Q-Day Countdown: No More Privacy? – WS 08 2026

From EuroDIG Wiki
Jump to navigation Jump to search

27 May 2026 | 16:30 - 17:30 CEST | SICCO MANSHOLT | Video recording | Transcript
Consolidated programme 2026

Proposals: #9, #48, (#49)

You are invited to become a member of the Session Org Team by simply subscribing to the mailing list. By doing so, you agree that your name and affiliation will be published at the relevant session wiki page. Please reply to the email send to you to confirm your subscription.

Kindly note that it may take a while until the Org Team is formed and starts working.

Check the discussion tab and the mailing list archive for information on the development of the session.

Session teaser

Could a single computer one day reveal every secret you’ve ever sent over the internet? From medical records to private chats and banking details, the digital locks we rely on are facing a looming threat: “Q-Day”. While large corporations and researchers race to build more powerful machines, we are left wondering what this means for our everyday privacy and the future of our (digital) lives. To protect our digital future, we must begin today.

Session description

The session addresses four key questions: (i) the importance of encryption in safeguarding personal data; (ii) how powerful quantum machines will challenge digital security; (iii) how to prepare for a quantum future by deploying stronger protections; and (iv) who bears the responsibility for ensuring Post-Quantum Cryptography (PQC) security.

Format

This is an interactive workshop where you are invited to present your views and ideas. The session is structured in three parts: each begins with a brief introduction by our panelists to set the stage, followed by an open forum for audience participation. We have designed this format to ensure that your concerns and questions take center stage, with our experts acting as facilitators for a community-wide conversation.

Further reading

  • Over the Quantum Cliff: How will we live once quantum computers spill all our secrets? [1]
  • Socio-political and technical impacts of IoT and PQC policies [2]
  • Migrating Telecom to quantum-resistant cryptography on a global scale [3]
  • Quantumveiligheid in onderwijs en onderzoek: bewustzijn is er, actie blijft uit [4]
  • EuroDIG 2025 messages [5]

People

Programme Committee member(s)

  • Filip Lukáš, Policy Advisor at CENTR
  • Nicolas Zahn, Senior Engagement Manager at ELCA Advisory, Managing Director of f0t1 GmbH and the association Swiss Internet & Digital Governance

The Programme Committee (PC) supports the programme planning process throughout the year and works closely with the Secretariat. Members of the PC give advice on the topics, cluster the proposals and assist session organisers in their work. They also ensure that session principles are followed and monitor the complete programme to avoid repetition. 1-2 PC members have signed up to each session and will compile the messages.

Focal Point

  • Frederic Taes, EURALO

Focal Points take over the responsibility and lead of the session organisation. They work in close cooperation with the Programme Committee and the EuroDIG Secretariat and are kindly requested to follow EuroDIG’s session principles

Organising Team (Org Team)

List Org Team members here as they sign up.

  • André Melancia, Technical community, Portugal
  • Wout de Natris - van der Borght, DC-IS3C
  • Karen Mulberry, Senior Manager, Public Affairs, IEEE Standards Association (IEEE SA)
  • Callum Voge, ISOC
  • Smee Cujic, BSoG
  • Biljana Zasova

The Org Team is a group of people shaping the session. Org Teams are open and every interested individual can become a member by subscribing to the mailing list.

Key Participants

  • Benoît Ampeau, Director for Partnerships and Innovation, Head of Afnic Labs
  • João Moreno Falcão, Cybersecurity Specialist and Vice-Chair of the Dynamic Coalition on Internet Standards, Security and Safety (IS3C) Working Group on Emerging Technologies
  • Wout de Natris - van der Borght, Internet Governance Consultant and Coordinator of Dynamic Coalition on Internet Standards, Security and Safety Coalition (IS3C)

Moderator: Smee Cujic, Advanced Master’s Student at BSoG

Messages

Rapporteur: Nicolas Zahn, Association Swiss Internet & Digital Governance

  1. Loss of privacy is seen as the most pressing concern regarding digital security in the post-quantum world by the workshop participants. Q-Day is not a far-distant threat but already a partial reality, as the first successful breaks of encryption using Quantum computers show. And since post-quantum effects almost every aspect of our digital lives, we need to start today. For organizations (public and private) more clarity is needed on where encryption is currently used.
  2. Technical standards are only part of the answer. We also need the awareness and resources to help organizations with the deployment of new standards. It will also need to become a part of the mindset of decision-takers, as Q-Day is a structural issue that needs coordinated actions and cannot be addressed on the individual level. In terms of responsibility for the PQC transition, participants are split between governments and service providers.
  3. A potential element in a government roadmap could be capacity building for procurement officers to ensure secure-by-design ICTs.
  4. Organisations must not wait and start their preparations for the PQC-transition now. Tomorrow might be too late

Video record

https://youtu.be/-Sr1Oman7fc

Transcript

Disclaimer: This is not an official record of the session. The DiploAI system automatically generates these resources from the audiovisual recording. Resources are presented in their original format, as provided by the AI (e.g. including any spelling mistakes). The accuracy of these resources cannot be guaranteed.

The Geneva Internet Platform will provide transcript, session report and additional details shortly after the session.


Smee Cujic: the moment anyone presses to speak, it automatically takes over from the current speaker. So be aware of that when trying to speak. Maybe when it comes to the room, same as online, they can raise hand, right? Perfect. So please raise your hand before speaking so you do not interrupt the previous person. As I said, we have our experts here, two in person and one online. And in no particular order, I would like to introduce Benoit Ampour on my right -hand side. He is the Director for Partnership and Innovation, Head of Ethnic Labs. Then we have Wout De Natris, the following. He is the Internet Governance Consultant and Coordinator of Dynamic Coalition on Internet Standards, Security and Safety Coalition, ISEC.

And we have our speakers. Online. Hi, Joao. Jean Moreno, he’s a cybersecurity specialist and vice chair of the Dynamic Coalition on the Internet Standards, Security and Safety, working group on emerging technologies. But before we start, I would like to see what your thoughts are. Can we share the Mentimeter? Okay. So we have a question. What are your most pressing concerns regarding digital security and post -quantum world? It’s using the application Menti. You have the QR code on the right, and you can also go to menti .com and give really the number just there. And there are five options. The first one is the loss of privacy and identity theft. It’s computing, breaks the encryption, protecting all your secrets from a password, a banking personal message.

That’s the first one. The second one is not knowing digital signature, contract, or identity is authentic because encryption is so used to sign contracts, to know that you are talking with your bank, the bank to recognize it is you. That’s the second one. The third one is the organization’s current slow adoptions. Of quantum computing resistant technology. due to the cost complexity or not knowing, not enough conscious on what needs to be done. And the next one, the fourth one, is only wealthy nations and corporations can afford advanced post -contrum security. That could be one of your concerns. That’s not accessible for, say, poor people, only from rich companies and countries or others. And if there are some others, please select that option, and you will be able to explain here what would be this other.

Yeah. Thank you. I see that we have already 29 answers. And you see it here. This is really the privacy. It’s a much bigger concern currently, but we have also some others. The identities, verification, signatures, and contracts. And authenticity, the slow adoptions of… post -quantum resistance solutions, activations, and others. 31 answers. Still a few seconds to answer. I don’t see more answers, so those are the answers here. I think we have a majority here, but I will let now our speakers tell us their thoughts about it. Wout?

Wout de Natris: Thank you, Smee. Smee, as I’ve been introduced, I will not do it again, but I do apologize for my voice, which, believe me, is a lot better than a week ago. I want to play a little bit with your mind to start. Just imagine a world in which all locks, all of a sudden, don’t work anymore because of a magical invention. So, of your front door, of your car, of your bank vault, whatever, they don’t work anymore. what would happen with everything you own would be an immediate risk got that in your mind? then we’re going to go to the day the first quantum computer comes online and we have not prepared ourselves as a world to protect our devices, our connections our email, our bank accounts our bitcoins, etc it would be the same situation if you would not be protected by your locks anymore but only online so the question then also is who turns on that first computer?

is that a benign someone who wants to make the world better or is it a malignant somebody who wants to attack you immediately? but if it is at a university where all of a sudden somebody has a eureka moment or has made a mistake why all of a sudden it works and they don’t know how but it works and that university has been hacked by a criminal gang somewhere in the world that they can’t be reached and they’ve been hacked for years so they build everything they know into the machine they have so that is a situation that we may face but this is something we can prevent for but that does mean there has to be a transition of just about everything online think of your mobile device, your laptops but your connections, your IOT devices, your sensors whatever, they all will need to go into a transition and that is something we can’t underestimate because this is not something that one person can decide or two persons decide it will be a worldwide necessary decision of people who know nothing nothing about this topic, but will have to be convinced that this is a step they have to invest in and it’s a step that they need to take to protect themselves and to protect the rest of the world and their customers, their own clients, etc.

If you look at the past at internet standards where they had a session next door in the other room an hour ago then the experience is not good. The original internet standards worked like a miracle because they were invented over 40 years ago and they connected the whole world. So it works perfectly except that they’re not secure. They were not made to be secure because there was no necessity to make them secure. The technical world came up with new standards. If you look at deployments and figures in the world depending on where you live it could be even, for example, DNS security less than 4%. of a country, while others perhaps reach 50 or 60 percent. So that is something that needs to change.

And although in the previous session someone said Y2K, the moment of the millennium bug, is not a good example, I do think it is. For this reason, everybody has to move around the same time. Yes, the difference is there is no single date. We can’t say 1st of January 2000 it needs to be done. But we do know it has to be done by 2029 or 2033, whatever. So in that sense it is about motivating people. There’s coming a day that you need to transition otherwise you’ll be too late, because not doing it means you lose everything. And then I come to my own dynamic coalition, and João will tell more about it, and Benoît has been working closely with us also because he strongly believes in it.

What we will try to do… is start expert working that is going to look into the topic from several angles. So not create any standards because that’s done elsewhere. But what does it mean when the standard is there? What does it mean for an organization that needs to deploy it? What will they run into physically and technically to actually deploy? How do you convince your boss that this is something he needs to finance because otherwise there will be an issue with his company later? So that’s the sort of topics that we want to address in that working group. We have the experts. We have people who are technically very feasible to be able to professionally assist the volunteers.

And we have me doing the coordination and organizing everything. But we do need parties who want to join it. And we do need parties who are able to finance the professionals. So that’s the invitation that we can discuss perhaps later. But that’s also where I’m going to stop my story now, because I think the issue is quite clear. And put that thing about the keys and locks that don’t work anymore in your mind as an example. Perhaps convince or discuss it to others. Thank you.

João Moreno Falcão: My turn? Yeah. Okay. Hello, everyone. Greetings from the Brazilian IGF. So I want to bring here in this first moment what we are seeing that we know it will change and how it relates to our fears and what you already strongly showed. So quantum computers, like quantum physics is a… reality. Every single computer only runs because we studied and we know quantum phenomena enough to make the computer work. But for the first time, we are being able to use quantum features to run algorithms. So when we are capable of using, for example, superposition inside a computer, we can expand a lot on what we can do. And this means that we can attack the public key infrastructure that we have now.

And this breaks integrity, this breaks authenticity, and with this, we know. for a fact that privacy is at risk when this powerful enough quantum computer appears. And as Walt said, we don’t know yet when it will happen, but we already know about Simplify, the text being executed in the quantum computers we have now, and we know that this will expand in the future. So, this systemic attack needs to be tackled. And what we did, me as an IS3C researcher, was to look after what governments were doing and how they were tackling the change, because we need to improve the systems, we need to make them safe. for when this new quantum computer comes, because it will put at risk our privacy and identity, because with this kind of computer, we can undermine the securities that we have now.

And I’m pretty happy that everyone sees this way, the quantum risk, and I would love to hear more about what you have to say. Thank you.

Benoît Ampeau: So I won’t add a lot, but we are, as AFNIC, a very proud member of the IS3C Dynamic Coalition. Now I will speak, and we will maybe dive into the infrastructure layer. So I speak here from the… a DNS registry operator perspective, running .ifr, but also French overseas territories, but also other ccTLDs and gTLDs. So my job and the job of my colleagues is to keep and contribute to an Internet which is open, secure, and stable. That being said, for AFNIC, the question is not only to choose, but how to preserve this interoperability and stability and trust at the DNS scale. So post -quantum cryptography is not just only a crypto topic. It’s also a very concrete operational topic.

As an example, so we operate a critical registry service at Internet scale, so the operational questions are very concrete. Can we sign zones in time? Can results? Can servers validate DNS names correctly? or can services remain interoperable during the transition? So with that framing in mind, the question is simple. Why does encryption matter in the everyday Internet people users? Encryption is now a condition for trusting everyday digital services. We already have DNS privacy and security improvements. I can quote and state DNS over TLS, DNS over HTTPS, or DNS over QUIC, but they mainly protect confidentiality on the transportation layer. It’s important and complementary to authenticity and integrity. That is why DNSSEC remains essential, because it lets resolver verify that DNS data really comes from the right source and has not been hacked.

Change tempered with during the transit. Let’s give me also some two examples. You might know SPF, DKIM and DMARC. These are email authentication standards that help verify whether a message really comes from the domain it claims to come from improved deliverability and better handle incoming messages policy on the recipient’s site. They use, they rely on the DNS. ECH, it’s a newer privacy mechanism for TLS that hides more of the secure session setup, but its configuration is distributed through DNS. So weak DNS authenticity can still put the ECH negotiation setup at risk. So encryption protects trust in daily internet services, not only secrecy. DNSSEC gives authenticity. And integrity. So it becomes even more important when we look at the quantum risk.

Thank you.

Smee Cujic: Thank you very much. I would like to open the floor for audience at this point. Are there any interventions? First, let’s see in the room. Okay, is there anyone online? No, not seeing. So hearing that people are very much concerned about their data and seeing how actually comprehensive an impact of having a quantum computer that can break the encryption matters, what can we really do about it at this point? Is there something that we can start with? just a moment, I see a hand yes, go does it work?

On-site participant: well, I just admit I’m not from the tech community, I’m from the EURODIG board and what I see, well I’m coming from the business side and businesses, not tech business, and just normal businesses and they don’t know whom to ask if they ask the big universities, of course you end up with some nerds, if they ask some NGOs it is just hell and doom, if they ask whoever, so who should actually ring the bell in a meaningful way meaningful, I mean just as if reading Financial Times, is it Financial Times? Financial Times, that should go to media, trustworthy media, who should tell it? So while I fully understand we have discussions about it, but actually from talking to you, it’s not the same as if I read it in the Financial Times.

Wout de Natris: I think that is the $64 million question, to paraphrase Crouch or Marx. But I haven’t got the answer yet, because where do you literally start? I think that is by having the right sort of information that is not only alarmist, but also proactive toward a solution. And with that message, you have to start doing the right outreach. And that would mean talking to people that you’ve already… already invited into the process at some period, so that they understand what it is about. But in the end, you arrive… an organization like the Financial Times or the Economist or that sort of trustworthy papers should be starting to addressing the topic from a non -alarmist point of view.

And I’ve been alarmist here deliberately to set the stage, but that is not the way you convince somebody because they will probably run away saying this is too difficult. Perhaps João or Benoit, you have another answer to get on

Benoît Ampeau: Maybe a piece of the answer. Assuming that you are considering that this is a technical transition you need to do as any technical transition you need to make for your business to run from the server side, software side, whatever. So you, I’m sure, you have training, certified organization. close to you that could deliver and help you also to have this approach having like being prepared how to transition and how can I set up the services once the standardization will be mature enough so forth and so on so I think this is also a way to look at the thing so about awareness it’s a thing but also considering that it’s a technical transition we have to do and I’ll follow up again

On-site participant: I’m a cyber security professional I’m from the technical community just last month a researcher cracked a 15 bit ECC using a quantum computer with only 70 qubits while that’s far smaller than the it’s a it’s a 256 -bit ECC protecting Bitcoin today, it’s the largest public quantum attack ever demonstrated. It shows that the Q -Day isn’t a distant theory. It’s already unfolding in real time. If such breakthroughs keep accelerating, our privacy and financial system could be exposed much sooner than expected. Thank you.

Wout de Natris: I’m talking about a technical transition. But quite often, the transition is not just technical. It’s about convincing the right people that we need to make the technical transition. Because quite often, you hear that… technicians have been trained to do the transition to DNS security for example but then they have to explain it to the CEO or CFO and he just asks what does it cost me and that’s not what we’re going to do today so in other words it’s not a technical transition, it’s also a mind transition of people have an understanding that they need to act now because otherwise they may lose a lot and I think that that is where the disorder discussions on a higher level at some points will help us

Smee Cujic: Just a moment, João.

João Moreno Falcão: Okay, thank you I read today an article co -authored by Google a researcher from Berkeley and one from Stanford saying that envision attackers much sooner than they were thinking before. So they did research focused on cryptocurrency, as Talaika mentioned, and they said that they advised everyone to migrate to post -quantum cryptography at most in 2029. So advancing seven years than what the U .S. government created in their guidance documents. Thank you.

Smee Cujic: We have intervention.

On-site participant: Hello. All right, great. So thank you for your attention. My name is Siva. I’m a university student. I was two years ago. I come from a technical background, although I’m not an expert in any shape or manner. So my question is, first of all, unless I’m mistaken, I think there exists complete cryptographic suit. It came out from NIST tournament, let’s say. So we do have post -quantum tools. So as it’s been mentioned, it’s mostly an adoption problem. So my question would be, what are the major obstacles between adoption and our current situation? Of course, economic burden will be one of them. But since the problem is so major, one wouldn’t imagine that we’d have such difficulties.

And especially I’d like to hear the business side, since we have a very diverse array of points of view here. And the second question. It’s maybe a bit more technical, but there is surface level. What should we do with the data that’s already been exposed? I’m talking about a collect and decrypt later strategy with, for instance, a malicious agent who stores encrypted communications that are vulnerable to quantum computers. Maybe should there be laws that force companies to change credentials? What are proposed mechanisms against this sort of scenario? Thank you very much.

João Moreno Falcão: Yeah, thank you. So the first thing, I will use a slightly different vocabulary just to differentiate two things. What Nest created are cryptographic algorithms and they sign it saying, okay, this is trustworthy. But what we need to develop are cryptography protocols, so the security protocols, because we know that this algorithm is here and can be used, but how can we translate this to the tools that we use in our daily basis? So what this means that RSA is essential, it’s everywhere, and it’s vulnerable against quantum computers. And this is used in TLS, this is used in DNS, this is used elaborate curves are used in Bitcoin and they are vulnerable too. So we need to translate these trustworthy algorithms into secure protocols.

And the second part that you pointed is something that we really want to discuss here on what should we do. And I picture my answer for this into four topics. And this is also in our report when we are advising on the next steps. The first one is that we need to develop cryptographic inventories. What this means? We need to understand where cryptography is used and using which algorithm. So in this way we know what needs to be done. To change to be resilient against a quantum computer attack. The second part we need to prioritize because, you know, resources are limited. And first, we need to protect what is most dear to us. The third one is crypto agility.

And this is another jargon that means how can we use the protocols we have, the security protocols we have, to implement and to use new crypto systems inside them. So TLS used to have triple deaths in their structure. It’s not secure anymore, so it’s been dropped by like 99.99% of the places using TLS. But… Now we use ellipid curves, we use RSA, and we need to go further and implement new… not we as ISRC, but we as the society. We need to define how we are going to change the protocols and then move towards that. And of course, we need… a coordinated deployment because we are speaking of thousands, millions of devices all around the world talking the same language and we need to keep that and like without allowing places to be vulnerable that can undermine the whole structure of the internet.

Smee Cujic: Thank you very much Joao. We have intervention in the room. Yeah just press one more. Okay yeah great yeah

On-site participant: I would like to circle back to the point of technical transition not being only technical one but also a mind transition and I would also add ethical transition to that and the great example is UNESCO’s commerce work. which kind of outlines that protecting privacy and human rights remains a central priority as countries and member states pursue quantum advantage. So that would be the first point. And then the second point, I think that research and human rights and security always need to work hand in hand. And a great example is a Quantum Austria initiative where they have funding and support to boost research and innovation. And to wrap this up, I think that member states should build upon the legacy of UNESCO’s work and maybe also try to follow Austria’s example.

Thank you.

Smee Cujic: No additional interventions? No, perfect. Oh. Thank you.

On-site participant: Hi, excuse me. My name is Aaron Gallagher and I’m a participant of this year’s Ute Dig. And I just have a question for the panel, as I don’t come from a very technical background myself. And I suppose my question really revolves around, is there any steps that we as individuals, as opposed to society, can take, I suppose, in preparation for Q Day? Thank you.

Wout de Natris: Thank you. That where large corporations and governments are concerned, things are different. One organization may offer a service provider or IoT device maker or whatever. They provide a lot of security and others don’t. When you procure, if you don’t procure your ICTs secure by design, you buy off the shelf. And that means you’re handing yourself over and all your data over to whoever. You don’t even know if it’s secure or not. So if governments, and that is, I think, one of the outcomes of the project that I was mentioning that we want to start, is a sort of roadmap saying what sort of solutions there are available for you. And one would be a capacity building program for procurement officers saying you need to procure securities by design and make sure that there’s enough examples in that document that they can actually start using it.

And that would mean as an individual. that if you want to look at your service provider today, then perhaps you could see that they don’t offer DNS security to you or they don’t even, the HTTPS, for example, that is not even included with some, that still happens. That means that you have the opportunity to move elsewhere. But you have to check what the level of security it is they’re offering you. When you’re buying IoT devices, perhaps you can check the list saying, is there any security in place so that not everybody can access that baby camera that you want to install in your room and that it’s closed. So that’s the sort of thing you can do as an individual, but not in the greater scheme of things.

And that’s where governments and larger corporations have to start giving the right example.

Smee Cujic: So just, I’ve noticed there’s another comment, but for the sake of the… having the session happening on time I would like just to do the second Mentimeter that builds perfectly on this one and it is about the responsibility where it should lie.

Frederic Taes: Thank you, Smee, so the responsibility of being quantum secure should be with governments, that’s the first option with service providers, second possibility individuals, that would be the third option or the internet community in general with ITF, particular internet society I can order, stakeholder organism or other, and if you choose other, please elaborate afterwards which other stakeholder should take it Do you see here? No, you don’t see? Okay, so I need to share again, yeah, I see I share my screen, I will share again Okay and authorize, okay and this this okay this one here this one okay you can see it okay so that’s the same code again on meti .com you have the qa code and you have the responsibility of being quantum secure through with government service providers individuals internet community or other and i see that there are some others and even a majority so you please elaborate afterwards if you are in the room or online please raise your hands to to explain who should act thank you so we have 14 answers we should have more i see that service provider now is growing governments you can also select you the different ones, but I see that individuals looks to be really the…

How to say that? With no option and no action to take. Just what we have discussed before. Yeah, see even now a majority of order. So not governments, not service providers. Few for individuals and internet community. So if we have someone in the room maybe to start and to share what the orders could be. For people having answers order. S

On-site participant: o I was just wondering instead of asking the question or just pointing fingers like who is going to be responsible. Maybe we could say… Think about in layers like people, process and technology. You mentioned procurements. And this is talking about debates, technology standards, supply chain developments, and then people, whether we are as citizens in different organizations, stakeholders, and, of course, as human rights perspective, and how we are responsible from beginning. I mean, cyber hygiene is different on different level and digital literacy in different countries. And you mentioned transition. It is a process and it is a kind of a roadmap. And the roadmap would be different in different countries and region. And I’m afraid if there is a transition, then we need to, I’m kind of thinking ahead, is this going to be, again, some kind of digital divide if we’re not ready at the same time to go from point A to point B?

in a same way, and it’s not going to be the same way. That’s definitely, we’re all in a different path for this. It’s kind of tricky, but maybe if we discuss it on layers, different layers, it’s going to be easier for the country to make plans, action plans. And if we talk about citizens layers, then how do we prepare this? If we talk about who’s responsible? Otherwise, this kind of question, who is responsible, is just pointing fingers and saying, getting rid of the accountability, and I think we’re all in it together. My name is Shamira Ahmed. I’m from TU Delft. And just to add on to what the… former speaker highlighted, it is a joint collaboration.

And actually, we’re working on this with UNESCO on an ecosystem perspective on how to advance responsible and safe quantum transitions. And we have a session at RISIS. If you’re going to be there, please join us as part of the workshop as we collaborate on creating an ecosystem -level quantum safe transition, focusing on the ethical, legal, societal, and regulatory aspects of a quantum safe transition beyond crypto agility and other limitations other people have mentioned. It’s not only a technical transition. It’s a mental, ethical governance, so on and so forth. Thank you. Just one sentence. To be honest, the greatest technological advancement and transition, the fastest one, happened during pandemics, right? So… So we have another comment online Tirak says we often hear cybersecurity discussions begin with warnings of collapse but with quantum computing this is not another warning it is a countdown to Q -Day and the only real safeguard is proactive migration to post -quantum cryptography NIST has already finalized Kiber, Ethelium and Sphinx Plus and if organizations wait until 2013 the encrypted data being harvested today we could be decrypted tomorrow the time is to act now Hi everyone my name is Bolo Tife and I’m with the non -commercial stakeholder group of ICANN and From my perspective, I think if there are limited resources for such a migration, I would propose a risk -based approach, which means prioritizing critical infrastructures.

And so I have an intervention and I also have a question. I believe ICANN on its own is a critical infrastructure that affects everyone, considering that they manage the root servers for the domain name system. So my question would be also to the speaker from the ESSA. What are the steps that are being taken from ICANN’s perspective to protect the root servers and the entire domain name system as a critical infrastructure? Which… Which I think should be prioritized. Thank you.

Benoît Ampeau: I might not have the correct answer, but I know it’s a topic for ICANN in the sense that they are looking and participating to different fora in addition to ICANN meetings and also proactive in standardization as well. So it’s a technical topic they are following for sure and they are even engaged in it, but I don’t have an exact roadmap from them as far as I’m concerned. S

Wout de Natris: orry again, my horse. I would still like to respond to the ladies over there that give you an example. João worked with a colleague of his from Uruguay, Nicolas, on an IoT report and we were asked by Microsoft to compare. legislation or roadmaps or whatever governments produced on IoT. And they’ve cataloged them and they came up with 442 different approaches, recommendations, whatever you want to call them, of which some were 100 % contradictory. So if industry has to work with 442 recommendations, nothing is going to happen. So with the roadmap that we hope to be able to make is to give a head start in this discussion so that not everybody starts inventing the wheel except that it is important that governments do join at some point this discussion because otherwise they will probably ignore it when it’s published.

And Joao, I think that you may be able to respond to the digital divide that we also recognize in the

João Moreno Falcão: hi yeah so I think we we have a on what we think about this who should bear the responsibility of being of making society quantum secure when we brought this discussion to erotic right the place where we can find all stakeholders in Europe and I think our answer to that comes from this so we know that ICANN have an important role coordinating we know that the governments as we researched have an essential role the service providers too individuals I have an example myself of of this because In the past, when I was like a teenager, I wanted to encrypt data in my hard drive. But almost none of the providers had that functionality embedded in their systems.

So I had to like search the internet, find a specific software to do that. And this is hard, but this also helps to set the standard. And when we talk about coordination, we know how hard it is. We know that everyone wants to do the best for their groups. And this is why we need to discuss this in this kind of forum. Because the contradictory parts need to be tackled on before implementing. This is the solution. And… Yeah, I think that’s it. Thank you very much.

Smee Cujic: We have had one intervention in the room. Y

On-site participant: es, thank you. Just coming back to what the earlier side said about the transition, I’ve also put it in the chat. The transition for non -technicians is a totally opaque thing. Okay. So it’s a totally, totally un -understandable thing. What means transition? Is it costly? Does it mean I just have to open all data and save it like from PDF to JPEG or vice versa? Is it something like I have to just buy new equipment fully? Do I have to change my provider? So as long as… Just the ones who should transition have no clue what transition would mean. They don’t start thinking about it, and there is no budget nowhere. It’s not in the private household, the budget for that.

Nobody is going to save for the new Q -safe iPhone if one doesn’t know about it. On the small businesses, they don’t know anything. You are not having budget for having consultants, so I think it should start there. There, bringing in some very low -floor knowledge about what transition would mean. People are not against, but they have no clue. S

Benoît Ampeau: o, tricky question. So, transition, if I’m talking about infrastructure layer, we are managing its infrastructure. typically what we call the crypto agility and it’s not a new concept it’s like 11 years ago there were i don’t even remember the rfc but it was like let me just check rfc 7696 also known as best quantum practices 201 cryptographic algorithm agility guidelines for cryptographic algorithm agility and select mandatory to implement algorithm so basically and we are also now the same for pqc dns pqc for engineers so from the standardization technical part it’s about being agile in doing the transition from the technical layer then when you are running a business if you are running a business on the internet where are you looking at some funds to switch from http to https you or were you relying on your providers to ask your provider, okay, I would like you to host my website in a secure manner and giving some secure communication between the end users and the providers.

So it’s more or less the same. So I understand food is a question, and there is a lot to raise, but the question is like you would need to look at your business. What are the threats and what are the concerned parts of the business who need to rely on PQC? And now you would start, since you have the inventory, start maybe also put some costs. Maybe it could cost nothing because you have providers that are ready in doing this transition, and the provider will provide you the PQC algorithm you need to protect your business. This is a mix between look at what you need and what to keep your business secure. And after, I think the cost is a shared cost between the business providers and all the stakeholders of this trust chain.

Frederic Taes: Yeah, Frederic Stas speaking. I speak on my own, but in my quality of cybersecurity manager during my day life. And I observe that already today, even with the classical encryption, you have some parts really not protected at all. And there was a good comment in the chat from Tilaka. It means upgrading protocols and software. Yes, that’s true, but that’s not sufficient. You need sometimes to have more powerful hardware with more CPU power, et cetera. And so it means sometimes really huge investments in terms of hardware and not only just upgrading the software. It’s like you have. A very old computer and you need you come with new software. It will just not work. So that’s huge investments behind.

Thank you.

Nicolas Zahn: before we come to the messages i’m uh very very short remark uh Nicolas Zahn from the swiss internet and digital governance uh i guess just building on your last point that’s also why one of the first steps that you see in quantum security or cyber security consulting is to start with the inventory because organizations first need to understand where they are currently using encryption so that they can understand where they potentially need to change something to uh to move towards the post -carnitine world but in terms of the discussions that we’ve seen i have two major messages prepared the the first um deals with the deals with the question of why does this matter and what specifically do we see as the biggest potential issue and there the mentimeter showed that loss of privacy is seen as the most pressing concern regarding digital security and the post -quantum world.

Q -Day is not a far -distant threat, but already a partial reality, as first successful breaks of encryption using quantum computers have shown. And since the post -quantum world affects almost every aspect of digital life we need to prepare today, or rather even yesterday, I’ve also noted down, given the back and forth on the lack of clarity on what it is that is expected by organizations, that organizations, public and private, need more clarity on what is needed and where they currently use encryption.

Frederic Taes: Otherwise you can share. I don’t have the right to share my screen again, but if you give me the rights, I can show the screen. I don’t have the right to share my screen again, but if you give me the rights, I can show the screen.

Nicolas Zahn: Okay, here we go. It’s a bit small. That’s better. Perfect. So, as you can see, the first message deals with the question of why this is a topic of relevance and what the timeline looks like. like and what we see as the biggest issue, the biggest issue being the loss of privacy. The second message then deals with the next logical step saying what should we be doing about this, what can be done and who should be doing it. There I noted down from the discussion that technical standards are only part of the answer. We also need awareness and resources to help organizations with the deployment of these new standards. And we also noted in the discussion that QDA is a structural issue that needs coordinated actions and cannot be addressed on the individual level, something that the Mentimeter showed.

Just to give an example, I’m adding the point on the potential element in a government roadmap could be capacity building for procurement officers to enforce procurement of secure by design systems. And in terms of responsibility, the survey shows that the participants, or split between governments and service providers, I know that others got an equal amount or almost as high amount of… votes but at least for me it was not clear from the discussion what this now refers to so I’m happy to add more specific content there in the message

Wout de Natris: If I can comment I would not use the word enforce because procurement is in the end voluntary something because you can you can either decide to join it or say but I’m not going to offer that so I’m not going to give an offer so the word that I would use is probably stimulate stimulate security by design deployment

Benoît Ampeau: I was just thinking about for instance in France the National Security Agency by next year they will propose a way to qualify for PQC -ready solutions, so it could help. So it’s something that capacity building in promoting or qualifying secure by design solutions, for instance.

Wout de Natris: It’s not promote either, because you don’t promote in a procurement process. So I would say the stimulation of secure by design deployment.

Smee Cujic: I just need to remind everyone that we need to work on a rough consensus, meaning it’s not about details. If there is any very strong disagreement, we still have, I think, a week to polish it out. So I want to give the word.

On-site participant: I just suggest a very minor thing. It is a potential government role. It could be capacity building. So capacity building and education, I would suggest we take it as a third. bullet. So take it out since this is not really fitting there or could be emphasized in putting it on the three. And as a final comment that we have to start now because tomorrow might be too late to make it explicit.

Smee Cujic: So again, unless there’s a really, really strong disagreement, we need to end the session since I’ve been informed that the plenary is waiting for us. Okay. Thank you very much for everyone’s participation. Thank you. Thank you. Thank you.