Research

Watch · narrated whiteboard episodesL3

Threat Modeling a Post-Quantum Migration

A post-quantum migration is usually treated as an algorithm swap. It is really a threat-modeling problem: assets whose secrecy must outlive the quantum transition, an adversary with future capability, and a migration that introduces its own attack surface. This series applies threat-modeling discipline to the crypto transition itself. Grounded in NIST IR 8547, SP 1800-38, Mosca, and Shostack.

Murali Chillakuru·5 episodes
  1. 23 min Episode 1Framing the Post-Quantum Threat Model: Assets, Adversaries, and BoundariesA moderator and a security-architecture expert establish how to threat-model a post-quantum migration — the three pillars of assets, adversaries, and boundaries, why assets are classified by shelf-life, the unusual adversary who has capabilities only in the future, the trust boundaries a migration crosses, and how to apply the discipline.
  2. 23 min Episode 2Harvest-Now-Decrypt-Later as the Anchor Threat: Building a Data-at-Risk InventoryA moderator and a security expert dissect the threat that makes post-quantum urgent today — why harvest-now-decrypt-later anchors the whole model, the cheap economics that make harvesting rational, how to build a data-at-risk inventory, the at-risk test for prioritization, three levers to shrink the risk, and keeping the inventory alive.
  3. 23 min Episode 3Downgrade, Rollback, and Negotiation Attacks: The Adversary That Strips the PQCA moderator and a protocol-security expert examine how an attacker defeats post-quantum protection without breaking any math — in-band downgrade and the negotiation binding that stops it, the fallback trap, rollback to old versions, why a forced downgrade re-arms harvest-now-decrypt-later, how to defend the negotiation, and the agent-mesh angle.
  4. 24 min Episode 4The Migration's Own Attack Surface: Combiners, Dual Stacks, and Key-Management GapsA moderator and a security-architecture expert map the vulnerabilities the migration itself introduces — the new surfaces of the transitional state, combiner failures that silently void hybrid, dual-stack complexity, post-quantum bloat weaponized as a denial-of-service vector, key-management gaps during transition, the controls that close them, and the agent-platform angle.
  5. 24 min Episode 5A Post-Quantum Threat-Modeling Playbook: Inventory, Attack Trees, Controls, and a CI GateIn the threat-modeling finale, a moderator and a security expert assemble everything into a repeatable playbook — a six-step method, building attack trees, mapping threats to controls, gating those controls in the pipeline, running it all as a living loop, and applying it across an AI-agent platform.