by

Microsoft speeds up quantum-safe security plans

Software King of the World, Microsoft is dragging its quantum-safe security roadmap forward as quantum computing starts looking less like a distant lab toy.

According to Bleeping Computer, Vole has announced that it is accelerating its quantum-safe security roadmap. It said advances in quantum computing mean today’s encryption standards may need to be replaced sooner than previously expected.

Today’s quantum computers cannot crack modern encryption. Security researchers have continued to warn about “harvest now, decrypt later” attacks, in which encrypted data stolen today is stored until future quantum computers can decrypt it.

That would expose sensitive information years after companies thought it was safe. It is a nasty little time bomb for anyone sitting on long-term secrets.

As a result, companies including the Fruity Cargo Cult Apple, Google and Signal have begun integrating post-quantum cryptography. The idea is to replace existing public-key encryption algorithms with quantum-resistant versions.

Microsoft said it plans to move “critical products and services” to post-quantum cryptography by 2029. The move is part of its Microsoft Quantum Safe Program, while quantum-safe requirements are being added to its Secure Future Initiative.

“For years, planning for post-quantum cryptography (PQC) was framed as a future problem: important, inevitable, but distant,” Vole said in a blog post.

“That perspective is evolving as technology advances and organisations prepare for the scale and complexity of the transition ahead.”

Microsoft has encouraged organisations to prepare for post-quantum cryptography for years. Now it says advances in quantum computing mean the transition needs to start earlier than expected.

“Advances in quantum research and development have shifted the risk horizon,” Microsoft warned.

“We believe cryptographically relevant quantum computers could arrive sooner than previously expected, and the work required to prepare is significant, so organisations need to start now.”

Microsoft said its Quantum Safe Program is being accelerated to transition critical products and services to post-quantum cryptography by 2029.

Rather than simply grabbing new cryptographic algorithms and hoping for the best, Microsoft said organisations should modernise their infrastructure first. That should make future transitions less painful when the next clever maths scare turns up.

The company said its first priority is upgrading network cryptography by adopting modern protocols such as TLS 1.3. That would support future hybrid and post-quantum key exchange.

It aims to build “crypto-agility,” enabling cryptographic algorithms to be swapped for post-quantum variants without requiring developers to redesign applications.

Microsoft wants to modernise cryptographic trust chains used for code signing, certificate issuance, software updates and hardware-backed key protection.

The company said that putting its post-quantum plans into the Secure Future Initiative will allow it to track quantum-safe readiness alongside other security goals.

Microsoft has not publicly detailed which advances prompted the faster roadmap. It has not explained why it thinks quantum computers could arrive sooner than previously expected.

Asked by BleepingComputer what prompted the accelerated timeline, Microsoft Azure CTO Mark Russinovich said the decision was about risk management rather than one specific breakthrough.

“Shifting to quantum-resistant security takes years. This is a proactive, risk-informed decision to help customers stay ahead of potential future threats,” he said.

Asked what falls under the “critical products and services” being transitioned by 2029, Russinovich said it refers to “the entire portfolio of Microsoft’s products and services.”

 

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews