← Back
Policy & LegalTrail of Bits·1 month ago

Shipping post-quantum cryptography to Python

Post-quantum cryptography is now accessible to Python developers with the release of cryptography v48, which implements NIST-standard ML-KEM and ML-DSA algorithms—critical as the White House has mandated federal systems migrate to quantum-resistant cryptography by 2030-2031 to counter "harvest now, decrypt later" attacks. However, successful migration requires more than swapping primitives; organizations must redesign protocols and data formats to accommodate significantly larger key sizes and signatures (often 1-2 orders of magnitude larger than classical counterparts). With pyca/cryptography handling cryptographic operations for 1.2 billion monthly downloads across projects like Certbot and Ansible, this library's

Read full article at Trail of Bits

Related Articles

Policy & LegalThe Record·2 hours ago

New Zealand to pursue social media ban for children under 16

New Zealand is advancing legislation that would ban children under 16 from accessing high-risk social media platforms including Instagram, TikTok, Snapchat, and Facebook. The law would require these platforms to implement age verification mechanisms such as facial age estimation, digital ID services, and formal identification checks to enforce compliance.

Policy & LegalCyberScoop·4 hours ago

Bipartisan Senate bill aims to prepare energy sector for Q-Day

A bipartisan Senate bill seeks to strengthen the energy sector's resilience against quantum computing threats by requiring the Federal Energy Regulatory Commission to evaluate quantum-related cyber risks in its reliability standards. The legislation aims to address the potential impact of quantum computers on cryptographic protections that currently secure critical energy infrastructure.

Policy & LegalInfosecurity Magazine·7 hours ago

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

TCG has released new guidance designed to help organizations verify that trusted platform modules genuinely meet quantum-safe requirements rather than making unsubstantiated claims. This resource addresses the growing need for businesses to validate the quantum-readiness of their hardware infrastructure as threats from quantum computing advance.

Policy & LegalInfosecurity Magazine·7 hours ago

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has identified 23 novel security challenges specific to multi-cloud environments, highlighting risks that extend beyond traditional single-cloud deployments. The organization is calling on the cybersecurity community to develop solutions that address these unique threats inherent to managing infrastructure across multiple cloud providers.