Following the news that AI helped discover a cryptanalytic attack against one of NIST’s candidates for a post-quantum digital signature, as well as against a weakened version of AES, Simon Pamplin, CTO of Certes, commented:
This is precisely why the key rotation speed and continuous adaptation to change are super important. Quantum resistance is not just an algorithm change - as this shows algorithms will be attacked and will have vulnerabilities - the smart companies will deploy Crypto-agile abstraction layers that are able to adapt and continuously change as newer, stronger algorithms are approved - these coupled with sovereign keys that are changed every 60 minutes per flow, is what will keep the data safe. From the research, these attacks were on severely compromised versions of AES and not how it is deployed today. Although it does make the point that a 25 year old algorithm has some vulnerabilities.
Editor’s note: Simon Pamplin, CTO of Certes, will be speaking at PQC+IQT, which is coming to New York City October 25-26.



