Podcast
Root Causes 464: Defending Against Harvest and Decrypt


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
February 5, 2025
Harvest and decrypt is a well-known attack vector against traditional cryptography prior to PQC. In this episode, we discuss what enterprises should be doing today to defend themselves against harvest and decrypt.
Podcast Transcript
Lightly edited for flow and brevity.
Where bad guys come in and they grab your blobs, they store them, and they wait until they are then able to decrypt them. And we understand that the ultimate solution for this is to put post-quantum cryptography in place and that will solve it. However, we also understand there's a gap between the identification of the potential for the attack, which is now. It's a very doable attack, so we need to assume that it's happening.
The implementation of PQC really in any kind of scale at all to prevent that attack. So here's the question, and if the answer is a big shrug and a nothing, this will be a very short podcast.
If I am a CISO, and I'm 100% cognizant of this problem, and I don't have PQC systems today, what am I doing NOW to defend myself against this attack. Not prepping, not inventorying my crypto, not all the stuff we always say. What am I doing so that TODAY, this attack doesn't happen or is less likely to happen.
Short episode. I'm just in trouble. So it's just good old-fashioned security. It's got to keep the bad guys out, because once they're in, it's a done deal.

