France's Anssi Will Block PQC-Free Products from Certification Starting 2027
Sami_Lehtinen
92 points
48 comments
July 21, 2026
Related Discussions
Found 5 related stories in 256.3ms across 14,369 title embeddings via pgvector HNSW
- A Post-Quantum Future for Let's Encrypt SGran · 241 pts · June 03, 2026 · 59% similar
- Cloudflare targets 2029 for full post-quantum security ilreb · 304 pts · April 07, 2026 · 54% similar
- We need Post-Quantum Cryptography more than ever ethanhawksley · 14 pts · April 13, 2026 · 47% similar
- GnuPG – post-quantum crypto landing in mainline zdkaster · 12 pts · April 26, 2026 · 46% similar
- France to ditch Palantir's AI data tools in favour of domestic provider devonnull · 27 pts · June 17, 2026 · 46% similar
Discussion Highlights (7 comments)
cold_pizz4
Related: https://news.ycombinator.com/item?id=48992806 (Are 128-bit symmetric keys really secure against quantum computers?)
vaadu
Will they decertify previously certified PQC-free products?
tsimionescu
I'm very curious how much people will look back on this frenzy of PQC migration panic by 2050 when, my bet, there still won't be any remotely viable QCs. The decade plus of even slower TLS negotiation that this will bring in the name of "security", after so much time spent previously on improving encrypted connection latency, will seem quite comical, at least.
colmmacc
I was at ANSSI headquarters last year doing a technical presentation and several of their questions were about Post-Quantum Cryptography, "Q day" (when a practical Quantum Computer is expected) and other related things. They keep a close eye on this stuff and it's to their credit. Similarly the BSI in Germany have been promoting Post-Quantum security for some time now. I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!
dredmorbius
PQC: Post-Quantum Cryptography. The concern is systems which won't be resistant against quantum cryptographic attacks. The US's NIST has an explainer page, "Post-Quantum Cryptography PQC": < https://csrc.nist.gov/projects/post-quantum-cryptography >.
6r17
TBF it's the healtiest approach to it. It's just risk mitigation. Nobody cares about it - there are nice papers to implement it ; just freaking do it.
dylan604
From TFA: "The policy reflects growing concern about Harvest Now, Decrypt Later (HNDL) attacks, in which adversaries intercept and store encrypted communications today with the intention of decrypting them once a cryptographically relevant quantum computer (CRQC) becomes available." Once it gets to be "later" where the harvest data is able to be decrypted, I guess will have decent enough LLMs to summarize all of that data? Otherwise, there's going to be such a huge back log to make it not too useful