That was that's, you couldn't send it any better. The entirety of that is based on this. And that's why when we say this, you know, I kind of skip ahead for a second on the question. Yeah. You're going to ask me is, you know, how do you sell us to people? Well, essentially quantum quantum when it attacks this, it basically kicks the s off a HTTPS. And I really want that to sink in, right. Like this is the best way I think that you can explain this to lay persons at the board level, right. It's not their job to be technical, right. They don't shouldn't have to. But I think that it makes it really poignant. Really, you know, they understand the gravity of this when we say, you know, would you do your banking with that little lock wasn't on the browser. Because we're taking the s off. And that block might say it's there. But, you know, when Q day happens that they haven't told us it happened. Basically that locks broken. And you don't even know it. Right. And we can't be there. You can't do a lot of transactions. How do you do business that way?
How do you obviously defend your country, all that kind of stuff like that. But, you know, how do you do business in that manner? Do you trust that the person in the middle, the man in the middle attacks become viable. And that's when we talked, we don't know if we did talk. We talked a little bit about gathering data and the harvest now to quit later. Harvest now to quit later is grab the data from someplace and get it. And obviously that's not scriptkitties, right. This is a little more serious. That's my nation's state. Bingo. Hey, can you think of any sites that you might have a lot of interest in getting data from even if it's encrypted that I'm known five years from now I can unencrypt. I don't know. A lot of people put the stuff in cloud right now. Children, documentation. You know, like there's a whole ton of things are code. And hammer away at it in my back end infrastructure. Yeah. Yeah. Right. If I had a year's worth of that stuff, how many different organizations do I have intense amount of data that I can extrapolate interpolate later on and then do the things like, you know, when you think of security, it's more than just a bits and bites.
You know, everyone knows how fishing, right. And, you know, and, and you know, they're targeted fishing, right. The people are going to try to get someone and know enough about them. Think of identity theft, right. And because we just mentioned identities everywhere that when we were just talking pretty much about the vice identity. But personal identity. And how do I walk into a back and I say I'm, I'm Joe X and I know all the transactions that have happened. I know all the account numbers and all the names and all the things that have happened for five years, right. You know, that's the, that's the seriousness of what, what happens when people have access to that data. So Harvard's not equipped later is really really bad. And I think sometimes I had someone actually tell me like, we're not worried about that because I'm like, why not. So well, the data in this channel is not relevant for that kind of the hacking that could happen there. The risk is not high. I disagree with them. But for most of us, that's not the case. So that's why I'm bringing that up there. The second thing is we just talked about the fake outs. But there's a trust now and and and forge later is the second big thing that gets gets talked about when you're in the quantum this preachy spectrum that I've been in lately.
And you know, when you can get the private key and you could be the man in the middle. And we all know about that, right. Interesting. Okay. Right. How bad is that? And when if Q day happens, you don't know about it. And like, how do you get the man in the middle? Because I could forge your signature. Right. I can say I'm you. And then I could put it back in and send it to the other side. And send it to the other side and not even interrupt it. Right. Right. Like that's always been the dream. Right. From a almost have a wire tab as a hacker. I basically have a wiretapping there. And even worse, I can even assert and mongering between. You know, so you think you set up a secure communication with a business partner or a cloud provider in your sending sensitive data. When in fact, that there is an adversary in the middle, who's forged that private key and is watching everything, even as they pass it on then to its final destination. And you have no idea. Done. Right. That's that's what those different tools you are in the security classes are there for right. These these proxies that can do this kind of thing front for one and the other. You know, it's it's pretty serious. It's incredibly serious. This is why PQC is I trying to get that out there. When you take the S off a HTTPS. What does that mean to you? And that should mean a lot of scary things.
And everyone should be able to interpret like that to whatever they they're important like whether to use in VPNs to go sites that they know what people know you're going to. Or you know, you're actually conducting the rational business and you're doing strike because you have a business on a food truck or something like that. Everything in in between. Right. Even just going to social media. What do you like to enjoy and see and keep up on even those things become very graphically open. No confidentiality. So can you level set us on what is the list? You know, crypto algorithm assessment process look like. And what is it? What does it mean when this says this is approved. And I know that could be a couple hour conversation. If you give us the thumbnail version. Yeah, I think that. I don't want to say they they approved the what they do. Or the tips right. So it's a recommendation at the end of the day. So what the government does. And what other governments are doing too, by the way, because this is, you know, US base. There's Canadian and name a country. They all have their own encryption that they're trying to use. In fact, I'm sure even our government.
We have a encryption that you and I, you know, that we three and the people listening this. They don't see that. That's all government based stuff. Right. We're talking about arms there. But what the government does to make a general populist work on this thing. So we could do international transactions. So people can work with a US standard. That's what they try to do. They publish standards for this. And it starts with a. Hey, we need new encryption ciphers with different math with different techniques. And they basically put that out to the world. And it's competition based at that point. And what they'll do is they'll receive a number of submissions for, hey, I think I got a great protocol, you know, cipher for this. And, you know, I think those people are encended by the fact that I think they'd be famous in a way, right. And they want to do good for the world. Right. A lot of good things behind their mindset. And they'll bring up the new ciphers. And then it basically they'll they'll narrow down a bit and publish them and make sure that the world. It's almost like open source in that sense. The same logic behind if everyone has access that everyone can beat it up. And every one of us together is smarter than any one of us. Right.
Or so it's kind of open process with cryptographers, computer scientists, mathematicians to kind of bang on these algorithms and see what can stand up to scrutiny. Yeah. And that's a multi-year process, right. It's not a quick thing. You know, but they have a lot of them in the hopper right now. Right. There's another. We were mentioned a couple today, right. HC M.O. Cam, right. M.O. DSA stuff, the Falcon. Those are the ones that are established right now that went through this process we talked about. Right. People may submissions and they put it out to the world and people weren't able to crack it yet. And and this is good. Here's how here's the standard the OEMs then grab that and it's on them to do the delivery. And so the government also has insight into the fifth and the fifth and the fifth and the fifth and the standards and this standards give you here's the algorithm and hear the parameters. Yes, but coders actually have to put that in code that goes on hardware that sits somewhere out in the deployed world. You got it. Right. Yes. That's where the government's liability is. That was of course there. They're monitoring stuff and it was the right. That's where you hear on your C. So and the is organization.
I need to say this as a network guy, right. I should be agile enough to put any cipher out there, but I don't want to be the guy to pick it. That's a policy decision. And that should be the security guy. Yeah, right. I support that statement. Yeah, I'm with you. Yeah. But I'll tell you I've had a lot of discussions where I had the network and the security guys in the in the room and I'm like. Guys, this is a relationship. You know, you're you're partnering on this thing here, but this is really should be the way as a network guy when I put my network hat. I'm thinking that I got to get out there as fast as I can. Well, we'll talk about hybrid and why hybrid is a pattern in here, but I get it out there in relevant time. So it's still good. But if I'm not picking the ciphers, that's your job. And that's and that is like you to the question you ask, like how is this doing this? How does the US do it right now? Same way in other countries. That competition. Get it get it to a standard and let the OEMs implement them. And of course there's always a look at the implementation as well. I think they they're looking at OEMs. And so are we just as customers, right as banks as restaurants as everything under the
side, right? We ourselves are also looking at this. That's what the I sac as you like the information sharing environment. So I'm scared like, hey, dude, this is not working for us. Right. And it goes everywhere. I mean, so that that's the gist of it. That's how it gets done. And mindful that there. It's going to be always happening. And this is another key implementation thing. It's happening over over. It's going to be iterative. We're not going to have a 20 30 year cipher in the in the same sense because I think that's the way to get it. Because we're not expecting it. Right. Quantum and AI together seem to be making advances all the time. I mean, heck it's it's built some we've discovered some new math that we weren't able to do is just without AI. And we expect more that. We'll get into that notion of crypto ability a little further in, but I just want to cover the my understanding is NIST has for they finalized for post quantum ciphers. Can you like give us a quick overview of each one and what they're for. Yeah. Yeah, there's four, but the way to be smart. I'm really worried about the well too for the most part here. So the first ML cam, right. So the key exchange manager that that first one, these people called Kiber.
So they use that old old names, right. It was Kiber, Dalithium, Spinks and Falcon. And I think that the people that did this must have been sci-fi fans. Because I think a Kiber crystals and like Star Wars. That's right. Yeah. But there's a set Star Trek and Falcon. Mill and Falcon, right. Okay. That's good. But this thing's, this thing's plus was more government issues. So I didn't have that much, you know, backward humor, you know, and homage. And so ML cam is the basic one you're going to see everywhere that that seems to be the standard right now the 768 version of it. A certain key size on that one is going to be the big one. So if you could say ML cam, you're, you're pretty current. ML DSA is the signature part of it. So, you know, making a encryption is good, but you still have to do the identity aspect of things. So all the identity stuff we mentioned signing and that stuff. ML DSA, they're built on the same math. I barely comprehend it. And I don't, I maybe I don't really, you know, I, but you don't really need to, right. The big part is if you could say ML cam and ML DSA right now, you actually have the PQC stuff in mind. Okay. They built sphinx. They built the built the S L H DSA to the hash based one to be an alternate. And those were in competition. We talked about the competition out there for different ciphers.
The, the sphinx one is, but the keys are huge. We'll talk about why that's bad. I'm sure right. And there's a little bit here, but the keys are huge. That's how they win the competitions. Right. Why am I going to use one of your, how hard is it for a CPU to do the math and how, how weighty is this going to be when I implement this on when OEM implements it and I'm loading it and I'm configuring it on a device. Right. How's that going to affect things? How big are the keys, you know, there's, there's a lot that goes into, you know, why gets one ranked above the other, but that that third one sphinx is a backup right now. They're trying to come up with yet another one. This goes back to the iter if thing. Right. HQC hamming quasi cyclic. I haven't even looked into it. I'm not sure exactly what that all means, but there's this HQC thing that is supposed to become the actual the next alternate for MLK, because sphinx is very weighty. They, they, they realize that that's going to be very difficult to move to. And the last, the fourth one is Falcon. And it's actually a use at last resort. It's, it's really because it's very lightweight.
The IOT, right, at the bane of existence for an or guy right IOT right. It's actually for. Right. So the love for for all the little devices in the field. Come on, man. Yeah, right. Then with, with no updates that don't have a lot of CPU and very little battery. And don't deal with bandwidth or well, right. All that stuff. That's why it's optimized for smaller signatures, right, because those low processing capability devices that are running on a battery for 10 years, right. You, it, it, it, it, at least improves their protection level somewhat, even if it's not the full hash length. Yeah. Exactly, right. Again, what the, what we talked about earlier, the, what data is in there, right. And you would hope that you don't give it a lot of time. It would take them maybe hack some of that, that data is not like a banking transaction that needs regulatory seven year right or governments. I'm 30 years, right. We are hoping that the IOT where it makes sense there, the data in there is in the person's comment to me like the data inside that stuff stuff that important.
I don't care about, you know, harvest down the crib later. Okay. That's that's really the my step behind is logical. It's not just because it's weak or something like that. But those are the four ML cam, ML DSA again, those, those are the two big ones you're going to be using. So, these things hopefully will never have to use that when I tell you about the key sizes could be like nine K. Sphinx is the right DSA, right? Yeah, S L H DSA. Right. That's, that's the things. Well, that's the L H DSA. Thank you. I was used the old term. See, that's, that's, we've been in this awhile. They're trying to eliminate those names and it doesn't go. They stay easily. Yeah. At all. That one's hopefully be a backup. You're going to see a different one. The two of seven, the two of seven, the two of seven, the HQC will come in likely before that one. And of course, the Falcon, we just talked about, which is the FN DSA and just give it the FN easier to remember. Okay. All right. So keep an eye out for ML Cam, ML DSA is you're doing your new research. Yes. All right. So let's get into the second part of this, which is about the impact of post quantum cryptography on network infrastructure.
Obviously, we've talked about larger key sizes. So that sounds like it's going to have an impact on day to day things like handshakes, packet sizes. So what, what should network engineers be thinking about? Yeah. Yeah. You hit that. That's exactly it. So now the rubber meets the road. I, we got to do a security thing. Here's the network impact. The key sizes. Even ML Cam, the 768, when the time it's done, the keys themselves are about one K size. And what time everything's done with how the things go through. I'm sorry. I'm skipping a lot here. All right. Just, we're only a too much detail on this one. But suffice to say that when you start passing these packets, it's going to take potentially two. Right. When you used that like 32 K key. I'm sorry, 32 by keys. And it's 30 times that now. Right. You got a full ethernet packet. And then with, if you go to even ML Cam, the 1024, the actual math that goes in there, when you only have like a 1500 byte payload for, you know,
for layer three inside your ethernet frames, you're going to need to do two ethernet frames. And that takes time. Right. It's just physics. If you put it in terms of that, what is it going to take a long to do. And then when you consider some of these keys, if you tried to send this as a singular packet, the MCU sizes in places, if you send this across a, you know, like a carrier network. And it's dropping packets because it doesn't like the fragmentation on UDP because some of this stuff does run on UDP. You see if sec fail. Right. So yeah, exactly. DNS when DNS sec comes about, it's going to be a problem for us because DNS is, you know, predominantly UDP. I mean, a lot of TCP inside of DNS. But even in DNS sec, but where your place is where the packet fragmentation, you might be dropping packets. And to put the two together and all the sudden, hey, I just tried to get to my, I just tried to get the lock working on my browser. And I'm trying to connect into connections, take it forever. Why? Because I'm have to send like two two packets on the setup. And when I'm sending back a certain we'll talk about the most certs now are hybrid certs MLK plus what they call X25519, which is classical.
That's a little bit of a curved Diffie homin. So X25519 is not scary dude. It's just classical classical and the are post quantum come together. And your cert is about 4k. That's three packets. No, right. Unless you're just changing the cert or just to send the search. Just to change the certain. Yeah, just to send the cert one right. What if you had a cert chain that you wanted to express to something. Right. Some applications do that. Now it's three and four certs to to to to to to to to to to to to and that has to serialize. The transmitted get to the other side. And you know, depending on on is this going to introduce it's not latency. But it's going to it's going to ensure it's going to feel like latency because that transaction is is going to take it's definitely impacts connection setup time. Right. And so I can't click pay until I can you know log in and it locks. So let me if I were to summarize this. There's there are there are advantages to getting smaller keys, especially when away I need to exchange multiple keys and it given cert to keep the cert length down.
Right. Minimize, you know, loss. However, like in engineering everything's a trade off rate. Those smaller keys may not provide as much protection as the longer keys. Exactly. And there are no smaller ones in this like these are going up that range and you know that hybrid model where you have two different types of crypto. What they do. They call it hybrid. I really would call it concatenated. But it really is like happy. The entire you can have half a key. You either have the whole key. You don't have the key. They were you haven't hacked it. Right. So what they've been doing is basically taking you know here's your X to four nine married up with ML cam and together that becomes the key. Now the beauty of that is that you know classical encryption might actually outlive ML cam. We don't know right. There's still there's some worry in there. But classical man say for sure how about the next the next TQC type algorithm. So let's say HQC is another one coming up. So we have ML cam next to the other one. So PCC and PCB is next to each other because one of them is going to get hacked.
And the reason why I say that is and this is an opinion. So make sure you know this is not for sure. But it is an opinion that I discussed a lot with the people that again in Boston. The last week of just to get an idea where other people's heads are at and they they seem to agree. You know why would you never not have the two different mass and a concatenated key. Because you know the second something is cracked. It's still you'll have some time to get the third one in right and it buys you love time and that that time also is not so much. You're getting it out there. We talked about the agility agility to get things in place right. But it also comes back to the data being available to the hacker. So you have to crack both algorithms before you finally get to it and we need the data life cycle right when want to make this last more than 30 years at least right. That's that's where the time really saves you that if you had two different algorithms and do their hackers have to have both in order to truly access and do the harvest down to grip later type thing right that that's what keeps that from showing up again.
And so you know it makes it interesting when you think about these are two larger keys. And right now just with X25519 and MLKM you know we're looking at a 4K cert you know what now is to two PC ones. Is it six right you know like we the numbers are going to be high and that's why there is there's not there's a lot of people working on this by the way there are you know what do you do when it's too big is if it well it's the same equivalent right people are trying to find ways to concatenate and like you know to compress compresses best work they're trying to compress the certificates to be able to pass that across there to make even faster because the serialization and then set up times. This quick break is courtesy of sponsor potential now if you follow network automation you have seen AI change how automation is done automation is not just about sources of truth and infrastructure is code and orchestrating scripts and playbooks and repositories and testing and yeah it is still about all those things. But AI ads even more capabilities and so then the question is how do I fit AI into my toolbox because you don't you don't just start throwing data into an LLM and expect to get back to these production quality results that's not how that works net up seems required that AI behaves like an engineer and that it's bound by the security we used to govern any technology that touches our beloved routers and switches.
It's potentials flow AI is all about that it's deterministic so for the same input you're going to get the same output it's bounded by security constraints and it is. A gentick now and a gentick is interesting a gentick AI is a set of agents each with a capability that can be dispatched to gather information or perform a task think of each agent like a specialized tool so flow AI can securely dispatch agents in response to network events or because you asked at applying English prompt. And then once dispatched they can bring back a deterministic result and then recommend next steps and then you control what happens after that you can approve the action or deny it or refine it whatever is appropriate in the moment flow AI is technology that makes you a more efficient and capable network engineer find out more at itential dot com slash flow AI they have a white paper there about flow AI that is worth reading and you don't have to give it be contact information to read it again that's itential dot com. slash flow AI and please tell them packet pushers sent you.
Okay, so we talked about the impact of post quantum algorithms on things like the central things like connection setup other other aspects of network engineering they're going to be affected by a PC. Oh yeah, definitely well, most of the operations of it, but just but right now the math is different the math is a little harder right in the sense of what the things have been made quite efficient you know within CPUs and stuff so that has hard implications. Yeah, it has a hardware implications so the first one we talked I can talk about with which just just in the boot right a lot of devices come up and they want to secure their boot well that's going to take a little longer and it might not have the bios. That does that and how big is the bios on you know the new bios that the OEM has to build well if it's you know twice as big as it was before was that space even on there when they design when the engineer did a great job right designed for what was there probably made it efficient. Right, probably made it efficient. Right, I made too much so there's there's gear that you're going to look at and say hey if it's already running at high CPU because it's already doing you know 10,000 BGP sessions right because it's maybe it's the rusty one thing there it's already you know using every every bit of its brain and it can do most of it's in the A6 but the bits that are up in there when you hit it from the control plane you want to topple your box when you PQ SSH you know when when Ansible or terraform or whatever you're using is is in there trying to play with it and even managing it right that someone.
Management stations come in there. It's got some packets back inside of BGP right you're going to be doing a TSA P.A.O. which is the own package to be password you know neighbor password I'm Cisco right now I'm using Cisco terms right if you're doing that you know even that there's encryption at that layer right it's as the router acting as a router passing packets we kind of talked about the buffering issues right if I have now I've got a whole bunch of set of the data. I'm just going to look hard to truck ratio right from you know smaller smaller packets you know the frames to bigger frames you know now I've got a lot more bigger frames because I'm definitely sending a full size key right so I'm going to see a lot more I'm going to say Jummel frames would frames right up to the limit right that have to be serialized that's takes spaces and buffers to and will I start seeing buffering issues right is my is my router ready for that thing so where that's just another consideration air so
work with your all you know that right and you do start doing start vacation and you start looking at the application suite that's on your network and you find out you I expect you're going to find out really soon that the observability time in your environment is going to be your best friend as a network guy right because who do they playing first right it's maybe or if not so much blame sometimes they run to us just for help because they know that we're trustworthy and we do a great job right we have to know how things happen and we we made we make it real even a security eyes we put the all this encryption into the environment those are controls you know the security guy looks at that that's a control that's a mitigating control go ahead Scott is you know very practically I would say you know the application people don't really need to know how the network works but the network people need to understand the behaviors of the applications that write the network so we are often in a good and unfortunate position of having the bigger view and maybe helping figure out where this problem really why you know because they just not always the network as some people like to think I mean I see about max max act real quick so is this going to be as simple as getting new algorithms inserted to max act or well I need a new set of mechanisms beyond max act or some of both you mean I am more more
mech is why is it sec is the big one so I think I know I've been brainwashed I know that IP sec is you know that's no longer the way to do it and max act is the way to go I'm being you know little snarky I know yeah I've heard something that too and I haven't bought in bought in all the way on that one but I'm you it's that acting as a router what is where does encryption show up I'm a router max act as a great one you hit it on the head right that's almost like an IP sec tunnel or max act tunnel on the router somewhere and hopefully it's on hard we're in a dedicated slot just for security processing right but you know and you five hashing stuff that's not good anymore right how do you validate the oh I always pf announcements the bgp announcements right this is in those protocols they also have to have that put in there so it hits those even if you're not doing a encryption you're still going to have a a bit of a brain power and is the asic doing that is the iOS or you know whatever OS you're putting on the router does it even how the cypher
it will that will can they be right to code interact with it so you do have I mean again we're kind of jumping ahead maybe in a sense not all your some of your gear will some of the gear will have no problem with it they'll just be able to tweak the software and any things are going to work vitally on a 10 gig circuit right maybe maybe not on a 400 or 800 I know when you can act to go on the 1.6 that right if you maybe it's maybe the gears fine for the operations that you're doing and you'll be fine there but there are there'd be a great many that won't be able to be patched you know like the thing that I would charge challenge the OEMs with is crypto agility I can only be as agile as the management stations and the gear itself right so if you're having me load a new model this OS on every other minute or I'm getting bios that the normal fit like that's on them and you got to be really careful with them and do that kind of thing because it's going to that's what's going to handle it hit your heart acting as a host itself you know what does it rather do it's it's set a net flow right it's getting net conf done to it or as a staging into it you know itself is is setting logs places it's it's very
you know itself is a host as well and those things will have to be sent potentially encrypted and that's that's the other aspect you're going to see inside there where where am I looking to know am I PQC ready you know or PQR people cause like all post quantum readiness do I have PQR on these devices some of them will be fine for a certain amount of time because I also will also caution you if I was doing budget hairy things and now it's kind of talking at the management level in there you know will you have the five years to sweat an asset and I should do the full department appreciation there is a there is a significant opportunity and I think it's something has to be discussed at the board levels you know especially with the finance guys right your chief finance officer that you know there there's a risk and risk has been a lot of ways or accepted a lot of ways that devices that you put out now even though they are PQR today you could hit a three year window where something comes up and it's like no we got to change the mask completely different and something else has to happen and get some devices out there so you know
something to put the back of the mind I hope they felt that was relevant to what you just asked but Yeah, so thinking of all the places where I might run into encryption on the network load balancers firewall switches routers are there logical candidates that folks might want to be thinking about if they know in their existing infrastructure they've already got some boxes they keep an eye on because they're getting a little weasy that are sensible candidates for a hardware upgrade or can I just kind of like let's see what happens with the rollout when I when I device they would give everyone here's mythos came out right and here's this frontier a lot you're going to have all these things you got to patch and everyone whoa we got to do this smart we got to organize this thing here right so it's the same thing here don't take this as PQC's here and you got to stick everything focused on the edge go right to the edge so you're right you know when you're determining um you know offloads on a load balancer you know the cryptography offloads for devices behind it and reencrypting start there right make sure your routers are not accessible first off it's just to compensate and control that no one should be able to send the management packet to anything that you have on the internet especially your bgp router right there's some form of packet filtering that only allows bgp between the two entities and nothing else is there
that's that outside port so be smart about that stuff right that that device is not going to do so much except for the bgp itself and back to your environment but that's it like pq ssh book on the edge find those devices right away the firewalls the routers the load balancers that are passing the stuff back in let the usually we don't own the proxies but you know make sure to proxy guys doing the same kind of thing you mentioned to land devices to like just the two big ones though for us are um SD when right so if you got the large SD when deployment that's where it's going to because now it's on the other end to and those devices are going to be more suspect I think then the ones you have your DMZ are typically a little more beefier and and ready for the internet right and you actually have speed up action and all the other fun stuff that that's a huge one and then the the second one of that one is check your business partner connectivity's because that's going to be you're going to have a lot of guys on the other end that we have all those patterns right I bring it to you you bring it to me on from type or mix you know I use my piece you use your piece right those are going to be your the big ones that you really need the buckle down figure out stuff out first
because that's where it's exposed right that that's where the um yeah exposure is the best word that's what the exposure is and and that's where I would focus first and then then you move internally hopefully learn a lot of lessons from that for what you just did in the first place and now you can move that all that logic back in the inside and you're going to know a lot more even how to budget for it how to get enough heads in there how to build automation automation is is the is the key aspect to this because you could do it once but get a new a new cipher coming or to roll that across a thousand devices or even a hundred devices you're not going to do that really yeah oh god no right and how are you going to get the change windows for that right and you have to just the aspect of automation that people seem to forget to I really do see that automation is no longer something you kick down right you literally you were going to have to be automated and I like to call it net dev and says to be about them net the dev first now we are network engineers first but we're going to have to learn about the but we're going to have to learn a lot more how to do the scripting how to work with the tools that we have to do like the AI op-stite things right when as the OEMs come out with new management platforms we're going to have to learn what was MCP mean to me what how do I do that how do I pull the data out of there to plan
my actions to do doom you know sources of truth is going to become a new word everyone's going to know and we have to have you have to count the cans we didn't talk about sea bombs yet but I mean that's really it you have to count the cans as a co-founder of the network automation forum I want to go on the record drew and say Bill and I have never met before and ordered weeks were made on this particular piece of the conversation before this recording so I was like I don't know who he's talking to but yes Scott Scott is our in-house automation evangelist so one of you is video yeah yeah I'm watching it's got to smile and because it really is it's super part you will be net dev you have to be in learning how to teach make change controls and and do them confidently right how do you start building on the digital twins you know how do you have build a source of truth how do you really certify things that's a huge aspect for you know just automating your certifications is going to see new code on different platforms of blah blah but I'm sorry talking over you drew no that's fine I think we're
we're coming to the point of we we've seen this term crypto agility and what I'm coming to understand is what we mean is that okay you're going to go through this you know post quantum readiness effort but it might not be the last time you have to do it as new ciphers new suites new tech these come out you might have to think about doing it again meaning this notion of crypto agility is this not a one and done this is something that you have to sort of roll into your ongoing processes no we got definitely right the I like to think of it as the ciphers now it's called I call it cipher patching and that's going to that's main making stuff up so you know take it or leave it but the ciphers themselves will be considered patches so and that's really important when you go back to poorly s off hgbs how do I explain after the cfo one of the things I have to explain to them because we took all the air you know out of the room how do I get the air back mythos and everyone's got hot and heavy on on automation and doing massive changes and and getting patching into applications at different places we can ride that train I think
I think the part of the strategy you can use is to say like you have to you have to seriously look at ciphers as a security patch and if you do it that way then now everyone can kind of if they saw the light if they already built you know cut down the jungle and they've got everyone understanding what it means what mythos can do for you you know mythos is fun because you can find a hole and patch it or maybe not patch it right away but we talked about pulling the s off of hgbs can't you can't not do that or you just you have to fix that that has to be a priority there's no way around you know again hopefully we have the double hybrid keys and stuff like that but you have to look at this as patching and if you look at it as patching I think you're going to have a better time explaining to other people what you're trying to do they've already cut that jungle with your cfo and you're going to you're going to start seeing how you build the same they have the same change control problems with great automation and it actually comes great outage sorry Scott but that's that's not wrong yeah right thank you I'm glad you agree because uh yeah and that's what they don't want to
see right you have to do this this crypto agility has to not interrupt the business when we're in network guys when did they let us do things you know the crack of the morning right you know you're three o'clock in the morning and and uh that's the only time you get to do it because the business is operating at a certain time that doesn't go away so you're going you got to be quick you got to be right you got to get it done and and you got to build that confidence in there so your automation crop your operations you know they've been talks about AIOPS and it's great to know AIOPS because that's when things fail but that's not when things evolve and that's where automation helps you have to be able to evolve your your network and this is a key aspect of it and you know I'm sure Scott will agree me completely right you got to count the cans you've got to know what's your what you're automating first off right you know I don't understand workflow as is right and if you don't you don't have a good understanding of workflow it's just like caffeine you know do stupid things faster with caffeine right um I can break the network more quickly with automation at scale right understanding workflow is is is paramount yeah yeah exactly I did with with uh
you know we thought a sea bomb well I'll just kind of assert this one I know you that's a cryptographic bill of material sea bomb yeah cryptographic bill of materials what is that it's really a viewpoint I would think of attributes right but you have a lot of places where you probably do have inventory I would hope the god that inside your management tool you have all your devices in there most of your devices no but you know honestly like you probably 99% 98% on a good on a good day we actually know where all the gear is right and um but that's not enough you know it's great that you know it's as a Cisco or Rista whatever blah blah blah piece you know my got my pile over here and um you know f5 sitting here uh 810 what name it but I need to know is the device that's there doesn't have the room we talked about to put the new bias on there to do the secure the secure boot is it even doing the secure boot is this thing a capable of doing hqc it's coming up like uh i'm ready that viewpoint is really what a sea bomb is so how do you get there there's a lot of tools right now that are on on the market right and i'll just you know hey come sing me wbt we'll
help you get there because we're building programs for this but um but you should search this out there are tools that actually have that they're made for that standpoint and what they do in general is they um because you want a single pane of glass right i want to get of a multi oeum shop i want to get the different versions of the different hardwares are come from then and what code they're on and at the same time they do a little bit of probing to make sure that the reconciler to make it's happening but another aspect that is often not understood or missed is that a lot of them actually put probes in your environment to make sure that the protocols are being used because there's some things just because you configured it doesn't mean necessarily didn't fall back to something classical right so those probes in there to help do that does that make sense totally yeah if you a transaction is going through and you know one end doesn't support the right cipher suite then it's falling back and maybe that's against policy or whatever and you don't know because the traction went to if you're not looking you don't know you attack them and get to see you know
the events happen every day every you logged in that's a good event but wasn't an incident the incident management was it something that fallback it very well be an incident like hey someone someone to go she had it down that's not good it will give you like certain firewalls and leave out names on this one but um you know certain firewalls there they're expecting this stuff there's some of them actually get involved in that transaction and until you get to a certain code one of them defaults to the classical it doesn't let the pqc go through so you got to get to that new code to make sure that that's happening so there's there's nuances inside of all these things where we were talking very high level today here i'm hoping that at the end of this conversation i hope the most persons have enough ammo that they can really start to dig dig in a bit right they know about crypto agility they they've heard about the new cipher as they understand the importance of what's going on there's there's a lot more even beyond what we're saying today not to be fearful of it but you know there's changes in how people are doing signatures and there's is an emirical trees and there's there's a there's all different techniques for sharing keys that are coming out it's it's an amazingly exciting new world that i hope that i can survive long enough
for me to get the retirement but um there's there's a lot going on in this space well that this leads to another question with the emergence of post quantum algorithms coming into my infrastructure does that have an impact on my monitoring and my visibility my observability do i need tool upgrades do i need to be looking at different things uh and and even if i've got a source of truth like a net box or something else that's that's supposed to be collecting all of this kind of data can i expect that to also incorporate cryptographic information yeah i don't think that's going to change much from where it already is but you do need to know things when people are crying that my setups are taking forever right and and and do i have what looks like a um a network issue is really application behavior yeah right you gotta get get the guy can can can help you determine those things because we talked about buffers potentially right and just the base of serialization of things so i don't i don't really expect and again this is going to be built in here like remember that the key sizes and stuff are still on the setup once it's set up and the keys are established we go to
the symmetric encryption and that's the same as it's always been sure oh you're not going to see like i'm gonna put 30 percent more in all my bandwidth don't go to the cfo and ask for money for that many kinds of upgrades and circuits right yeah nice and maybe it won't be you but you know you're probably i mean if you can squeeze it in yes right it's almost like your security through there's always budget for security so network infrastructure needs to forget it but if you call a security thing there you go yeah well you know what you what you said about the security stuff those controls you know the controls the things that monitor these things that know about the fact when things went down when I downgraded in the the ciphers that are going on or just to know hey did i really get everything that i is everything working on hqc now because i work at where the ml cam where's it at like there's still need to be probes right and and things to do that so you're going to see a lot of the security devices need to understand the firewalls especially you know they they're gonna see transactions going across them so if you're doing um
if you're doing we'll call integrated firewall stuff inside your routers and switches that's where i think it's gonna you're gonna feel the most okay as a direct answer to that question you know and it just as a mother implication for the networking team right you now's a really good time to look at your network architecture and your processes if you start to think about okay what's it going to look like to do software upgrades and hardware upgrades to accommodate want them safe crypto just on my infrastructure like you can start thinking about that now um before 2029 and 2031 and where you where you might want more redundancy to keep a service up while i'm taking something down for upgrades like now's the time to be thinking about that yeah you i can tell you've done automation because you're right on the money right because i know that you're gonna you're gonna quee us things right and you're gonna move the move to one side make the changes validate validation's a big thing gotta use the v word right gotta validate that
stuff before you bring it back in the cycle and then we're gonna repeat ad nauseam there i think it's hard for network guys to sometimes want to give up the reins a little bit on the fact that you're gonna you're gonna do what you did before but you're doing it through you know through the script and and you're it's a process you the process doesn't change it's how it's affected seems to be the the the terminus thing and uh you know you shouldn't be afraid of that you shouldn't you should do like run to it right and but it's amazing how many people don't know what the processes they do because now everyone's got to do things the same and i think that's that's a lot of the the the inertia that people face you know well i just have to do the the tread network engineer mindset right and it's culture culture is powerful right and when you like identify as a cci like i am a cci or i am a j n c i and i am j n c i um you know you like i have muscle memory for those
you know cli commands and uh you know we still gotta do the same things but they're implemented and and affected in different ways yep right and you know it's i think it's somewhat scary i guess for some that you know you're starting using AI assisted stuff right like i i myself now i'm fighting a lot with that and uh i wouldn't write my scripts the way i did the four even and it's easier and i think there's it but it is a brave new world for someone is not done it before and culture is everything called the culture of your team is is paramount and you know hopefully you can bring these these changes to that culture yeah because it there is no room to not do it right people should be get off this call scott needs to take the lead and we need they need to talk to you about automation because that is you have to start planning that and that means everything from you know what can i do today you gotta go to your lcm and go if i'm buying gear that's not even considered pq ready right if my oem is even have a road map on it don't deploy that right so you've
got to start at the lcm there you look at the edge right away and start building your c you got to have a c bomb you got to count the candy you had need to have that cryptographic viewpoint the attributes of the devices that you have in your environment know where those are start finding them make sure your sources of truth or whether at right so that you can overlay that that that pq awareness to those things there you gotta get out there and find all the cans right count i say that because it's the work in the grocery store right and you got the count pants you what was stolen them i was broken and all that kind of stuff right you know you can do that today there's no reason why you can't be doing that you should only look at your certification plans start updating those things you somewhere in there you know just throwing code out on these these switches right you you better be certified in the some point do you have test tools to do that you'll go get them right you'll go figure that kind of thing out so you know this does some of the simple things that are not you you can do right away that start making you pq ready as a organization right that says the devices it is it is a cultural aspect that you have to you have to take on it's
gonna be i really do you think like some of this patching on this is almost like you're gonna be in the jnc ie or in the cc ie exams like you know how do you recognize these things how do you automate that stuff how do you how do you make sure that your cypher is in place is this play a room for it did you really configure bgp to is it secure now right the even the lspf right the ls aes where it what's going on there you it's going to be at least some kind of consideration bill i think you've given everyone a lot to think about one don't write off post quantum it's it's a thing and whether you think qda is coming or not some organizations do and they are taking steps and so should you so just final thoughts on on you know for network engineers how to be thinking about this how to bring it to the organization you know and how not to freak out yeah all right and i hope that that's what we did today i hope we didn't freak anyone out this this is business table stakes right everything you hear in here's table stakes there's there's more to the story and but you know those things will come after you started to take the viewpoint of it is true it is real
you know it is super important when you take the s alpha htp so you have words on how to make other people be aware what you have to do and as a network guy let people know i have to do a lot to make this happen this is not just a security thing the cto and the cso need to be going in there so again that that that's really the goal of this one you should have that much and if you want to learn more about it i'm you know i'm on linkedin for that matter and i work for wbt right i work biggest integrator out there right happy to work with you and your organizations i was a little pitch there for that but that's let me leave it there all right we'll leave bill's linkedin in the show notes or you can go find it itself build ocarie he's on linkedin but we'll have that link in the show notes bill thank you for being here this was a really good discussion and i hope it did give folks a lot of places to begin to this because there are a lot of ways to come at it but yeah post quantum is coming it's real and whether or not we know when q day happens things are happening so i think the best time to start your post quantum plans is probably now
bill you're online it linkedin any other place where folks and find you or do you blog do you do do anything else twitter handle i'm not a network space i do a lot of more short stuff i have two books ikeysecrets.com that's why i usually put my after hour stuff i try to stay away so but i can link it in work so okay very good that's cool that's nice to know you've got hobbies right well that does wrap it up for this episode of heavy networking and bill thank you for having made this a very heavy episode indeed Scott thanks to you for joining and stepping in it was great to get the automation perspective and the practical perspective as you always bring you can find this and many more podcasts at packuporsh.net we've got so much plus a slack group youtube channel you can watch this podcast it preferred instead of listening and so much more always at free at packuporsh.net thanks for listening
More episodes
More from The Everything Feed - All Packet Pushers Pods

Tech Bytes: Why Beaver Excavating Tapped Firezone for WireGuard-Powered VPN (Spo...
The Everything Feed - All Packet Pushers Pods

NB592: AWS Recommends UAE Migration; FCC Wants More Spectrum for Satellite Broad...
The Everything Feed - All Packet Pushers Pods

TNO073: Network Automation Forum: From Simple Survey to Global Community
The Everything Feed - All Packet Pushers Pods

IPB208: IPv6 Address Management Is Broken
The Everything Feed - All Packet Pushers Pods