Skip to content
TrackPodcasts
technologySep 18, 20261:13:08

HN842: How Network Engineers Can Prepare for a Post-Quantum World

Get every episode summarized

Each time Heavy Networking publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

If you hear the song ABC by the Jackson Five and you mentally substitute BGP in your head, you found the right podcast. I'm Drew Connry Murray, Ethan Banks is away, so Scott Raban is joining as guest co-host.From the transcript
Q-Day signals the public emergence of a cryptographically relevant quantum computer that can break public key encryption. The date of Q-Day is unknown but the tech industry is making preparations now. Bill Dockery joins Drew and guest host Scott Robohn to dig into Post Quantum Cryptography (PQC), what network engineers need to know to test... Read more »

Hosts & guests

Transcript ready

629 searchable segments. Every word is indexed and playable.

HN842: How Network Engineers Can Prepare for a Post-Quantum World

Heavy Networking

0:00
1:13:08

Full transcript

Heavy NetworkingHN842: How Network Engineers Can Prepare for a Post-Quantum World. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Welcome to Heavy Networking. If you hear the song ABC by the Jackson Five and you mentally substitute BGP in your head, you found the right podcast. I'm Drew Connry Murray, Ethan Banks is away, so Scott Raban is joining as guest co-host. You can hear Scott on the Total Network Operations Podcast right here on the Pack of Pursures Podcast Network. On today's show, we're going to dig into post-quantum readiness. Now you may have heard of Q-Day, Q-Day signals the emergence of a cryptographically relevant quantum computer that can break public key encryption. Q-Day itself is actually unknown the date, but the tech industry is making preparations now. Network and security vendors, the big browser providers, cloud companies, they're all rolling out support for post-quantum algorithms. So on today's show, we're going to dig into post-quantum cryptography or PQC. We'll talk about what network engineers need to know to test and integrate post-quantum algorithms into their infrastructure. Why organizations might want to think more broadly about things like crypto agility and more. Our guest is Bill Dockery. He is consulting Solutions Architect at WWT. He's been thinking, writing and talking about post-quantum cryptography for network engineers.

He's here to share what he's learned. We're going to spend the first part of the podcast on level setting and then move into what's relevant specifically for network engineers. No, we'll wrap up with some big idea kind of questions. Fonser Itentials Flow AI delivers agentic operations for infrastructure, meaning easily build AI agents that actually work the way engineers need them to governed, terministic and built for production. Add intelligent automations to your network operations without the usual AI chaos, find out more at itential.com slash flow AI. That is itential.com slash flow AI. So Bill, welcome to the podcast. Just to kick us off, how does quantum computing put classical cryptography at risk and one of those risks mean for organizations? Yeah, well, thank you for having me here and answer those kind of questions. So quantum computing is going to basically crack what we call classical cryptography. This as RSA is at risk. And so with that, you can basically take a encrypted communication that you would typically use today and determine what the private key was and in doing so, we work through the entire conversation itself and pull all the data out from between it.

And what it takes there is it's a different mindset. The reason why cryptography today classical cryptography, we're going to be calling that correct classical from here on out. The reason why it's so viable is that data has a life cycle. And for RSA with traditional computers, the way they operate the way they act, the way the operating systems are built and the way GPUs work in general, it took a lot of time. It really was a time thing, right? It was it could be as long 100 years, 1000 years before someone could crack the encryption on a particular communication. And that all changes because quantum computers are very different in how they work. And because of that, they could do a little bit of different math. And the one math is, you know, a little more powerful than the other one and they can take this now to classical cryptography could be cracked and they're saying minutes, right? You know, within within a very reasonable amount of time for a hacker wanted to do something malicious, very reasonable amount of time for them to do that stuff. And so now when you consider the length of data viability, the life cycle of the data itself, that's not good.

So can you explain at a high level why quantum safe algorithms aren't susceptible to attack by quantum computers? Yeah, I'm coming back to them. Honestly, the Plank Spoked Cryptographer Yublin, tell me how used to prime numbers as the basis for the foundation for how the math became hard for a GPU to crack. And it just would take it and the like that's right. I mean, they didn't have an algorithm that just to do that algorithm would have taken forever. And the new PQ, like let's say MLKM, the math in there, when you look at RSA, which is the classical side of things, it was basically multiplying prime numbers together. And it really hard to factor backwards. And the new one, MLKM, the best way I could describe it, you know, to make it layman's kind of terms, the way it was explained to me, because I am a layman is that, you know, the MLKM, it actually introduces noise. Right. So it's not the same foundation, right. It's just a bit of noise that can be taken out on the far end, right. So you can actually have the conversation with another host.

And that complete different process is difficult for a quantum computer, because I think maybe one good misconception that people have is that, you know, quantum computers is not just the computer you have on steroids. Right. There are things that GPUs are really good at the kind of math that they do, right. And that's why we came, came out with GPUs and all sorts of other co processing. You can kind of think of a quantum in the same layer, though it does a lot of overlap, right. You can get the new analyses, right. We used CPUs and GPUs to do analysis. The new quantum stuff is going to be able to do different types of analysis. And so where it's strong, this is just one of the areas that is really strong when cracking the R say, prime numbers, kind of things. So just we stay away from it now. New math has to come about. Right. I'm sure we'll talk about that in a minute like, you know, new ciphers. That's the thing that's going to be coming out. These new ciphers are basically built on different techniques, you know, mathematical techniques.

So let me some some of for another layman, you know, not primarily a security person, but it's not just bigger prime numbers. It's not just bigger crypto keys. It's inserting techniques that mess with the math, the quantum computers are good at. Yeah, it's a quick analogy for that is, you know, ML is it's adding noise. One of the ones that's out there, the SLA DSA. It's it's using a bunch of hashes. So it's the methodologies are completely this can. And I did that on purpose. We need more ciphers to keep doing different things because the expectation is that the quantum, well, maybe someone like sure some of the smartest Peter can come out and find the new algorithm inside of that to break that new that's life right there today. So you shouldn't expect ciphers to live quite as long as they have today. That's one of the big discussions will have. You're referencing sure who develops shores algorithm, which like mathematically prove that these classical cryptography was vulnerable to quantum computing.

Right. And you know, to that point, you met a Q day. The Q day is a cryptographically relevant quantum computer. Right. So it needs a bunch of qubits. They don't have enough. They don't think they have enough to implement shores algorithm. And that's where Q day comes from because there are quantum computers today, right. And they are doing things with them. They're they're making advances in science and medicine all sorts of great things. But the cryptographically relevant version of it is what's coming and that that's the big point of it all is that it's going to it's going to keep adapting and building and it's honestly, if you look at cryptography, just, you know, take a step back for a second. Cryptography is really an arms, right. It's literally you're not allowed to send cryptography to another country that you're not copicetic with, right. We've got a couple were an odds with right and you would never send them that piece of that. So it will be an arms race and they are developing their own and we're developing ours and they're attacking ours and we're attacking theirs. And you know, it really is that piece there.

So for most of us who aren't in a antagonistic situation, most people trying to serve businesses, you have to go along with it, right. You have to follow along with it because that's that's the other part of it. The other people are in scent of a little different way. I very much remember when because versions of software with those ciphers, you know, we're on export restriction lists. I was attack engineer, you know, what a major router manufacturer and it's like, yeah, customers in this country or this region of the world couldn't get this version of software because it had had those export restricted ciphers and it's seriously. Yeah, it's dead on people forget sometimes that cryptography is how we stay well confidentiality integrity and availability of the CIA thing right that if you're security guy, but I know we're talking about a network guys, but security first thing they teach you is CIA confidentiality integrity and availability. And we care about that is network guys, of course, right. We actually want to implement most of that the fun part of this. And that's why I wrote this discussion. Why I have this discussion a lot with the network engineers is the.

The C so in his team are recognizing the issue confidentiality. How to make concrete conversations private, but it's cat it's writing a check that the network guys have to cash right we we are the ones that do things like the old. It's always that way it's all it's not just security thing with sorry sorry. Sorry, you touched. I'm sure we got a lot of heads nodding when if they're hearing that yeah, definitely right we were the Kate as network guys, I should say my background is really CCI and then and then, but I became more of a security guy later on. I'm a network head and it's always been we are expected to the way to keep and where the application might not be inconsiderate us right. When we talk about how fast people can move we talk about agility and there's agility of all the places we need to be agile because you know what if we're not the most nimble ones the applications are likely to fall behind. And it's always been the expectation and in my right experience and then life right to put the bidding cryptors online and cryptors, you know, to make sure that even if the application failed its job, we were still making sure the confidentiality was there.

And I think those expectations are probably going to be even a little more intense. When you consider everyone trying to bring up the tail right we just talked about the arms race and a new cipher and a new cipher and I guess we'll expand upon it, but you know, I think that the first place that it really does have to happen is legitimately the network because again, the business partner connectivity, you know, what's going out of our DMC's right when we do them because a lot of network guys actually tend to own the firewalls and the low balancer. To at least in the sense of, you know, we manage them and you know they they love the one the policy, but they love to make us do the work for getting yourself certified and implement it right and so you kind of get my draft right where I think we're all smiling on that one there. So how for folks who have a lot of their plates already lots of projects, maybe lots of long term projects with Q day being an unknown date how pressing is this issue of quantum readiness. So the indicators are definitely pretty pretty broad. I'm sorry, actually very discreet that's probably better way to say it so you have things like Google Google has challenged themselves to 2029 and and not that they have, I mean, obviously I'm more information they're big information.

But I'm sure that that's, but that's something you should assess in your own mind because this is going to come to how do I sell this to my organization. How do I get the funding and things in there. So one of the places you can quite do is definitely there, but the Google is anticipating Q day emerging in in sometime in 2029. Yeah, exactly. And I think that they're expecting it to be a little later. They want to be ahead of it. So I think they're being very responsible. So look at that. Right. Here's a very responsible organization. And that is looking at 29 is like a very, very viable day for us to get things in place. The two new executive orders came out in June. I think it was June 22nd. They doesn't matter, but 14 412 and 14 413 were the two that the government themselves just sent out. In fact, we have the 23rd today. Why that's relevant is yesterday, I think, was the deadline for all of the little three letter organizations and every organization in the government to a point they lead for PC implementation across the entire government.

And that's not that was the 30 day one. That's in the first, the first one of the executive orders and they're taking very serious and they say in there that we want to see you doing signatures by 31. So that's that's the end goal. There's some little things in between, but the end goal. So basically you can say the government themselves is pretty much put a line in the sand that they within the government you had by 2031. Why is that super relevant, especially if you're like a bank and you're clearing your transactions, I come from global finance, right? I've had a lot of banking stuff. I worked for some banks for a long time longer than I want to admit. But you know, the government and is going to be implementing it. It's not like we're maybe V6 like they are going to implement this by 31. If you're not doing it by then and Q day maybe hasn't happened. We'll talk about what Q day really means. But if Q day hasn't happened publicly, then you're a bad way because how are you going to transact with the government that order is going to see that right away. And I can tell you now, 2031 is is depending on your organization. It might be considered aggressive. And it's not a small task. This is a very, very large task. This is why again, I've been prepping a lot of the clients that we work with, especially the ones I know the most because I'm working with friends at this point around global five worked in banking for a long time.

I'm working with friends like, hey guys, we got to get on got on the hook on this one. But a quick one less mention on that moment and close this is the second executive order basically says that the government themselves is highly interested in quantum computing. Like they, they really see that quantum computing again is another arms race itself. Right. We talk about AI a lot. AI takes all the air out of the room. Right. And then you get in the quantum quantum takes all the air out of the room. Now we have the mythos thing. And take it all the air. Me, even more air out of the room. Yeah. Right. I was in the stratosphere trying to breathe. And, and then there's PC in the bottom of this. But yeah, the government is looking at quantum computers because they, they realize they're going to need that to do the same. We talked about the cipher. The cipher is being elevated and changed and moved around to keep confidentiality. That's that's the reality. What's going on. So again, start by 31 is a. So the thing is even if Q day doesn't emerge by 2031 there is a line in the sand from the government saying we need to support.

And PC for digital signatures. So if you do any kind of business with the government. So do you. Yeah. Hello, exactly. Right. And at that point, the expectation beyond everywhere. Right. The, not just the government. I mean, well, the government makes me do this. Why are you not doing this? Are you afraid that why are you not right? So there's, there is a little bit of the, you got to get on the bandwagon. And I mean, maybe there's a little bit faster. This is not V6. Don't consider that right? Actually, head a little back and stuff on that internally. Yeah. Yeah. Right. You know, this is not, this is not easy. V6, things to work with out V6 and the government made that. And the reason why this comes to mind is, you know, the government had some e-dicks about V6 and, you know, eight of your old amount of remember, there's some coding stuff. They make a lot of e-dicks sometimes. But this one, this one's no joke. And I hope to make that serious enough for persons to realize that this is truth.

I mean, eventually we're going to need to do this everywhere. I want to say everywhere. We'll talk a little more. I guess a lot of that. You asked more questions before I just run this one long bill speaks. So, just a couple comments on the dates. So, you know, nothing, nothing motivates action like a deadline, right? So having deadlines, whether it's 2031 or 2029, you know, at least there's something. There's a line in the sand. There's a target to go after. You know, I would, I would argue that, you know, we are dealing with probabilities here, you know, because Q day is unknown. And we may not know that it's Q day when it arrives, right? You hinted at that a little bit. There's a quantum joke in here somewhere about the probabilities and the unknowns. But well, the quantum joke is both funny and unfunny at the same time. So, but so I don't think we could be too aggressive. Whether it's 29 or 2031, you know, where if we can move those things up, great. But implementation adds another wrinkle to this. And we'll see where we go on the front for the rest of the conversation today.

Oh, yeah, especially with large organizations. But, you know, the thing about Q day not being known. If you know some mystery, you know about the enigma machine, right? You get into security classes. They always talk about the enigma machine, right? And what was it, you know, the the access had a device that could keep their confidentiality. And they didn't know we hack. Right. And that was what happened there. So when I say Q day publicly, we have adversarial persons in the world in the globe, right? That may not be copacetic with us right now. And we can leave it out names and trying to stay very far away from politics. But note that we're not friends with everyone. And some of those persons are trying to build quantum machines. The same thing that the second executive order to came that right. They you think they're going to tell us when they get there before we do. Uh-huh. Q day could have happened and we wouldn't know depending on who who reaches that right. Yeah. The only reason why I think they're confident on that right now is the technology. The number of Q bits is not quite there. But I'll give you the give me another maybe a little scare. And again, I don't want to scare people on here.

I think the purposes meeting is a really good people are aware so they act correctly right. Yes. But I think that the question is, um, appropriately, and is that AI is helping a lot of things advance. So I went to this quantum tech world in Boston, just in June time frame and again, short was actually there. A lot of people will still in line to give a picture with them. But the gentleman, if he was there, I did get a picture with him. I'm a little bit of a geek to security side. Um, but AI does seem to be advancing quantum. And I saw the three things that that that made me feel confident that that's a true statement is that there are more and more qubits showing up, right. The road maps of the OEMs are going to add more more more qubits. And that's what we need to be to be a cryptographer cryptographically relevant was that was a big one, right. Then I saw all the things they're using quantum even more efficiently. They're learning how to get the standard algorithms that run on CPUs and stuff like that. But now the work in the quantum world, they're doing more with less.

Sorry. So what we expect cryptograph cryptographically relevant thing to need might shrink. But that's just my intuition. I want you to take that is a bill ism. Okay. So they're doing more with the less that they have. And lastly, the big one is on the error corrections are getting better. And what that really means is I won't say that they're more accurate. I mean, accuracy is about algorithms and running math. But what they are, they're probably more reliable. Right. That when it's an item, right. When you do it, you do it the same way comes out the same way. That's the error correction part of it. So they're getting more. Is that efficient? So I want to say accurate. I don't know reliable. We'll leave it on reliable in the sense of the math that the computation that it did is becoming more reliable. You factored these three things in and 29 and 31 should be definitely hard held lines in the sand. So just to make sure we're all understanding when we talk about post quantum cryptography, what aspects or elements of classical cryptography are affected? Are we talking? Is it all public key based? Is it symmetric key based? And that will inform how we need to think about what to do in our infrastructure. Yes.

Yeah, you hit it on the head. So I'm sure when after RSA, right, the public in private key, everyone was kind of familiar with that. That's called asymmetric encryption. Right. I, you see my public key. You can send things to me that only I can undo. That's not the same as symmetric. So AES, the world were familiar with us as never engineers. Right. That is a symmetric encryption where the keys are on both are known on both sides. That's where our PSK's are pre-share keys all come from, you know, in TLS and in a lot of other methodologies for building an encrypted tunnel. Like if you know, if that kind of stuff like that, they are using that prime number based math. So sometimes if you human, they call it a lift to curve here, you're lift to curve, right, that's part of the the math on building to feed home and sharing over an open line. How do I, how do we both derive the secret that we're going to use on that encryption. Right now, sure is algorithm takes care of the front part. So in like TLS, what's the first thing I do? We see these packets, you know,

you say, okay, I'm a client. I would, I would like to do these algorithms. This is what I'm capable of. And, you know, let, let's set this up. And I have real summer like stats. Sorry. I'm boiling this down to be quick. Right. Here on the client. Here's what I can do because, you know, you don't know the client cannot, cannot do every site for yet. Right. Here's as a client. Here's what I'm capable of. Here's what I like to do. Mubba boss. Then the server comes back with let's come back with. Okay. Well, here's what I would then here's what we're going to do. And here's my serve. Right. That's served as a tool. And here's what I would say is that the public key portion of things. And of course, that's based off of PKI. So the client trusts the route, the CA, right. The certificate authority that this sort was given to, you know, as kind of the third party to build the true to trust here. Okay. Great. I accept that. Let me take it over here. And let's start negotiating what that what the key is for our symmetric encryption. That's where a AES comes from. Now, hopefully with short algorithm attack the asymmetric the PKI stuff where the actual key is established for the other. But even a yes has been under attack to there's an algorithm that has weakened it significantly. And when I say, okay, did it. It's kind of funny. It's just awkward the way they do this. They say you have a thousand might keep, but it's a strength is only like, you know, 500. And that's really what it's done. The algorithms that are following right now have not cracked a yes, they don't think it math them out. Okay, crack it. But it does.

It makes it reduces the time by saying a thousand by key of 500 by keys really it all comes down to how long can it be kept private. It's like how long before your friend tells on you, right. That kind of thing is is really where cryptography gets its confidentiality from. So we have attacked it, but that is a yes is still viable. So and that's a really good thing when we consider that, you know, we're not really not changing the flow of the transactions. We're not modifying things that are really modifying just the first aspect of it is setting up the encryption in there. Okay, so we're talking about when I'm thinking about where post quantum cryptography is going to come in to my life. It's around things like digital certificates digital signatures that kind of stuff. Things related to asymmetric encryption and public key infrastructure. Right. Because if you think about signatures, which is a huge part of just validation. So identity. I mean, most of the identity is basis way. It was secure boots, right. We're looking at certificates to acknowledge that a router's part.

My SD win environment, right. So all those things come in there in signatures, right. That I have my private key. I you can I can, you know, math and I can encrypt technically I think it can encrypt a cipher text give it to you. You can unencrypt it and go, yep, that has to be him because he's the only one we have the private key. That's its signed, right. Our entire, you know, trust infrastructure relies on certs and signatures. Yeah. Thank you for the words I couldn't find you said it so well. That was that's, you couldn't send it any better. The entirety of that is based on this. And that's why when we say this, you know, I kind of skip ahead for a second on the question. Yeah. You're going to ask me is, you know, how do you sell us to people? Well, essentially quantum quantum when it attacks this, it basically kicks the s off a HTTPS. And I really want that to sink in, right. Like this is the best way I think that you can explain this to lay persons at the board level, right. It's not their job to be technical, right. They don't shouldn't have to. But I think that it makes it really poignant. Really, you know, they understand the gravity of this when we say, you know,

would you do your banking with that little lock wasn't on the browser. Because we're taking the s off. And that block might say it's there. But, you know, when Q day happens that they haven't told us it happened. Basically that locks broken. And you don't even know it. Right. And we can't be there. You can't do a lot of transactions. How do you do business that way? How do you obviously defend your country, all that kind of stuff like that. But, you know, how do you do business in that manner? Do you trust that the person in the middle, the man in the middle attacks become viable. And that's when we talked, we don't know if we did talk. We talked a little bit about gathering data and the harvest now to quit later. Harvest now to quit later is grab the data from someplace and get it. And obviously that's not scriptkitties, right. This is a little more serious. That's my nation's state. Bingo. Hey, can you think of any sites that you might have a lot of interest in getting data from even if it's encrypted that I'm known five years from now I can unencrypt. I don't know. A lot of people put the stuff in cloud right now. Children, documentation. You know, like there's a whole ton of things are code.

And hammer away at it in my back end infrastructure. Yeah. Yeah. Right. If I had a year's worth of that stuff, how many different organizations do I have intense amount of data that I can extrapolate interpolate later on and then do the things like, you know, when you think of security, it's more than just a bits and bites. You know, everyone knows how fishing, right. And, you know, and, you know, they're targeted fishing, right. The people are going to try to get someone and know enough about them. Think of identity theft, right. And because we just mentioned identities everywhere that when we were just talking pretty much about the vice identity. But personal identity. And how do I walk into a back and I say I'm, I'm Joe X and I know all the transactions that have happened. I know all the account numbers and all the names and all the things that have happened for five years, right. You know, that's the, that's the seriousness of what, what happens when people have access to that data. So Harvard's not equipped later is really really bad. And I think sometimes I had someone actually tell me like, we're not worried about that because I'm like, why not. So well, the data in this channel is not relevant for that kind of the hacking that could happen there. The risk is not high.

I disagree with them. But for most of us, that's not the case. So that's why I'm bringing that up there. The second thing is we just talked about the fake outs. But there's a trust now and and and forge later is the second big thing that gets gets talked about when you're in the quantum this preachy spectrum that I've been in lately. And you know, when you can get the private key and you could be the man in the middle. And we all know about that, right. Interesting. Okay. Right. How bad is that? And when if Q day happens, you don't know about it. And like, how do you get the man in the middle? Because I could forge your signature. Right. I can say I'm you. And then I could put it back in and send it to the other side. And send it to the other side and not even interrupt it. Right. Right. Like that's always been the dream. Right. From a almost have a wire tab as a hacker. I basically have a wiretapping there. And even worse, I can even assert and mongering between. You know, so you think you set up a secure communication with a business partner or a cloud provider in your sending sensitive data. When in fact, that there is an adversary in the middle, who's forged that private key and is watching everything, even as they pass it on then to its final destination. And you have no idea.

Done. Right. That's that's what those different tools you are in the security classes are there for right. These these proxies that can do this kind of thing front for one and the other. You know, it's it's pretty serious. It's incredibly serious. This is why PQC is I trying to get that out there. When you take the S off a HTTPS. What does that mean to you? And that should mean a lot of scary things. And everyone should be able to interpret like that to whatever they they're important like whether to use in VPNs to go sites that they know what people know you're going to. Or you know, you're actually conducting the rational business and you're doing strike because you have a business on a food truck or something like that. Everything in in between. Right. Even just going to social media. What do you like to enjoy and see and keep up on even those things become very graphically open. No confidentiality. So can you level set us on what is the list? You know, crypto algorithm assessment process look like. And what is it? What does it mean when this says this is approved.

And I know that could be a couple hour conversation. If you give us the thumbnail version. Yeah, I think that. I don't want to say they they approved the what they do. Or the tips right. So it's a recommendation at the end of the day. So what the government does. And what other governments are doing too, by the way, because this is, you know, US base. There's Canadian and name a country. They all have their own encryption that they're trying to use. In fact, I'm sure even our government. We have a encryption that you and I, you know, that we three and the people listening this. They don't see that. That's all government based stuff. Right. We're talking about arms there. But what the government does to make a general populist work on this thing. So we could do international transactions. So people can work with a US standard. That's what they try to do. They publish standards for this. And it starts with a. Hey, we need new encryption ciphers with different math with different techniques. And they basically put that out to the world. And it's competition based at that point. And what they'll do is they'll receive a number of submissions for, hey, I think I got a great protocol, you know, cipher for this. And, you know, I think those people are encended by the fact that I think they'd be famous in a way, right. And they want to do good for the world.

Right. A lot of good things behind their mindset. And they'll bring up the new ciphers. And then it basically they'll they'll narrow down a bit and publish them and make sure that the world. It's almost like open source in that sense. The same logic behind if everyone has access that everyone can beat it up. And every one of us together is smarter than any one of us. Right. Or so it's kind of open process with cryptographers, computer scientists, mathematicians to kind of bang on these algorithms and see what can stand up to scrutiny. Yeah. And that's a multi-year process, right. It's not a quick thing. You know, but they have a lot of them in the hopper right now. Right. There's another. We were mentioned a couple today, right. HCML Cam, right. MLDSA stuff, the Falcon. Those are the ones that are established right now that went through this process we talked about. Right. People may submissions. And they put it out to the world and people weren't able to crack it yet. And and this is good. Here's how here's the standard the OEMs then grab that and it's on them to do the delivery. And so the government also has insight into the fifth and the fifth and the fifth.

The fifth standards and this standards give you here's the algorithm and hear the parameters. Yes. But coders actually have to put that in code that goes on hardware that sits somewhere out in the deployed world. You got it. Right. Yes. That's where the government's liability is. That was of course there. They're watching monitoring stuff and it's the right. That's where you see so and the is organization. I like to say this as a network guy, right. I should be agile enough to put any cipher out there, but I don't want to be the guy to pick that's a policy decision. And that should be the security guy. Yeah. Right. I support that statement. Yeah. I'm with you. Yeah. But I'll tell you I've had a lot of discussions where I had the network and the security guys in the room and I'm like, guys, this is a relationship. You know, you're you're partnering on this thing here, but this is really should be the way as a network guy when I put my network hat. I'm thinking that I got to get out there as fast as I can. Well, we'll talk about hybrid and why hybrid is a pattern in here, but I get it out there in relevant time. So it's still good.

If I'm not picking the ciphers, that's your job. And that's and that is like you to the question you ask, like, how is this doing this? How does the US do it right now? Same way in other countries. That competition. Get it get it to a standard and let the OEMs implement them. And of course there's always a look at the implementation as well. I think they they're looking at OEMs and so are we just as customers, right as banks as restaurants as everything under the sun, right. We ourselves are also looking at this. That's what the I sac as you like the information sharing environment. So I'm scared like, hey, dude, this is not working for us, right. And it goes everywhere. I mean, so that that's the gist of it. That's how it gets done. And mindful that there it's going to be always happening. And this is another key implementation thing here. It's happening over and over. It's going to be iterative. We're not going to have a 20, 30 year cipher in the same sense because well, we're not expecting it. Right. Onum and AI together seem to be making advances all the time. I mean, heck, it's built some we've discovered some new math that we've been able to do is just without AI.

And we expect more of that. We'll get into that notion of crypto ability a little further in, but I just want to cover the my understanding is NIST has for they finalized for post quantum ciphers. Can you like give us a quick overview of each one and what they're for. Yeah, there's four, but the way to be smart, I'm really worried about the well too for the most part here. So the first ML cam, right. So the key exchange manager that that first one, he's called Kiber. So they use that old old names, right. There was Kiber, Dalithium, Sphinx and Falcon. And I think that the people that did this must have been sci-fi fans. Because I think a Kiber crystals and like Star Wars. That's right. Yeah. There's a star trek and Falcon, you know, Falcon, right. Okay. That's good. But the Sphinx, the Sphinx Plus was a more government issue. So it didn't have that much, you know, backward humor, you know, or homage. And so ML cam is the basic one you're going to see everywhere that that seems to be the standard right now the 768 version of a certain key size on that one is going to be the big one.

So if you could say ML cam, you're, you're pretty current. ML DSA is the signature part of it. So, you know, making a encryption is good, but you still have to do the identity aspect of things. So all the identity stuff we mentioned signing and that stuff. ML DSA, they're built on the same math. I barely comprehend it. And I don't, I maybe I don't really, you know, I, but you don't really need to, right. The big part is if you could say ML cam and ML DSA right now, you actually have the PQC stuff in mind. Okay. They built Sphinx. They built the S-L-H DSA to the hash based one to be an alternate. And those were in competition. We talked about the competition out there for different ciphers. The, the Sphinx one is, but the keys are huge. We'll talk about why that's bad. I'm sure, right. And there's a little bit here, but the keys are huge. That's how they win the competitions, right. Why am I going to use one of your, how hard is it for a CPU to do the math? How, how weighty is this going to be when I implement this on, when OEM implements it, and I'm loading it in and I'm configuring it on a device, right.

How's that going to affect things? How big are the keys, you know, there's, there's a lot that goes into, you know, why gets, when it's ranked above the other, but that, that third one Sphinx is a backup right now. They're trying to come up with yet another one. This goes back to the iter if thing, right. HQC, hamming quasi cyclic. I haven't even looked into it. I'm not sure exactly what that all means, but there's this HQC thing that is supposed to become the actual the next alternate for MLK, because Sphinx is very weighty. They, they, they've realized that that's going to be very difficult to move to. And then lastly, the fourth one is Falcon, and it's actually a use of last resort. It's, it's really because it's very lightweight. The IOT, right, at the Bane of existence for an network, IOT, right. It's actually for, right. We got to show the love for, for all the little devices in the field. Come on, man. Yeah, right. Then with, with no updates that don't have a lot of CPU and very little battery. It don't deal with bandwidth or well, right. All that stuff. That's why it's optimized for smaller signatures, right.

Because those low processing capability devices that are running out of battery for 10 years, right. You, it, it, it, it, at least improves their protection level somewhat, even if it's not the full hash length. Yeah, exactly, right. Again, what, what, what, what we talked about earlier, the, what data is in there, right. And you would hope that you don't give it a lot of time. It would take them maybe hack some of that, that data is not like a banking transaction that needs regulatory seven year, right. Or governments, I'm 30 years, right. We are hoping of the IOT where it makes sense there. The data in there is in the person's comment to me, like the data inside that stuff, stuff that important, I don't care about, you know, harvest down the script later. Okay. That's, that's, that's really the mysep behind it is logical. It's not just because it's weak or something like that. But those are the four ML cam, ML DSA, again, those, those are the two big ones you're going to be using. Sphinx, hopefully, we'll never have to use that when I tell you about the key sizes could be like 9K. Sphinx is the HDSA, right? Yeah, S.H.DSA, right. That's, that's the things. Well, that's the L.H.DSA. Thank you. I was used the old term. See, that's, that's, we've been in this

a while. They're trying to eliminate those names and it doesn't go for stay easily. Yeah, that one's hopefully be a backup. You're going to see a different one. The two of seven tips to some of the HQC will come in likely before that one. And of course, the Falcon, we just talked about, which is the FN, DSA, just give it the FN easier to remember. Okay. Alright, so keep an eye out for ML cam, ML DSA is you're doing your new research. Yes. Alright, so let's get into the second part of this, which is about the impact of post quantum cryptography on network infrastructure. Obviously, we've talked about larger key sizes, so that sounds like it's going to have an impact on day-to-day things like handshakes, packet sizes, so on. What, which network engineers be thinking about? Yeah, you hit that, that's exactly it. So now that rubber meets the road, we got to do a security thing. Here's the network impact, the key sizes, even ML cam, the 768, when the time it's done, the, the keys themselves are about one

K size and what time everything's done with how the things go through. I'm skipping a lot here. Alright, just, we're only a too much detail on this one, but suffice to say that when you start passing these packets, it's going to take potentially two. When you use that like 32 K, 32 byte keys, and it's 30 times that now. You got a full Ethernet packet, and then if you go to even ML cam, the 1024, the actual math that goes in there, when you only have like a 1500 byte payload for layer three inside your Ethernet frames, you're going to need to do two Ethernet frames. And that takes time, right? It's just, it's physics. If you put it in terms of that, what is it's going to take a lot of to do? And then when you consider some of these keys, if you tried to send this as a singular packet, the MCU size is in place. If you send this across a carrier network, and it's dropping packets because it doesn't like the fragmentation on UDP,

because some of this stuff does run on UDP, you see Ipsek fail. Right? So yeah, exactly. DNS, when DNS sec comes about, it's going to be a problem for us because DNS is, you know, predominantly UDP. I mean, there's a lot of TCP inside of DNS, but, and even in DNS sec, but your place is where the packet fragmentation, you might be dropping packets. And to put the two together and all of a sudden, hey, I just tried to get to my, I just tried to get the lock working on my browser. And I'm trying to connect into connections, take it forever. Why? Because I'm going to have to send like two two packets on the setup. And when I'm sending back a certain, we'll talk about the most certs now are the hybrid certs MLK, plus what they call x25519, which is classical. That should be the lipped curve, Diffie-Homan. So x25519, yeah, it's not scary, dude. It's just classical. Classical and the, our post-quang come together. And your cert is about 4k. That's three packets. No, right? Unless you're on the job of changing the

cert or just to send the cert. Just to change the cert. Yeah, just to send the cert one right. What if you got a cert chain that you wanted to express to something, right? Some applications do that. Now it's three and four certs, two, two, two, two, two, two, two. And that has to serialize, be transmitted, get to the other side. And you know, depending on, it's just going to introduce, it's not latency, but it's going to, it's going to, it's going to feel like latency because that transaction is, is going to take a while. It's connection setup. It's definitely impacts connection setup time, right? And so I can't click pay until I can, you know, log in and it locks. So let me, if I were to summarize this, there's, there are advantages to getting smaller keys, especially when I went, I need to exchange multiple keys and it given cert to keep the cert length down, right? Minimized, you know, loss. However, like in engineering, everything's a trade off, right? Those smaller keys may not provide as much protection as the longer keys.

Exactly. And there are no smaller ones in this. Like these are going up that range. And, you know, that hybrid model where you have two different types of crypto, what they do, they call it hybrid, I really would call it concatenated, but it really is like, I have the entire, you can't have half a key. You either have the whole key, you don't have the key, or you haven't hacked it, right? So what they've been doing is basically taking, you know, here's your X-D4K19, buried up with MLK, and together that becomes the key. And the beauty of that is that, you know, classical encryption might actually outlive MLK. We don't know, right? There's still, there's still some worry in there, but classical, I say for sure, how about the next, the next PQC type algorithm? So let's say HQC is another one coming up. So we have MLK next to the other one. So PQC A and PQC B is next to each other because one of them is going to get hacked. And the reason why I say that is, and this is an opinion. So make sure, you know, this is not for sure, but it is an opinion that I discussed a lot with the people that, again,

in Boston the last week of just to get an idea where all the people's heads are at, and they seem to agree, you know, why would you never not have the two different mass and a concatenated key? Because, you know, the second something is cracked, it's still, you'll have some time to get the third one in, right? And it buys you a lot of time. And that time also is not so much, you're getting it out there. We talked about the agility to get things in place, right? But it also comes back to the data being available to the hacker. So you have to crack both algorithms before you finally get to it. And we need the data life cycle, right? We want to make this last more than 30 years at least, right? That's where the time really saves you that if you had two different algorithms and do that, the hackers have to have both in order to truly access and do the harvest down to grip later type thing, right? That that's what keeps stuff from showing up again. And so, you know, it makes it interesting when you think about these are two larger keys. And right now, just with x25519 and MLKM, you know, we're looking at a 4K cert, you know, what Navis to two,

peak you see once, is it six, right? You know, like, the numbers are going to be high. And that's why there is, there's a lot of people working on this, by the way, there are, you know, what do you do when it's too big? You zip it. Well, it's the same equivalent, right? People are trying to find ways to concatenate and like, you know, to compress compresses best work. They're trying to compress the certificates to be able to pass that across there to make it even faster because the serialization and setup times. This quick break is courtesy of sponsor, I tend to know if you follow network automation, you have seen AI change how automation is done. Automation is not just about sources of truth and infrastructure as code and orchestrating scripts and playbooks and repositories and testing. Yeah, it is still about all those things, but AI adds even more capabilities. And so then the question is, how do I fit AI into my toolbox? Because you don't, you don't just start throwing data into an LLM and expect to get back to these production quality results. That's not how that works. NetObsings require that AI behaves like an engineer and that it's bound by the security we

use to cover in any technology that touches our beloved routers and switches. Itemials flow AI is all about that. It's deterministic. So for the same input, you're going to get the same output. It's bounded by security constraints and it is a gentick now and a gentick is interesting. A gentick AI is a set of agents, each with a capability that can be dispatched to gather information or perform a task. Think of each agent like a specialized tool. So flow AI can securely dispatch agents in response to network events or because you asked at a plain English prompt. And then once dispatched, they can bring back a deterministic result and then recommend next steps and then you control what happens after that. You could approve the action or deny it or refine it whatever is appropriate in the moment. Flow AI is technology that makes you a more efficient and capable network engineer. Find out more at itential.com slash flow AI. They have a white paper there about flow AI that is worth reading and you don't have to give it your contact information to read it again. That's itential.com slash flow AI and please tell them packet pushers sent you.

Okay, so we talked about the impact of post quantum algorithms on things like the central things like connection setup, other other aspects of network engineering. They're going to be affected by a PC. Oh yeah, definitely. Well, most of the operations of it, but just but right now the math is different. The math is a little harder in the sense of what the things have been made quite efficient within CPUs and stuff. So that has hardware implications. Yeah, it has a hardware implication. So the first one we talked I could talk about with just in the boot, right, a lot of devices come up and they want to secure their boot. Well, that's going to take a little longer and it might not have the BIOS that does that. And how big is the BIOS? The new BIOS that the OEM has to build. Well, if it's twice as big as it was before, was that space even on there when they designed when the engineer did a great job, right? Designed for what was there, probably made it efficient. Probably made it too much. So there's there's gear that you're going to look at and say, hey,

if it's already running at high CPU because it's already doing 10,000 BGP sessions, right? Because it's maybe it's the rusty wind thing there. It's already using every bit of its brain that can do most of it's in the A6, but the bits that are up in there when you hit it from the control plane, do you want to topple your box when you pick you SSH? You know, when when Ansible or Terraform or whatever you're using is in there trying to play with it and even managing it, right? That someone the management stations come in there. It's got some packets back inside of BGP, right? You're going to be doing a TCPAL, which is the own Pages to be password, you know, neighbor password. I'm Cisco, right? Right now. I'm using Cisco terms, right? If you're doing that, you know, even that there's encryption at that layer, right? It's as the router acting as a router, passing packets. We kind of talked about the buffering issues, right? If I have now, I've got a whole bunch of, instead of the card, a truck ratio, right? From, you know, smaller, smaller packets, you know, the frames to bigger frames, you know, now I've got a lot

more bigger frames because I'm definitely sending a full size key, right? So I'm going to see a lot more, I'm going to say, Jummel frames would frames right up to the limit, right? That have to be serialized. That's takes spaces and buffers too. And will I start seeing buffering issues, right? Is my is my router ready for that thing? So where that's just another consideration there. So the good part about that is you work with your OEM on that, right? And you do start doing startification and you start looking at the application suite that's on your network. And you find out, that I expect you're going to find out really soon that the observability kind in your environment is going to be your best friend as a network guy, right? Because who are they playing first, right? It's maybe, or it's not so much play. And sometimes they run to us just for help because they know that we're trustworthy and we do a great job, right? We have to know how things happen and we we make it real. Even a security guys, we put all this encryption into the environment. Those are controls, you know, the security guy looks at that and that's a control. That's a mitigating control. Go ahead, Scott. I can't. No, very practically. I would say, you know, the

application people don't really need to know how the network works. But the network people need to understand the behaviors of the applications that write the network. So we are often in a good and unfortunate position of having the bigger view and maybe helping figure out, okay, where is the problem really why? You know, because it is not always the network as some people like to think. Let me ask you about Max. Max act real quick. So is this going to be as simple as getting new algorithms inserted in Max act or while I need a new set of mechanisms beyond Max act or some of both? You mean, yeah, more more mech is why is it sec is the big one? So actually, I don't know. I've been brainwashed. I know that IPsec is, you know, that's no longer the way to do it. And Max act is the way to go. I'm being, you know, a little snarky here. I know. I've heard something that too. And I haven't bought in bought in all the way on that one. But um, it's, it's that acting as a router. What is, where does encryption show up? So I'm going to

router Max. That's a great one. You hit it on the head, right? I'm turning in an IPsec tunnel or a maxct tunnel on the router somewhere. And hopefully it's on a hard, we're in a dedicated slot just for security processing. Right. But you know, MD5 hashing and stuff. That's not good anymore. Right. How do you validate the OS, um, OSPF announcements, the BGP announcements, right? This is in those protocols. They also have to have that put in. So it hits those, even if you're not doing a encryption, you're still going to have a, a bit of a brain power. And is the ASIC doing that? Is the iOS or, you know, whatever OS you're putting on the router, does it even have the cipher? It will, right? Well, can they even write the code interact with it? So you do have, I mean, again, we're kind of jumping ahead. Maybe in a sense, not all your, some of your gear will, some of the gear will have no problem with it. They'll just be able to tweak the software and any things are going to work vitally on a 10 gig circuit, right? Maybe, maybe not on a 400 or 800. I know. And you know, they're going to go on the 1.6 now, right? Um, maybe it's, um,

maybe the gear is fine for the operations that you're doing. And, and you'll be fine there. But there are, there are going to be a great many that won't be able to be patched. You know, like, the thing that I would charge challenged the OEMs with is crypto agility. I can only be as agile as the management stations and the gear itself, right? And so if you're having me load a new monoliths OS on every other minute, or I'm getting bios that the Yomol fit, like that's on them. And you got to be really careful with them and do that kind of thing because it's going to, that's what's going to handle it, um, hit your heart. I think as a host itself, you know, what does it rather do? It's, it's set in net flow, right? It's getting net conf done to it or SSAging into it. You know, itself is, is, is setting logs places. It's, it's very, um, you know, itself is a host as well. And those things will have to be sent potentially encrypted. And that's, that's the other aspect you're going to see inside there. Where, where am I looking to know? Am I PQC ready? You know, or PQR people cause like, like, all post-quart, I'm ready this. Do I have PQR

on these devices? Some of them will be fine for a certain amount of time because I also, well, also caution you if I was doing budget, hairy things. And now it's kind of talking to the management level in there. You know, will you have the five years to sweat an asset and actually do the full depreciation? There is a, there is a significant opportunity and I think it's something that has to be discussed at the board levels, um, you know, especially with the finance guys, right? You're a cheap finance officer that, you know, there, there's a risk and risk has mitigated a lot of ways or accepted in a lot of ways that devices that you put out now, even though they are PQR today, you could hit a three year window where something comes up and it's like, no, we got to change the mask completely different and something else has to happen and get some devices out there. So, you know, something to put in the back of the mind. I hope they felt that was relevant to what you just asked. But yeah. So thinking of all the places where I might run into encryption on the network load balancers, firewalls, switches, routers, are there logical candidates

that folks might want to be thinking about? If they know in their existing infrastructure, they've already got some boxes they keep me an eye on because they're getting a little wheezy that are sensible candidates for a hardware upgrade or can I just kind of like, let's see what happens with the rollout. When I, when I, the vice, they would give everyone, here's mythos came out, right? And here's this frontier AI. Oh, you're going to have all these things you got to patch. And everyone, whoa, we got to do this smart. We got to organize this thing here. So it's the same thing here. Don't take this as pqs easier and you got to stick everything focused on the edge. Go right to the edge. So you're right, you know, when you're determining offloads on a load balancer, the cryptography offloads for devices behind it and re-encrypting, start there. Right? Make sure your routers are not accessible. First off, it's just to compensate and control that no one should be able to send the management packet to anything that you have on the internet, especially a BGP router, right? There should be some form of packet filtering that only allows BGP between the two

entities and nothing else hits that outside port. So be smart about that stuff, right? That, that device is not going to do so much except for the BGP itself and back to your environment. But that's it, like pqssh. Look on the edge, find those devices right away. The firewalls, the routers, the load balancers that are passing the stuff back in, let the, usually we don't own the proxies, but you know, make sure to proxy guys doing the same kind of thing. You mentioned SD-WAN devices too. Like there's two big ones though for us are SD-WAN, right? So if you have the large SD-WAN deployment, that's where it's going to, because now it's on the other end too. And those devices are going to be more suspect, I think, than the ones you have in your DMZ, they're typically a little more beefier and ready for the internet, right? And you actually have D-Dops, Action and all the other fun stuff. That's a huge one. And then the second one on that one is check your business partner connectivity's, because that's going to be, you're going to have a lot of guys on the other end that we have all those patterns, right? I bring it to you, you bring it to me on-prem type or mix, you know, I use my piece, you use your piece, right? Those are going

to be your, the big ones that you really need to buckle down, figure out stuff out first, because that's where it's exposed, right? That's where the exposure is the best word. That's where the exposure is, and that's where I would focus first. And then you move internally, hopefully you learned a lot of lessons from what you just did in the first place, and now you can move that all that logic back under the inside, and you're going to know a lot more, even how to budget for it, how to get enough heads in there, how to build automation. Automation is the key aspect of this, because you could do it once, but get a new, a new site for coming, or to roll that out across a thousand devices, or even a hundred devices, you're not going to do that real well. You did that manually, yeah. Oh god, no, right? And how are you going to get the change windows for that, right? And you have to, just the aspect of automation that people seem to forget too. I really do see that automation is no longer something you kick down right? You've literally, you're going to have to be automated, and I like to call it net dev, and say, this is to be about

dev net, and dev first. No, we are network engineers first, but we're going to have to learn a lot more how to do the scripting, how to work with the tools that we have to do like the AI ops type things, right? When as the OEMs come out with new management platforms, we're going to have to learn what does MCP mean to me? How do I do that? How do I pull the data out of there to plan my actions to do doom, you know, sources of truth. There's going to become a new word. Everyone's going to know and we have to have you have to count the cans. We didn't talk about sea bombs yet, but I mean, that's really it. You have to count the cans. As a co founder of the network automation forum, I want to go on the record drew and say, Bill and I have never met before, and noted weeks, ordinate on this particular piece of the conversation before this recording. So I was like, who is he talking to? But yes, Scott, Scott is our in-house automation evangelist. One of his videos. Yeah, yeah. I'm just going to smile because it really is. It's super important. You will be net dev. You have to be. You have to be and learning how to make change

controls and do them confidently, right? How do you start building on the digital twins? How do you have build a source of truth? How do you really certify things? That's a huge aspect for you. And just automating your certifications. You're going to see new code on different platforms of blog line, but I'm sorry, talking over you, Drew. No, that's fine. I think we're coming to the point of we've seen this term crypto agility. And what I'm coming to understand is what we mean is that, okay, you're going to go through this post quantum readiness effort, but it might not be the last time you have to do it as new ciphers, new suites, new tech these come out. You might have to think about doing it again, meaning this notion of crypto agility is this not a one and done. This is something that you have to sort of roll into your ongoing processes. No, we got definitely right. I like to think of it as the ciphers now. It's called cipher patching. And that's going to that's main making stuff up. So, you know, take it or leave it, but the ciphers themselves will be considered patches. And that's really important when you go back to poorly s off

a HTTPS. How do I explain that to the CFO? One of the things I have to explain to them because we took all the air out of the room. How do I get the air back mythos and everyone's got hot and heavy on automation and doing massive changes and getting patching into applications at different places. We can ride that train, I think. I think the part of the strategy you can use is to say, like, you have to you have to seriously look at ciphers as a security patch. And if you do it that way, then now everyone can kind of if they saw the light, if they already built, you know, cut down the jungle and they've got everyone understanding what it means, what mythos can do for you. You know, mythos is fun because you can find a hole and patch it or maybe not patch it right away. But we talked about pulling the s off a HTTPS. You can't not do that. You have to fix that. That has to be a priority. There's no way around it. You know, again, hopefully we have the double hybrid keys and stuff like that. But you have to look at this as patching. And if you look at it as patching, I think you're going to have a better time explaining to other people what you're trying

to do. They've already cut that jungle with your CFO and you're going to you're going to start seeing how you build the same they have the same change control problems. With great automation, it definitely comes great outage. Sorry, Scott, but that's that's that's not really wrong. Yeah. Right. Thank you. I'm glad you agree because you know, and that's what they don't want to see, right? You have to do this. This crypto agility has to not interrupt the business. We're in network guys. When did they let us do things? You know, like the crack of the morning, right? You know, you're three o'clock in the morning and and that's the only time you get to do it because the business is operating at a certain time. That doesn't go away. So you're going to be quick. You got to be right. You got to get it done. And you got to build that confidence in there. So your automation, your operations, you know, they would talk about AI ops and it's great to know AI ops because that's when things fail. But that's not when things evolve. And that's where automation helps you. You have to be able to evolve your network. And this is a key aspect of it. And you know, I'm sure Scott will agree

me completely right. You got to count the cans. You've got to know what you're what you're automating. First off, right? You understand workflow as is, right? And if you don't, if you don't have a good understanding of workflow, it's just like caffeine, you know, do stupid things faster with caffeine, right? I can break the network more quickly with automation at scale, right? Understanding workflow is paramount. Yeah. Yeah, exactly. I think with, you know, we thought a sea bomb. Well, I'll just kind of assert this one. I know you. That's a cryptographic bill of material, see, Bob? Yeah, cryptographic bill of materials. What is that? It's really a viewpoint. I would think attributes, right? But you have a lot of places where you probably do have inventory. I would hope the God that inside your management tool, you have all your devices in there. Most of your devices. No, but you know, honestly, like you're probably 99% 98% on a good day. We actually know where all the gear is. Right? And that's not enough. It's great that you know, it's a Cisco, a Rista, whatever, blah, blah, blah, piece, you know, my, my pile over here and, you know, F5 sitting here,

810, what name it, but I need to know is the device that's there doesn't have the room we talked about to put the new bias on there to do the secure, the secure boot is even doing the secure boot is this thing that people of doing HQC. It's coming up like I'm ready. That viewpoint is really what a sea bomb is. So how do you get there? There's a lot of tools right now that are on, on the market, right? And I'll just, you know, hey, come see me WFT. We'll help you get there because we're building programs for this. But, but you should search this out. There are tools that actually have that, they're made for that standpoint. And what they do in general is they, because you want a single pane of glass, right? I want to get a multi OEM shop. I want to get the different versions of the different hardware's that come from them and what code they're on. And at the same time, they do a little bit of probing to make sure that they've reconciled that they make it's happening. But another aspect that is often not understood or missed is that a lot of them actually put probes in your environment to make sure that the protocols are being used because there's some things just because you configured it doesn't mean necessarily didn't fall

back to something classical, right? So those probes in there to help do that. Does that make sense? Totally. Yeah. If you, a transaction is going through and you know, one end doesn't support the right cypress wheat, then it's fallen back and maybe that's against policy or whatever. And you don't know because the transaction went to, if you're not looking, you don't know. It's actually just to see, you know, the events happen every day. Ernie, you logged in. That's a good event. But wasn't an incident. The incident management was something that fall back and very well be an incident. Like, hey, someone, someone to go she had it down. That's not good. I'll give you like certain firewalls. I'm going to leave out names on this one. But, you know, certain firewalls there, they're expecting this stuff. There's some of them actually get involved in that transaction. And until you get to a certain code, one of them defaults to the classical. It doesn't let the PQC go through. So you've got to get to that new code to make sure that that's happening. So there's new losses inside of all these things. We were talking very high level today here. I'm hoping that at the end of this conversation, I hope the most persons have enough ammo that they can really start to dig in a bit, right? They

know about crypto agility. They've heard about the news cipher as a understanding of importance of what's going on. There's a lot more in and beyond what we're saying today. Not to be fearful of it. But, you know, there's changes in how people are doing signatures. And there's just an emircle trees. And there's a there's all different techniques for sharing keys that are coming out. It's an amazingly exciting new world that I hope that I can survive long enough for me to get the retirement. But there's a lot going on in this space. Well, to this later on, another question with the emergence of post quantum algorithms coming into my infrastructure. Does that have an impact on my monitoring and my visibility and my observability? Do I need tool upgrades? Do I need to be looking at different things? And even if I've got a source of truth like a net box or something else that's supposed to be collecting all of this kind of data, can I expect that to also incorporate cryptographic information? Yeah, I don't think that's going to change much from where it already is. But you do need to know things when people are crying that my setups are taking forever. Right. And do I have what looks like a network issue is really

application behavior? Yeah. Right. You got to get the guy can can help you determine those things because we talked about buffers potentially. Right. And just the base of serialization of things. So I don't I don't really expect. And again, this is going to be built in here. Like, remember that the key sizes and stuff are all in the setup. Once it's setup and the keys are established, we go to the symmetric encryption. And that's the same as it's always been. Sure. Oh, you're not going to see like all I'm going to put 30% more in all my bandwidth. Don't go to the CFO and ask you for money for that money. Kind of upgrades on circuits, right? You're nice. Maybe he'll believe you, but you know, you probably I mean, if you can squeeze it in. Yes. All right. So my first security drew is always budget for security. So network infrastructure grades forget it. But if you call a security thing, there you go. Yeah. Well, you know, what you what you said about the security stuff, you know, those controls, you know, the controls, the things that monitor these things that know about the fact when things went down, when I downgraded in the, in the ciphers that are going

on or just to know, hey, did I really get everything that I, is everything working on HQC now? Because I work at where they'll come. Where's it at? Like, there's still need to be probes, right? And and things to do that. So you're going to see a lot of the security devices need to understand the firewalls, especially. You know, they they're going to see transactions going across them. So if you're doing, if you're doing, we'll call integrated firewall stuff inside your routers and switches. That's where I think it's going to you're going to feel the most. Okay. As a direct answer to that question. You know, and it just as a mother implication for the networking team, right? You now's a really good time to look at your network architecture and your processes. If you start to think about, okay, what's it going to look like to do software upgrades and hardware upgrades to accommodate, want them safe crypto, just on my infrastructure? Like, you can start thinking about that now before 2029 and 2031 and where you, where you might want more redundancy

to keep a service up while I'm taking something down for upgrades. Like now's the time to be thinking about that. Yeah, you, I can tell you've done automation because you're right on the money, right? Because I know that you're going to you're going to queues things, right? And you're going to move the move to one side, make the changes, validate, validation is a big thing. You've got to use the V word, right? You've got to validate that stuff before you bring it back in the cycle and then we're going to repeat ad nauseam there. I think it's hard for never guys to sometimes want to give up the reins a little bit on the fact that you're going to you're going to do what you did before, but you're doing it through, you know, through the script and and you're it's a process. The process doesn't change. It's how it's affected seems to be the the the terminus thing. And, you know, you shouldn't be afraid of that. You should have you should like run to it, right? And but it's amazing how many people don't know what the processes they do because now everyone's got to do things the same. And I think that's that's a lot of the the the inertia that people face. You know,

well, I have the tread network engineer mindset, right? And it's culture culture is powerful, right? And when you identify as a CCIE, like I am a CCIE or I am a JNCIE and I am a JNCIE. You know, you like I have muscle memory for those, you know, CLI commands and, you know, we still got to do the same things, but they're implemented and and affected in different ways. Yep. Right. And you know, it's I think a somewhat scary, I guess, for some that, you know, you're going to start using air assisted stuff, right? Like I myself now I'm fine a lot with that. And I wouldn't write my scripts the way I did the four even. And it's easier. And I think there's it, but it is a brave new world for someone who's not done it before. And culture is everything. Col, the culture of your team is is paramount. And, you know, hopefully you can bring these changes to that culture. Yeah. Because it there is no room to not do it. Right? People should be

get off this call. Scott leads to take the lead. And we need they need to talk to you about automation because that is you have to start planning that. And that means everything from, you know, what can I do today? You got to go to your LCM and go, if I'm buying gear that's not even considered PQ ready, right? If my OEM is even have a roadmap on it, don't deploy that. Right? So you've got to start at the LCM there. Look at the edge right away and start building your C, you got to have a C bomb. You got to count the candy. You hadn't either have that cryptographic viewpoint, the attributes of the devices that you have in your environment. Know where those are. Start finding them. Make sure your source is the truth or whether at, right? So that you can overlay that that that PQ awareness to those things there. You've got to get out there and find all the cans, right? Count I say that because I used to work in a grocery store, right? And you got the count pants. What was stolen them? I was broken and all that kind of stuff, right? You know, you can do that today. There's no reason why you can't be doing that. You should only look at your certification plans. Start updating those things. You're somewhere in there, you're not just throwing code out on these, these switches, right? You better be certified in the some point.

Do you have test tools to do that? You'll go get them, right? You'll go figure that kind of thing out. So you know, there's, there's some of the simple things that are that you can do right away that start making you PQ ready as an organization, right? That just says the devices. It is, is a cultural aspect that you have to, you have to take on. It's going to be, I really do think like some of this patching on this is almost like you're going to be in the JNCIA or in the CCIE exams. Like, you know, how do you recognize these things? How do you automate that stuff? How do you, how do you make sure that your SIFT was in place? Is this playing room for it? Did you really configure BGP to, is it secure now? Right? The other thing that was PF, right? The LSA is where, what's going on there? You, it's going to be at least some kind of consideration. Bill, I think you've given everyone a lot to think about. One, don't write off post-quantum, it's, it's a thing. And whether you think QD is coming or not, some organizations do, and they are taking steps and so should you. So just, final thoughts on, you know, four network engineers,

how to be thinking about this, how to bring it to the organization, and how not to freak out. Yeah. All right. And I hope that that's what we did today. I hope we didn't freak anyone out. This is business table stakes, right? Everything you hear in here is table stakes. There's, there's more to the story. But, you know, those things will come after you've started to take the viewpoint of, it is true, it is real. You know, it is super important when you take the SIFT HGTP. So you have words on how to make other people be aware what you have to do. And as a network guy, let people know, I have to do a lot to make this happen. This is not just a security thing, the CTO and the CSO need to be going in there. So again, that, that's really the goal of this one. You should have that much. And if you want to learn more about it, I'm, you know, I'm on LinkedIn, you know, for that matter. And I work for WWT, right? I work biggest and a greater out there, right? Happy to work with you and your organizations, I was a little pitched there for that. But, um, that's, I want to leave it there. All right. We'll, um, leave Bill's, uh, LinkedIn in the show notes,

or you can go, uh, find it itself, Bill Dockery. He is on LinkedIn, but we'll have that link in the show notes. Bill, thank you for being here. This was a really good discussion. And I hope it did give folks a lot of places to hike into this because there are a lot of ways to come at it. But yeah, post quantum is coming. It's real. And whether or not we know when Q day happens, things are happening. So I think the best time to start your post quantum plans is probably now. Bill, you're online. It linked in any other place where folks can find you or do you blog? Do you do do anything else? Twitter, handle it? I'm not in a network space. I do a lot of more short stuff. I have two books, Ikeysecrets.com. But that's where I usually put my after hour stuff. I try to stay away. So, but I can link it in work. So, okay, very good. That's cool. That's nice to know you've got hobbies. All right, well, that does wrap it up for this episode of Heavy Networking. And Bill, thank you for having made this a very heavy episode indeed. Scott, thanks to you for joining in stepping in. It was great to get the automation perspective and the practical perspective, as you always bring. You can find this in many more podcasts at packuporshut.net. We've got so much

plus a Slack group YouTube channel. You can watch this podcast at BeFord instead of listening. And so much more always at free at packuporshut.net. Thanks for listening.

More episodes

More from Heavy Networking

View all episodes →