Podcast

Root Causes 635: Do We Need to Get Rid of ECC?

Hosted by
Tim Callan
Tim Callan
Chief Compliance Officer
Original broadcast date
June 29, 2026

Bas Westerbaan of Cloudflare joins us to discuss recent information that heightens concerns about Elliptic Curve Cryptography (ECC) and its vulnerability to a cryptographically relevant quantum computer (CRQC). We pose the question do we need to deprecate ECC in advance of our migration to ML-DSA and other PQC algorithms.

Podcast Transcript

Tim CallanTim CallanWelcome back to Root Causes, and welcome back to Root Causes, Bas Westerbaan from Cloudflare. Good to have you back.
BWBas WesterbaanGreat to be here.
Tim CallanTim CallanSo we've talked in previous episodes about Cloudflare accelerating its PQC deployment schedule, and one of the big motivators was that there was very credible research that suggests that ECC in particular is perhaps more vulnerable to quantum attack than people had previously thought. And based on that - I think I want to ask the question, and other people are asking the question - do we all need to get rid of ECC?
BWBas WesterbaanShort answer: well, yes. Don't migrate to RSA in between - that doesn't make sense. A similar thing you hear is, okay, just go from RSA-2048 to RSA-4096 or something like that. I think the best way to explain why this doesn't work is with a picture from Sam Jaques. He makes this nice 2D graph - he calls it the quantum landscape. Let me pull it up.
Jason SorokoJason SorokoI just saw that image - I just saw it recently. So maybe we could put a link, I don't know if you can put the link. I have that image, Bas. I promise you I'll put it up at this point in the podcast right now. So I assume it's on the screen. Okay, excellent.
BWBas WesterbaanSo what you see here is a graph - horizontally it's the number of qubits, and vertically it's how good, or how little noise they have, so higher means less noise. And this box on the left, that's where the quantum computers are now. And on the right we have these lines - the long lines are when the different RSAs are broken with Gidney's approach - and then we have these dots, where RSA is broken with new algorithms on special reconfigurable quantum computers, ones that have reconfigurable qubits. And as you can see here, the one that's closest is ECC-256. With very special codes, that's a hell of a lot closer than it was. But the thing is, this is not the right way to look at it, because today we compare quantum computers to a developed technology, like silicon chip manufacturing - that's what we compare it to, and that's a predictable industry with year-over-year progression: Moore's law. Whether Moore's law is actually describing nature, or whether the industry is just following its own law, interesting question, sure, it's an interesting question - but the people who are actually working on quantum computers, they're not thinking about how much they're improving this key metric each time. The thing they are solving is, okay, how am I able to fit - okay, I know how to scale the number of qubits now, but now I have two wires which go to each qubit, and I want to have 200 qubits, but now all these wires don't fit through the aperture of my fridge. So they don't think in terms of how big the aperture of my fridge is to pull through all these wires - what they're thinking about now is, can I make this multiplexer to have one wire control them all? They're thinking in capabilities. And so this picture doesn't show capabilities. So there's a good chance that once all the engineering hurdles are solved, the jumps will not be gradual - there'll be a big jump, in various approaches, especially in the qubit count. So that is one worry - why this graph might be a little bit misleading - and those big jumps might be, there might not be prior evidence to telegraph that a big jump is coming. Those big jumps might essentially be a surprise. That's the problem with breakthroughs. That's the point.
The thing is, also the scary thing is - I think we're changing the topic a little bit, but I think it's an interesting conversation. So, we have on the frontier different approaches to make a quantum computer. Today we have basically just the classical, silicon-based computer - that's the only computer we have. But on the quantum computer side, we have all these different approaches: the transmon ones, the ion ones, the neutral atom ones, and moonshots like Microsoft's Majorana. And most of these - except Microsoft's Majorana - are actually on the frontier, they're actually quite competitive if you look at the performance. But there's of course differences if you look at the number of problems left to solve. Now, the neutral atoms - they weren't on my radar for a long while, because they had a longer list of problems, but that one has skipped ahead. But the problem is, we have each of these approaches on the frontier, and whereas maybe ten years ago you'd think, oh, there's so many problems for each of them, will any of them make it - now it's like, oh God, we have to believe that each of them will hit that insurmountable wall in their last engineering challenges. So that's the thing that makes it - small-chance events get amplified, because there are still these different, quite different approaches. If you look at the graph - so, first the question: RSA-2048 or RSA-4096? If you look, there's a whole lot of nothing on the left, and then all of these RSAs are very close together, each of these lines - and the reason is that quantum computers are noisy, and they require quantum error correction, and this error correction has a baseline overhead. Once you finally get over the baseline overhead, then it grows quickly, and that's why they're tucked together. In a sense, it's kind of the same thing Scott Aaronson says: if someone is building a nuclear bomb, you don't expect the first nuclear explosion to be a small nuclear explosion - the first thing you expect is a big boom. So that's the thing. So moving to RSA-4096, I don't know how much that buys you <- a few months. The effort in moving is not worth it. And also, ECC is now the one that's in the most trouble. For the longest time we thought - so originally we thought ECC, just from looking at Shor's algorithm and the way it works, it depends on the size of the group - then we thought ECC is more vulnerable. And then if you think a little bit more, it's like, oh, but the operations are a bit more complex - and then, so we thought maybe RSA. Then we optimized. So it has been going back and forth between which one is most vulnerable over time. I mean, maybe RSA will become more vulnerable in the future - do we want to bet on this? I don't. Then I just go PQC now.
Tim CallanTim CallanSo your point is: any effort we would spend migrating systems from ECC to RSA would be effort better spent prepping for PQC.
BWBas WesterbaanI would say so.
Jason SorokoJason SorokoBas, that's a fantastic place to land, because I think a lot of people have been thinking about raising key sizes. A lot of people have been thinking, is it RSA or ECC that's most vulnerable? And I think for the longest time, people always put RSA at the top of the list - even though that's just an old wives' tale rule of thumb that doesn't make any sense anymore. We have to think all factorization-based cryptography is vulnerable to quantum computers. And once we have a cryptographically relevant quantum computer, it all just falls.
Tim CallanTim CallanAlright. Well, there you go - that's a gloomy end. Thank you so much, Bas. This is a topic that we could probably discuss forever. I think this is a good place to leave it today. I'm certain we'll be having you back, especially as things develop, and we appreciate you.
BWBas WesterbaanI was happy to be here.
Jason SorokoJason SorokoThanks so much, Bas. Take care.

Stay informed with expert insights

Subscribe to Root Causes for engaging discussions on PKI, digital security, and best practices for protecting your organization's critical assets. Don’t miss an episode!

Listen on Apple PodcastsListen on SpotifyListen on SoundCloud