The Quantum Attack Surface Federal Roadmaps Miss

By Quantum XChange

Share this post

QXC-Media-Article-FederalNewsNetwork-EddyZ

Eddy Zervigon, CEO of Quantum XChange, published commentary in Federal News Network arguing that federal agencies are being measured against a migration plan narrower than the exposure it is meant to address. Executive Order 14412 sets deadlines of 2030 for post-quantum key establishment on high-value assets and high-impact systems, and 2031 for digital signatures, with OMB’s M-26-15 setting the phases. That work is necessary. Eddy’s argument is that it is not sufficient.

The piece walks through six areas that sit later in the timeline or outside a system-by-system inventory entirely. Identity and public key infrastructure, where a quantum computer can derive private keys from public certificates and generate valid credentials for any user on the network. Network trust, where forged certificates redirect traffic through DNSSEC and internet routing without triggering a single alert. Software integrity, where a forged code-signing certificate turns the update channel into a delivery mechanism for malware. Operational technology, where the consequences reach the physical world. And the supply chain, where an agency can complete its own migration and still be exposed through a single unmigrated vendor.

The sixth is the one drawing the most response. Audit logs are how an agency reconstructs a breach, and they are trusted because digital signatures protect them. If those signatures can be forged, an attacker can alter the record of what they did. The organization loses the incident and loses the ability to establish what the incident was.

Eddy closes with what agencies should prioritize now: long-lived keys rather than only long-lived data, the systems an agency depends on rather than only the ones it owns, and cryptography that can be replaced without redesigning the system around it. He notes that Google, Microsoft and Cloudflare are each targeting 2029 to complete their own post-quantum migrations. Phio TX® delivers quantum-safe symmetric keys out of band, so cryptography can be changed without re-architecting the network or taking it offline.

Read the full commentary: The quantum attack surface is bigger than it seems

Frequently asked questions

Can a quantum computer break authentication, not just encryption?

Yes, and that is the argument at the center of this piece. A cryptographically relevant quantum computer can derive private keys from public certificates, which means it can generate valid credentials for any identity on a network. Public key infrastructure, Common Access Cards, and the digital signatures underpinning zero trust all rest on that same cryptography. The attacker is not breaking in, they are authenticating.

Does post-quantum TLS solve the problem for federal networks?

Only part of it. TLS 1.3 is adopting post-quantum key exchange, which protects the contents of a session. It does not verify who is on the other end of it. Certificates, DNSSEC, and internet routing all depend on digital signatures to establish identity, and forged signatures redirect traffic without triggering an alert, because cryptographically nothing appears wrong.

Why does audit log integrity matter for quantum risk?

Audit logs are how an organization reconstructs a breach, and they are trusted because digital signatures protect them. If those signatures can be forged, an attacker can alter or erase the record of their own activity. The organization does not simply lose the incident, it loses the ability to establish what the incident was.

Share this post

See Phio TX in action

Have one of our experts show you how Phio TX protects your organization from threats today and the quantum future.

Request Request 

a

demo demo

grainy-bg-blue