Podcast

Root Causes 630: The PQC Physicality Crisis

Hosted by
Tim Callan
Tim Callan
Chief Compliance Officer
Original broadcast date
June 17, 2026

Resource-constrained devices may need to address PQC through real-time, seed-based, key generation. Unfortunately, this leaves the full key exposed very briefly in RAM. The potential consequences of this are far-reaching and scary. We go into the details.

Podcast Transcript

Tim CallanTim CallanSo, we like our series of episodes, Jason. We, unknowingly - without knowing it - started a series some months ago when we defined a side oracle attack. Then more recently, in 2026, we talked about the side channel apocalypse. Again, with regards to PQC in specific. Now I think there's a third installment in this series, correct?
Jason SorokoJason SorokoTim, I think the third installment, it's basically a takeoff from the side channel apocalypse episode. I think we should call this the PQC physicality crisis.
Tim CallanTim CallanThe PQC physicality crisis.
Jason SorokoJason SorokoI noticed the word physicality in there. We're talking about atoms now. We are actually talking about the hardware on which things are running. And very specifically, the constrained devices that PQC could be running on in the future. So what this podcast is about, Tim, is that the IETF very recently started issuing constrained-device warnings.
Resource-constrained devices, IoT devices, lightweight HSMs, thumb drives, and things like this. So here's the evidence. By the way, there's a working group in IETF who's done deeper thinking than this podcast will discuss - we're just bringing you some news. So this working group that I'm looking at right now - there are experts on that panel, on that working group, that admit that there's certain kinds of constrained devices that have very strict limitations on RAM and Flash...
Tim CallanTim CallanYou bet there are.
Jason SorokoJason Soroko...that are exhausted by the increased sizes of PQC.
Tim CallanTim CallanSure. No surprises there.
Jason SorokoJason SorokoNo surprises there. So the workaround - this working group is explicitly suggesting a seed-based key generation as a mitigation. So they're actually talking about, instead of storing the massive PQC private key in the secure element, the device only stores a seed that can generate -
Tim CallanTim Callan- the equivalent. The device has the logic to generate it, built in?
Jason SorokoJason SorokoWell, with the seed - because the seed is so much simpler to deal with. It's an abstraction of the thing. It's a workaround. The problem is this. Here's the risk: every time the device needs to sign something, it has to derive the full key from that seed. If that derivation -
Tim CallanTim CallanSo it's doing this a lot.
Jason SorokoJason SorokoIt's happening a lot. But here's the point: it's happening in RAM. The physicality crisis.
Tim CallanTim CallanIt's happening in physical RAM. So suddenly, I can spy. I look at the ways I normally look at it: I look at temperature, I look at power usage, and I can use that to try to gain -
Jason SorokoJason Soroko- the information. The full private key is exposed in software for a millisecond.
Tim CallanTim CallanSo if I can just find a way to get a snapshot of that software, I just have it. So it's not even a side-channel attack I'm talking about. Not even a side-channel attack - it's just a spy-on-the-RAM attack. So, unfortunately -
Jason SorokoJason Soroko- the workaround leaks the full key. I use the word "crisis" in the title of this podcast on purpose, because you can see what could happen if the bad guy gets good at looking at that millisecond.
Tim CallanTim CallanAbsolutely. You just got the key, pure and simple. Again, depending on the nature of the device, it may be - if you can get your hands on one of these devices, you can study it to your heart's content. Once you figure out how to do it to the one you have in your lab, you can do it to the ones in production.
Jason SorokoJason SorokoI'm gonna land on this for this podcast, Tim, and then sleep well after I say this.
Tim CallanTim CallanI'm done sleeping.
Jason SorokoJason SorokoToday's trusted platform modules - TPMs - the ones that are inside your laptop right now, the ones that are inside your car, even. TPM 2.0 - you can go look at the standard right now. Get on the internet, search it: TPM 2.0 standard. It was designed for RSA-2048 and ECC, and does a very good job. All right. The problem is, ML-DSA can be over 3,000 bytes. It wasn't designed for that. So here's the outcome: a lot of the TPMs that are being delivered right now in the world are dead on arrival, with respect to - they will expose PQC. The seed will derive a PQC private key in RAM for a millisecond.
Tim CallanTim CallanSo, presumably, this includes every laptop?
Jason SorokoJason SorokoTell me a laptop that doesn't have TPM 2.0. If I'm wrong, this is conflagulatory type of talk. What I'm saying here is kind of humongous. If I'm wrong -
Tim CallanTim CallanIt's been a lot of humongous lately, but come on.
Jason SorokoJason SorokoIf I'm wrong - and I fully admit - this is just me looking at it, and me reading the tea leaves out of this IETF working group. Okay, this is not making it to CNBC here. CBC News Canada, BBC - this is not making it to that. This is old Jay looking at obscure experts in an obscure other place. What I'm reading is: the workaround is to derive the private key in RAM. We have a physicality crisis, Tim. Have a nice night.

Stay informed with expert insights

Subscribe to Root Causes for engaging discussions on PKI, digital security, and best practices for protecting your organization's critical assets. Don’t miss an episode!

Listen on Apple PodcastsListen on SpotifyListen on SoundCloud