Posts

Showing posts with the label Post-Quantum Cryptography

Post-Quantum Cryptography and Crypto-Agility for CompTIA SecurityX (CAS-005)

Every TLS handshake, VPN tunnel, and signed firmware update running today relies on math problems that classical computers can't solve in a reasonable amount of time — mainly integer factorization and discrete logarithms. A sufficiently powerful quantum computer would solve both quickly, which is why CompTIA added post-quantum cryptography and crypto-agility to the SecurityX (CAS-005) exam's Security Engineering domain. This guide breaks down what you actually need to know, in the depth CAS-005 expects. Why Post-Quantum Cryptography Matters Now No cryptographically relevant quantum computer exists yet, so it's tempting to treat this as a future problem. SecurityX candidates need to think like architects, not just administrators: data encrypted today with RSA or elliptic curve cryptography (ECC) can be captured now and decrypted later, once quantum hardware catches up. For data with a long confidentiality shelf life — medical records, government secrets, trade secrets, l...