<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Guillaume Dumas on Senthorus Blog</title><link>https://blog.senthorus.ch/author/guillaume-dumas/</link><description>Recent content in Guillaume Dumas on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/guillaume-dumas/index.xml" rel="self" type="application/rss+xml"/><item><title>Inside the RSA-260 Factorization: GPU-Accelerated GNFS and the Role of Devin</title><link>https://blog.senthorus.ch/posts/rsa_260_factorization_cognition_explanation/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/rsa_260_factorization_cognition_explanation/</guid><description>&lt;img src="https://blog.senthorus.ch/rsa_260_factorization/rsa_260_factorization_main_visual.png" alt="Featured image of post Inside the RSA-260 Factorization: GPU-Accelerated GNFS and the Role of Devin" />&lt;p>When Eric Lu announced the factorization of &lt;strong>RSA-260&lt;/strong> on September 3, 2026, he published a valid factor but almost nothing about how it had been found. My &lt;a class="link" href="https://blog.senthorus.ch/posts/rsa_260_factorization" target="_blank" rel="noopener"
>previous RSA-260 article&lt;/a> therefore separated two questions: could the result be verified, and what method had produced it? Only the first had a firm answer.&lt;/p>
&lt;h2 id="the-missing-method-is-no-longer-missing">The Missing Method Is No Longer Missing
&lt;/h2>&lt;p>On September 9, Lu published a detailed account through Cognition. The second question now has an answer, at least according to the team that performed the computation: RSA-260 was factored with the &lt;strong>General Number Field Sieve&lt;/strong> (GNFS), using a heavily modified, GPU-accelerated version of &lt;strong>CADO-NFS&lt;/strong> developed and operated with multiple Devin agents.&lt;/p>
&lt;p>There was no quantum computer and, by Lu&amp;rsquo;s own account, no new factoring algorithm:&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>&amp;ldquo;I report essentially no algorithmic advancements&amp;rdquo;&lt;/strong>&lt;br>
&lt;em>Eric Lu, &lt;a class="link" href="https://cognition.com/blog/factoring-rsa-260" target="_blank" rel="noopener"
>Cognition&lt;/a>&lt;/em>&lt;/p>&lt;/blockquote>
&lt;p>That distinction matters. A better algorithm could change how factoring difficulty grows with key size. A better implementation reduces the practical cost of the same mathematics. Cognition reports the second kind of advance: established GNFS techniques were adapted to modern GPU memory systems and otherwise fragmented computing capacity.&lt;/p>
&lt;p>This follow-up focuses on the information that was missing from the first announcement: the software, the resources, the role of Devin, and the limits of the larger security claims.&lt;/p>
&lt;h2 id="what-cognition-actually-built">What Cognition Actually Built
&lt;/h2>&lt;p>GNFS is not one monolithic calculation. It is a pipeline combining polynomial selection, relation sieving, filtering, sparse linear algebra, and square-root extraction. Cognition did not replace that sequence. It changed where much of the work ran and optimized almost every stage around it.&lt;/p>
&lt;p>The starting point was &lt;strong>CADO-NFS&lt;/strong>, a mature open-source implementation. Its modular design gave the Devin agents established interfaces, reference outputs, and CPU programs against which GPU replacements could be tested.&lt;/p>
&lt;p>According to Lu, the modified pipeline included:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>gps1&lt;/strong>, a GPU adaptation of CADO-NFS&amp;rsquo;s first polynomial-selection stage, incorporating kernel techniques from &lt;strong>msieve&lt;/strong>&lt;/li>
&lt;li>&lt;strong>glas&lt;/strong>, a GPU lattice siever replacing the CPU-based &lt;strong>las&lt;/strong>&lt;/li>
&lt;li>optimized coordination, deduplication, filtering, merging, and replay programs&lt;/li>
&lt;li>a GPU-oriented &lt;strong>block Wiedemann&lt;/strong> implementation for sparse linear algebra&lt;/li>
&lt;li>a GPU-accelerated square-root stage and new run scripts&lt;/li>
&lt;/ul>
&lt;p>The central component was the lattice siever. It searches for billions of useful mathematical relations that can later be combined. The work divides naturally into independent units, but each unit performs many reads and writes at irregular memory locations.&lt;/p>
&lt;p>That pattern is difficult for GPUs, which work best when many threads follow similar instructions and access predictably arranged data. The challenge was not to compile CPU code for CUDA. It was to reorganize the workload until the GPU&amp;rsquo;s much greater memory bandwidth outweighed the cost of branching and scattered access.&lt;/p>
&lt;p>The mathematics remained GNFS. The operational system around it changed substantially.&lt;/p>
&lt;h2 id="why-spare-ai-compute-was-a-good-fit">Why Spare AI Compute Was a Good Fit
&lt;/h2>&lt;p>Cognition says the project began while its research team was improving the allocation of disaggregated compute. Large AI workloads prefer tightly connected groups of machines inside NVLink-equipped racks. Real scheduling leaves gaps: one node may remain idle, a job may require an even number of machines, or capacity may be reserved for failover.&lt;/p>
&lt;p>Those gaps represented a single-digit percentage of Cognition&amp;rsquo;s cluster. They were awkward for training jobs, but well suited to relation sieving.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/rsa_260_factorization/rsa_260_fragmented_gpu_compute.png"
loading="lazy"
alt="Fragmented GPU capacity reused for independent GNFS sieving workloads"
>&lt;/p>
&lt;p>Sieving is described as &lt;strong>embarrassingly parallel&lt;/strong> because billions of small work units can run on separate machines with little coordination. A low-priority unit can be interrupted and rescheduled without invalidating the rest of the computation. The siever could therefore fill small scheduling holes left by larger AI workloads.&lt;/p>
&lt;p>Lu says the factorization ran at &lt;strong>&amp;ldquo;no marginal cost&amp;rdquo;&lt;/strong> (&lt;a class="link" href="https://cognition.com/blog/factoring-rsa-260" target="_blank" rel="noopener"
>Cognition&lt;/a>). This does not mean that the hardware, energy, or computation was free. It means the run reportedly used capacity that Cognition already owned and could not assign productively to higher-priority jobs at those moments.&lt;/p>
&lt;h2 id="the-rsa-260-run-by-the-numbers">The RSA-260 Run by the Numbers
&lt;/h2>&lt;p>Lu says the first prompt asking Devin to build a GPU lattice siever was issued on August 13. Polynomial selection began on August 18, and the factors were produced on September 3. The recorded run took about &lt;strong>15.6 days&lt;/strong>, while the broader engineering effort lasted roughly three weeks.&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Stage&lt;/th>
&lt;th style="text-align: right">Reported compute&lt;/th>
&lt;th style="text-align: right">Share&lt;/th>
&lt;th>Main output&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Polynomial selection&lt;/td>
&lt;td style="text-align: right">643 GPU-days&lt;/td>
&lt;td style="text-align: right">13.1%&lt;/td>
&lt;td>Candidate polynomials&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Lattice sieving&lt;/td>
&lt;td style="text-align: right">3,813 GPU-days&lt;/td>
&lt;td style="text-align: right">77.5%&lt;/td>
&lt;td>13.85 billion raw relations&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Linear algebra&lt;/td>
&lt;td style="text-align: right">467 GPU-days&lt;/td>
&lt;td style="text-align: right">9.5%&lt;/td>
&lt;td>Dependencies in a 656-million-row sparse matrix&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;strong>Total&lt;/strong>&lt;/td>
&lt;td style="text-align: right">&lt;strong>4,923 GPU-days&lt;/strong>&lt;/td>
&lt;td style="text-align: right">&lt;strong>100%&lt;/strong>&lt;/td>
&lt;td>About 13.5 GPU-years of aggregate work&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>The reported stage totals reproduce Cognition&amp;rsquo;s rounded market estimate:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>gpu_days &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#ae81ff">643&lt;/span> &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">3_813&lt;/span> &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">467&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>market_price_per_gpu_hour &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#ae81ff">3.50&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>market_equivalent &lt;span style="color:#f92672">=&lt;/span> gpu_days &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">24&lt;/span> &lt;span style="color:#f92672">*&lt;/span> market_price_per_gpu_hour
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(gpu_days) &lt;span style="color:#75715e"># 4923&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(round(gpu_days &lt;span style="color:#f92672">/&lt;/span> &lt;span style="color:#ae81ff">365&lt;/span>, &lt;span style="color:#ae81ff">1&lt;/span>)) &lt;span style="color:#75715e"># 13.5 GPU-years&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(&lt;span style="color:#e6db74">f&lt;/span>&lt;span style="color:#e6db74">&amp;#34;$&lt;/span>&lt;span style="color:#e6db74">{&lt;/span>market_equivalent&lt;span style="color:#e6db74">:&lt;/span>&lt;span style="color:#e6db74">,.0f&lt;/span>&lt;span style="color:#e6db74">}&lt;/span>&lt;span style="color:#e6db74">&amp;#34;&lt;/span>) &lt;span style="color:#75715e"># $413,532&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Cognition summarizes this as about &lt;strong>4,900 GPU-days&lt;/strong> and &lt;strong>$400,000 at market prices&lt;/strong>. The latter is a market-equivalent compute estimate, not a bill or a complete project budget. It excludes the distinction between owned spare capacity and rented GPUs, and says nothing about hardware acquisition, power, cooling, human work, or Devin&amp;rsquo;s development cost.&lt;/p>
&lt;p>GPU-days are aggregate work, not elapsed time. Parallel execution compressed the run into just over two weeks, with available capacity varying across B200, GB200, and GB300 systems.&lt;/p>
&lt;h2 id="what-happened-inside-the-pipeline">What Happened Inside the Pipeline
&lt;/h2>&lt;p>The detailed timings reveal where the computation succeeded and where it remained inefficient.&lt;/p>
&lt;p>Polynomial selection consumed far more work than planned. Lu attributes the 643 GPU-days to misread early benchmarks and unproductive search ranges. The total is therefore not presented as a theoretical minimum.&lt;/p>
&lt;p>Sieving remained the dominant expense. It ran for about &lt;strong>7.9 days&lt;/strong>, generating 13.85 billion raw relations. After removing roughly 40% duplicates, 8.30 billion unique relations remained. The team upgraded the live siever twice, reporting gains of approximately 14% to 17% on the measured GPU types.&lt;/p>
&lt;p>Filtering transformed those relations into a sparse binary matrix of about &lt;strong>656 million rows by 656 million columns&lt;/strong>, with 98.4 billion non-zero entries. The values represent whether relevant prime exponents are even or odd, so the linear algebra operates over &lt;strong>GF(2)&lt;/strong>, using only zero and one.&lt;/p>
&lt;p>The block Wiedemann stage then searched the matrix for dependencies. Unlike sieving, its workers had to stay available together and communicate. Higher-priority jobs repeatedly pre-empted allocations, making checkpointing and job placement essential.&lt;/p>
&lt;p>Even square-root extraction failed at first. A roughly 176-billion-bit intermediate product overflowed an internal &lt;strong>mpz_t&lt;/strong> limb counter. Lu says Devin rebuilt the component three times, the final GPU-accelerated version completed its main calculation in 88 minutes.&lt;/p>
&lt;p>This is what a record computation looks like in practice: measurements, failures, restarts, validation checks, parameter changes, and resource decisions, not one elegant command.&lt;/p>
&lt;h2 id="what-devin-did-and-what-still-required-a-human">What Devin Did, and What Still Required a Human
&lt;/h2>&lt;p>Cognition presents the result as evidence that an AI software-engineering agent can contribute to specialized computational research. Its report supports a substantial role for Devin, but not the simpler story of an autonomous AI independently deciding to factor RSA-260 and completing the project alone.&lt;/p>
&lt;p>Lu first asked Devin to create a drop-in GPU replacement for &lt;strong>las&lt;/strong>. According to his account, an initial version surpassed the CPU reference after about nine hours. Over the following weeks, parallel Devin sessions optimized components, benchmarked changes, debugged failures, tuned parameters, prepared scripts, and managed cluster jobs. An average of three sessions ran concurrently, with a maximum of eighteen.&lt;/p>
&lt;p>What did Devin still need a human for? Lu&amp;rsquo;s concise answer is &lt;strong>&amp;ldquo;still a lot&amp;rdquo;&lt;/strong> (&lt;a class="link" href="https://cognition.com/blog/factoring-rsa-260" target="_blank" rel="noopener"
>Cognition&lt;/a>). He reports sending 3,328 messages across 192 of the 233 sessions used for the project. His role included defining priorities, establishing comparable benchmarks, detecting unproductive directions, organizing results, and deciding when evidence was trustworthy enough to proceed.&lt;/p>
&lt;p>Verification remained central. While RSA-260&amp;rsquo;s linear algebra was running, the team completed an end-to-end factorization of a smaller 344-digit special-form number. It also checked stored linear-algebra states with CADO-NFS&amp;rsquo;s existing tools. One check failed after about fourteen hours, forcing the affected interval to be rerun.&lt;/p>
&lt;p>The practical lesson is balanced. Agents can accelerate implementation and experimentation, but faster iteration increases the need for reference code, measurable objectives, independent checks, and informed human supervision. CADO-NFS supplied the stable, human-designed decomposition that made parallel agent work possible.&lt;/p>
&lt;h2 id="a-tenfold-cost-claim-not-a-mathematical-breakthrough">A Tenfold Cost Claim, Not a Mathematical Breakthrough
&lt;/h2>&lt;p>Cognition calls &lt;strong>glas&lt;/strong> the highest-performance GPU lattice siever and estimates that its pipeline cuts factoring costs by about ten compared with the previous public state of the art.&lt;/p>
&lt;p>This is a &lt;strong>performance and cost claim&lt;/strong>, not a change to GNFS&amp;rsquo;s theoretical complexity. The gain comes from GPUs, software optimization, scheduling, and pricing assumptions. Factoring cost still rises extremely quickly as the modulus grows.&lt;/p>
&lt;p>There is also no earlier public RSA-260 run for a direct comparison. Cognition scales the CPU cost of the RSA-250 record to estimate what RSA-260 would have required with the earlier approach, then compares that projection with its GPU accounting.&lt;/p>
&lt;p>The publication includes detailed parameters, timings, relation counts, and matrix dimensions. At publication time, however, it does not link to the modified pipeline&amp;rsquo;s source code. The factors are independently verifiable, and the performance advantage is a detailed claim by the team, not yet an independently reproduced result.&lt;/p>
&lt;h2 id="what-the-rsa-1024-estimate-really-means">What the RSA-1024 Estimate Really Means
&lt;/h2>&lt;p>The most security-relevant extrapolation concerns &lt;strong>RSA-1024&lt;/strong>. Using standard GNFS scaling, Lu estimates that a 1,024-bit modulus would require about 78 times the RSA-260 computation. At the same assumed price of $3.50 per GPU-hour, the appendix gives &lt;strong>$32.3 million&lt;/strong>, rounded to $30 million in the main article.&lt;/p>
&lt;p>That is not an observed attack cost. It assumes that GNFS follows the heuristic scaling model, that this implementation remains usable at the larger scale, and that the same market price is meaningful. It also applies to one chosen modulus, not a reusable universal break.&lt;/p>
&lt;p>The estimate suggests that a GPU-rich organization might contemplate attacking one legacy RSA-1024 key. It does not mean Cognition has factored RSA-1024 or that an organization without the software, expertise, and cluster access could reproduce the estimate.&lt;/p>
&lt;p>Nor does it change current guidance. NIST already disallows RSA moduli below 2,048 bits for generating digital signatures and for RSA-based key establishment. Cognition refines the economics of an obsolete size. It does not redefine modern RSA hygiene.&lt;/p>
&lt;h2 id="why-rsa-2048-remains-out-of-reach">Why RSA-2048 Remains Out of Reach
&lt;/h2>&lt;p>Cognition&amp;rsquo;s extrapolation places RSA-2048 about &lt;strong>a billion times beyond RSA-1024&lt;/strong> under the same GNFS model. A projection over such a distance is not a precise budget, but the order of magnitude is the point: a tenfold engineering improvement does not bridge a billionfold gap.&lt;/p>
&lt;p>The conclusion of the &lt;a class="link" href="https://blog.senthorus.ch/posts/rsa_260_factorization" target="_blank" rel="noopener"
>previous RSA-260 article&lt;/a> therefore remains intact. This record matters for computational number theory, legacy-key economics, and AI-assisted performance engineering. It is not evidence of a practical classical attack against correctly generated RSA-2048 keys.&lt;/p>
&lt;p>That assessment would change if someone found a fundamentally better factoring algorithm. Cognition explicitly reports no such discovery.&lt;/p>
&lt;h2 id="facts-measurements-and-projections">Facts, Measurements, and Projections
&lt;/h2>&lt;p>The disclosure is easiest to interpret when its different kinds of evidence remain separate:&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Statement&lt;/th>
&lt;th>Status&lt;/th>
&lt;th>Basis&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>The factors multiply to RSA-260&lt;/td>
&lt;td>Independently verifiable&lt;/td>
&lt;td>Direct arithmetic, shown in the &lt;a class="link" href="https://blog.senthorus.ch/posts/rsa_260_factorization" target="_blank" rel="noopener"
>previous article&lt;/a>&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>GPU-accelerated GNFS based on CADO-NFS was used&lt;/td>
&lt;td>Reported methodology&lt;/td>
&lt;td>Lu&amp;rsquo;s technical account and parameters&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>The run consumed about 4,900 GPU-days&lt;/td>
&lt;td>Reported measurement&lt;/td>
&lt;td>Cognition&amp;rsquo;s stage accounting&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>The compute is worth about $400,000&lt;/td>
&lt;td>Cost estimate&lt;/td>
&lt;td>GPU-days multiplied by an assumed market price&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>The pipeline is about ten times cheaper&lt;/td>
&lt;td>Comparative claim&lt;/td>
&lt;td>GPU result compared with a scaled CPU baseline&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>RSA-1024 could cost about $30 million&lt;/td>
&lt;td>Projection&lt;/td>
&lt;td>Heuristic GNFS scaling from this run&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>RSA-2048 is not meaningfully threatened&lt;/td>
&lt;td>Security conclusion&lt;/td>
&lt;td>Remaining scaling gap and no new algorithm&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>A verified factorization does not automatically verify every performance estimate or extrapolation published alongside it.&lt;/p>
&lt;h2 id="conclusion-engineering-leverage-not-cryptographic-collapse">Conclusion: Engineering Leverage, Not Cryptographic Collapse
&lt;/h2>&lt;p>The &lt;a class="link" href="https://blog.senthorus.ch/posts/rsa_260_factorization" target="_blank" rel="noopener"
>previous RSA-260 article&lt;/a> ended with an open question about the method. Cognition now fills that gap: classical GNFS, a substantially modified CADO-NFS pipeline, modern GPUs, opportunistic scheduling, and multiple Devin agents directed by Eric Lu.&lt;/p>
&lt;p>The result is significant because it shows how much leverage can still be extracted from established mathematics through better hardware use, performance engineering, open-source foundations, and AI-assisted iteration. It also shows the limits of the autonomous-agent narrative: Devin reportedly wrote and optimized substantial parts of the system, while human prioritization, benchmark design, judgment, and verification remained essential.&lt;/p>
&lt;p>For security teams, the practical response is modest but important: identify and retire any remaining RSA keys below 2,048 bits, confirm that key-generation and crypto-agility plans are sound, and avoid treating this record as evidence that RSA-2048 has suddenly become breakable.&lt;/p>
&lt;p>The measured boundary moved, especially for legacy key sizes and GPU-rich adversaries. Modern RSA did not collapse with it. The factorization is verified, the resource figures are team-reported measurements, and the costs for larger keys remain projections.&lt;/p>
&lt;h2 id="sources-and-further-reading">Sources and Further Reading
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://cognition.com/blog/factoring-rsa-260" target="_blank" rel="noopener"
>Eric Lu / Cognition: Factoring RSA-260 (September 9, 2026)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://cado-nfs.gitlabpages.inria.fr/" target="_blank" rel="noopener"
>CADO-NFS Development Team: Number Field Sieve implementation and workflow&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://arxiv.org/abs/2006.06197" target="_blank" rel="noopener"
>Fabrice Boudot et al.: Comparing the Difficulty of Factorization and Discrete Logarithm&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://csrc.nist.gov/pubs/sp/800/131/a/r2/final" target="_blank" rel="noopener"
>NIST SP 800-131A Rev. 2: Transitioning Cryptographic Algorithms and Key Lengths&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://sourceforge.net/projects/msieve/" target="_blank" rel="noopener"
>Jason Papadopoulos and contributors: msieve&lt;/a>&lt;/li>
&lt;/ol></description></item><item><title>RSA-260 Has Been Factored: What It Really Means for Modern Cryptography</title><link>https://blog.senthorus.ch/posts/rsa_260_factorization/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/rsa_260_factorization/</guid><description>&lt;img src="https://blog.senthorus.ch/rsa_260_factorization/rsa_260_factorization_main_visual.png" alt="Featured image of post RSA-260 Has Been Factored: What It Really Means for Modern Cryptography" />&lt;h2 id="rsa-260-has-fallen-what-actually-happened">RSA-260 Has Fallen: What Actually Happened
&lt;/h2>&lt;p>On September 3, 2026, engineer Eric Lu (&lt;a class="link" href="https://x.com/penlume" target="_blank" rel="noopener"
>@penlume&lt;/a>) published a 130-digit number on X, followed by only two words: &lt;strong>&amp;ldquo;divides RSA-260&amp;rdquo;&lt;/strong>&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/rsa_260_factorization/rsa_260_factorization_twitter_screen.png"
loading="lazy"
alt="Original Tweet from Eric LU"
>&lt;/p>
&lt;p>The number is one of the two prime factors of &lt;strong>RSA-260&lt;/strong>, a 260-decimal-digit integer that had remained unfactored since the RSA Factoring Challenge began in 1991. Dividing by the published factor reveals the other prime, multiplying them reconstructs the challenge number exactly.&lt;/p>
&lt;p>The result moves the public record for factoring a general RSA-style number from 829 to &lt;strong>862 bits&lt;/strong> and closes a 35-year-old challenge.&lt;/p>
&lt;p>It is also easy to misunderstand. RSA-260 is not a production key, and the result does not mean current 2048-bit keys can suddenly be broken. Its broader significance depends on &lt;strong>how the factorization was obtained&lt;/strong>, a detail not yet disclosed by Eric Lu.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>Update: Cognition Explains the Factorization&lt;/strong>&lt;/p>
&lt;p>On September 9, 2026, Eric Lu published a detailed account on Cognition&amp;rsquo;s blog, explaining how RSA-260 was factored. According to the report, the computation used the &lt;strong>General Number Field Sieve (GNFS)&lt;/strong> through a heavily modified, GPU-optimized version of &lt;strong>CADO-NFS&lt;/strong>. Lu reports essentially no algorithmic advances: the gains came from performance engineering, without a quantum computer or a new mathematical shortcut.&lt;/p>
&lt;p>This disclosure supersedes the earlier uncertainty about the method described below. Lu&amp;rsquo;s approximately &lt;strong>$30 million estimate for RSA-1024 remains an extrapolation&lt;/strong>, while the report provides no practical attack on RSA-2048.&lt;/p>
&lt;p>&lt;a class="link" href="https://cognition.com/blog/factoring-rsa-260" target="_blank" rel="noopener"
>Read Cognition&amp;rsquo;s full article: &amp;ldquo;Factoring RSA-260&amp;rdquo;&lt;/a>&lt;/p>&lt;/blockquote>
&lt;h2 id="what-is-rsa-260">What Is RSA-260?
&lt;/h2>&lt;p>RSA-260 belongs to a collection published by RSA Laboratories to measure progress in integer factorization. Each number was created by multiplying two secret primes:&lt;/p>
&lt;p>&lt;code>N = p × q&lt;/code>&lt;/p>
&lt;p>The public received &lt;strong>N&lt;/strong>, while &lt;strong>p&lt;/strong> and &lt;strong>q&lt;/strong> were withheld. Recovering them provided a practical benchmark for algorithms, software, hardware, and distributed computing.&lt;/p>
&lt;p>The name is confusing: in the original series, &amp;ldquo;260&amp;rdquo; refers to &lt;strong>decimal digits&lt;/strong>, not bits. RSA-260 is 862 bits long, while each newly published factor has 130 decimal digits, or 431 bits.&lt;/p>
&lt;p>RSA-260 is a &lt;strong>challenge modulus&lt;/strong>, not a complete production key. A real public key also includes an exponent &lt;strong>e&lt;/strong>. Knowing &lt;strong>p&lt;/strong> and &lt;strong>q&lt;/strong> allows the corresponding private exponent to be calculated. This challenge protected no production data, so its factorization breaks one mathematical target, not a deployed service.&lt;/p>
&lt;h2 id="why-does-factoring-one-number-matter">Why Does Factoring One Number Matter?
&lt;/h2>&lt;p>RSA relies on a useful asymmetry: multiplying two large primes is easy, but reversing the multiplication is extremely difficult when the primes and modulus are large enough. Think of two ingredients fused into a solid block. Anyone can inspect the block, but separating it into the exact originals requires enormous work. Factoring reveals the trapdoor behind private-key operations.&lt;/p>
&lt;p>Factorization records show what is &lt;strong>practically achievable&lt;/strong>, helping researchers calibrate security estimates and identify key sizes within reach of well-funded classical projects.&lt;/p>
&lt;p>The previous record, &lt;strong>RSA-250&lt;/strong>, was completed in 2020. The 829-bit number was factored with the &lt;strong>Number Field Sieve&lt;/strong> and &lt;strong>CADO-NFS&lt;/strong> at a reported cost of approximately &lt;strong>2,700 CPU core-years&lt;/strong>. About 2,450 core-years went into the sieving phase.&lt;/p>
&lt;p>A core-year measures total work, not elapsed time: thousands of comparable cores can compress millennia of aggregate computation into months. Actual performance also depends on memory, networking, hardware, and software optimization.&lt;/p>
&lt;p>RSA-260 adds 33 bits, but difficulty does not grow linearly with length. It remains close enough to RSA-250 that improved classical software and hardware could plausibly explain the result without a mathematical breakthrough.&lt;/p>
&lt;h2 id="how-large-rsa-numbers-are-factored-in-practice">How Large RSA Numbers Are Factored in Practice
&lt;/h2>&lt;p>Factoring algorithms suit different targets. Trial division handles small numbers, Pollard&amp;rsquo;s rho and the Elliptic Curve Method help when one factor is relatively small. RSA challenge numbers avoid that weakness by using two large, balanced primes.&lt;/p>
&lt;p>For a general number of this size, the strongest known classical approach is the &lt;strong>General Number Field Sieve&lt;/strong> (GNFS). RSA-260&amp;rsquo;s method remains unpublished, so GNFS is an expected baseline, not a confirmed explanation.&lt;/p>
&lt;p>At an operational level, a GNFS computation is a pipeline:&lt;/p>
&lt;ol>
&lt;li>
&lt;p>&lt;strong>Polynomial selection&lt;/strong>&lt;br>
Find representations that make the remaining work more efficient.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Relation sieving&lt;/strong>&lt;br>
Distribute the expensive search for useful relations across many systems.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Filtering&lt;/strong>&lt;br>
Remove duplicate and unhelpful data before building the matrix.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Sparse linear algebra&lt;/strong>&lt;br>
Solve a huge sparse matrix, a memory intensive task.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Square root and factor extraction&lt;/strong>&lt;br>
Convert the final dependency into one factor: ordinary division reveals the other.&lt;/p>
&lt;/li>
&lt;/ol>
&lt;p>&lt;img src="https://blog.senthorus.ch/rsa_260_factorization/rsa_260_gnfs_pipeline.png"
loading="lazy"
alt="High-level General Number Field Sieve pipeline"
>&lt;/p>
&lt;p>This explains the apparent paradox: &lt;strong>finding&lt;/strong> the factors may require years of aggregate work, while &lt;strong>checking&lt;/strong> them takes seconds.&lt;/p>
&lt;h2 id="what-we-know-and-what-we-still-dont-know">What We Know, and What We Still Don&amp;rsquo;t Know
&lt;/h2>&lt;p>The published factor can be checked independently with a dependency-free Python script:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>N &lt;span style="color:#f92672">=&lt;/span> int(
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;2211282552952966643528108525502623092761208950247001539441374831&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;9128822941402001986512729726569746599085900330031400051170742204&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;5608592763579537571859542988389587092292384910067030341246205457&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;84566413664540684214361293017694020846391065875914794251435144458199&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>p &lt;span style="color:#f92672">=&lt;/span> int(
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;4397328654844826923795068102505872571721883526553349659561256924&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;505973939597593482272505698004801207988043088656411102133523080581&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">assert&lt;/span> N &lt;span style="color:#f92672">%&lt;/span> p &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#ae81ff">0&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>q &lt;span style="color:#f92672">=&lt;/span> N &lt;span style="color:#f92672">//&lt;/span> p
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">assert&lt;/span> p &lt;span style="color:#f92672">*&lt;/span> q &lt;span style="color:#f92672">==&lt;/span> N
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(N&lt;span style="color:#f92672">.&lt;/span>bit_length(), len(str(p)), len(str(q)))
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e"># 862 130 130&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Dividing RSA-260 by &lt;strong>p&lt;/strong> gives the complementary &lt;strong>130-digit prime&lt;/strong>:&lt;/p>
&lt;pre tabindex="0">&lt;code>q = 5028695206842569864686141618253083416610081090075366674776775706538324961364412200138116378509733307971876652984898985905923678379
&lt;/code>&lt;/pre>&lt;p>With both factors known, a direct multiplication is enough to verify the result:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>N &lt;span style="color:#f92672">=&lt;/span> int(
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;2211282552952966643528108525502623092761208950247001539441374831&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;9128822941402001986512729726569746599085900330031400051170742204&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;5608592763579537571859542988389587092292384910067030341246205457&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;84566413664540684214361293017694020846391065875914794251435144458199&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>p &lt;span style="color:#f92672">=&lt;/span> int(
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;4397328654844826923795068102505872571721883526553349659561256924&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;505973939597593482272505698004801207988043088656411102133523080581&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>q &lt;span style="color:#f92672">=&lt;/span> int(
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;5028695206842569864686141618253083416610081090075366674776775706&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#e6db74">&amp;#34;538324961364412200138116378509733307971876652984898985905923678379&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">assert&lt;/span> p &lt;span style="color:#f92672">*&lt;/span> q &lt;span style="color:#f92672">==&lt;/span> N
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(&lt;span style="color:#e6db74">&amp;#34;RSA-260 factorization verified&amp;#34;&lt;/span>)
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>The arithmetic is not the uncertain part. As of September 6, 2026, these details remain undocumented:&lt;/p>
&lt;ul>
&lt;li>the factoring algorithm and parameter choices&lt;/li>
&lt;li>the software and version used&lt;/li>
&lt;li>the hardware, total compute, and wall-clock duration&lt;/li>
&lt;li>whether any new optimization or research contribution was involved&lt;/li>
&lt;/ul>
&lt;p>GNFS is plausible because it is established for balanced composites at this scale. Employment by an AI company is not evidence that AI found the factors, and a joking reference to &amp;ldquo;paper and pencil&amp;rdquo; is not a technical disclosure. There is no public evidence of a quantum computation either.&lt;/p>
&lt;p>The missing methodology changes how the result should be interpreted:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Established GNFS plus large-scale computing&lt;/strong> would be a record and useful calibration point, but a continuation of existing progress.&lt;/li>
&lt;li>&lt;strong>A major implementation or hardware optimization&lt;/strong> could lower the cost of attacking other undersized keys.&lt;/li>
&lt;li>&lt;strong>A fundamentally better algorithm&lt;/strong> would have much broader consequences, but no evidence currently supports that scenario.&lt;/li>
&lt;/ul>
&lt;p>Until a reproducible report appears, the responsible conclusion is simple: the factorization is confirmed, and the claimed technique is not.&lt;/p>
&lt;h2 id="does-this-put-rsa-2048-at-risk">Does This Put RSA-2048 at Risk?
&lt;/h2>&lt;p>At 862 bits, RSA-260 is smaller than legacy 1024-bit keys already considered inadequate for new protection. NIST maps RSA-1024 to no more than 80 bits of classical security and RSA-2048 to approximately 112 bits. RSA-3072 provides about 128 bits.&lt;/p>
&lt;p>Although 2048 is about 2.4 times 862, the required work is not 2.4 times greater. GNFS complexity rises extremely quickly with modulus size.&lt;/p>
&lt;p>The result is also specific to one modulus. It reveals nothing about an unrelated, correctly generated key. Reused primes or weak randomness can connect keys, but those are implementation failures, not consequences of this record.&lt;/p>
&lt;p>An organization still using an 862-bit key should treat this as a serious warning. For correctly generated 2048- and 3072-bit keys, it creates no new immediate attack path. Existing migration plans should continue, but RSA-260 is not itself a breach.&lt;/p>
&lt;h2 id="conclusion---a-record-not-a-cryptographic-collapse">Conclusion - A Record, Not a Cryptographic Collapse
&lt;/h2>&lt;p>RSA-260 is a genuine achievement: a 260-digit challenge that stood for 35 years has been split into two 130-digit prime factors.&lt;/p>
&lt;p>It does &lt;strong>not&lt;/strong> show that RSA-2048 is broken, that a quantum computer was involved, or that AI discovered a new algorithm. Correctly generated modern keys do not require emergency rotation because of this announcement.&lt;/p>
&lt;p>The practical response is simple: retire undersized RSA keys, verify key-generation quality, monitor the eventual technical disclosure, and preserve cryptographic agility.&lt;/p>
&lt;p>Think of RSA-260 as one difficult lock opened after an enormous effort. It measures the frontier of classical computation. It is not a master key for every larger lock.&lt;/p>
&lt;p>For now, the factorization itself is verified and the method remains the open question. That distinction is what turns a dramatic headline into an accurate security assessment.&lt;/p>
&lt;h2 id="sources-and-further-reading">Sources and Further Reading
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://x.com/penlume/status/2095372672356212876" target="_blank" rel="noopener"
>Eric Lu - Original RSA-260 factor announcement (September 3, 2026)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://mysterytwister.org/challenges/level-3/rsa-factoring-challenge-rsa-260" target="_blank" rel="noopener"
>RSA Inc. / MysteryTwister - RSA Factoring Challenge: RSA-260&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://mysterytwister.org/media/challenges/pdf/mtc3-rsa-08-en.pdf" target="_blank" rel="noopener"
>RSA Inc. / MysteryTwister - Original RSA-260 challenge document&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://cado-nfs.gitlabpages.inria.fr/" target="_blank" rel="noopener"
>CADO-NFS Development Team - Number Field Sieve implementation and workflow&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://caramba.loria.fr/rsa250.txt" target="_blank" rel="noopener"
>Fabrice Boudot et al. - Factorization of RSA-250 (February 28, 2020)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://arxiv.org/abs/2006.06197" target="_blank" rel="noopener"
>Fabrice Boudot et al. - Comparing the Difficulty of Factorization and Discrete Logarithm: A 240-Digit Experiment&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final" target="_blank" rel="noopener"
>NIST SP 800-57 Part 1 Rev. 5 – Recommendation for Key Management&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://csrc.nist.gov/pubs/sp/800/131/a/r2/final" target="_blank" rel="noopener"
>NIST SP 800-131A Rev. 2 – Transitioning the Use of Cryptographic Algorithms and Key Lengths&lt;/a>&lt;/li>
&lt;/ol></description></item><item><title>Introduction to post-quantum cryptography and its implications</title><link>https://blog.senthorus.ch/posts/introduction_to_post_quantum_cryptography/</link><pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/introduction_to_post_quantum_cryptography/</guid><description>&lt;img src="https://blog.senthorus.ch/introduction_to_post_quantum_cryptography/intro_to_pqc_quantum_computer_ibm_main_visual.png" alt="Featured image of post Introduction to post-quantum cryptography and its implications" />&lt;h2 id="quantum-vs-classical-computing-simple-first-steps">Quantum vs Classical Computing: Simple First Steps
&lt;/h2>&lt;p>When we talk about computing, the main difference between &lt;strong>classical&lt;/strong> and &lt;strong>quantum&lt;/strong> systems lies in how they represent and process information.&lt;/p>
&lt;p>Classical computers, which underpin most modern IT infrastructure, operate on &lt;strong>bits&lt;/strong>: simple units of data that can take the value of either 0 or 1. You might picture this as a librarian who checks one book at a time, moving quickly but always sequentially.&lt;/p>
&lt;p>Quantum computers, on the other hand, rely on &lt;strong>qubits&lt;/strong>. Unlike classical bits, qubits can exist in a state of 0, 1, or a &lt;strong>superposition&lt;/strong> of both, allowing them to explore multiple possibilities at once. In our librarian analogy, this would be like a clerk capable of reading many books simultaneously: a kind of parallelism that classical systems cannot achieve. This gives quantum machines the potential to solve certain problems much faster than classical ones.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/introduction_to_post_quantum_cryptography/intro_to_pqc_qubit_bloch_sphere.png"
loading="lazy"
alt="QuBit in Bloch Sphere"
>&lt;/p>
&lt;p>From a &lt;strong>cybersecurity&lt;/strong> perspective, this is not just a fascinating scientific development but a &lt;strong>serious concern&lt;/strong>. Many of today’s cryptographic standards, such as those based on the difficulty of factoring large prime numbers, would become vulnerable once practical quantum computing is achieved. This is why organizations like &lt;strong>NIST&lt;/strong> are working on &lt;strong>post-quantum cryptography&lt;/strong> to prepare security teams for the coming paradigm shift.&lt;/p>
&lt;h2 id="why-is-quantum-a-problem-for-current-cryptography">Why Is Quantum a Problem for Current Cryptography?
&lt;/h2>&lt;p>The security of modern public-key cryptography, such as RSA, Diffie-Hellman, and elliptic-curve cryptography (ECC), is based on mathematical problems that are extremely hard for classical computers to solve. Factoring a large number or solving a discrete logarithm would take astronomical amounts of time, making these systems the backbone of secure communication, digital signatures, and key exchanges.&lt;/p>
&lt;p>However, the discovery of specialized quantum algorithms changes everything. &lt;strong>Shor’s algorithm&lt;/strong>, the most famous one, can efficiently factor large numbers and solve discrete logarithms on a powerful quantum computer. If such machines become practical, the assumptions behind RSA and ECC would collapse, allowing attackers to decrypt data, forge signatures, or impersonate trusted entities.&lt;/p>
&lt;p>The impact doesn’t stop there. &lt;strong>Grover’s algorithm&lt;/strong> offers a quadratic speedup for brute-forcing symmetric encryption keys. While this doesn’t break symmetric cryptography entirely, it effectively reduces the security strength of current key sizes, meaning we need to increase key lengths (for example, doubling AES keys).&lt;/p>
&lt;p>The biggest threat lies with &lt;strong>public-key algorithms&lt;/strong>, which enable authentication and key exchange across the internet. This is where post-quantum cryptography (PQC) comes in. PQC focuses on developing cryptographic methods based on &lt;strong>problems that are hard for both classical and quantum computers&lt;/strong>.&lt;/p>
&lt;p>The goal is not to rebuild security from scratch, but to replace vulnerable algorithms with &lt;strong>quantum-resistant alternatives&lt;/strong> for signatures, encryption, and key exchange.&lt;br>
Organizations like &lt;strong>NIST&lt;/strong> are leading this effort, pushing forward the &lt;strong>standardization of PQC algorithms&lt;/strong> so that organizations can start transitioning now, well before quantum computing poses a real-world threat to global cybersecurity.&lt;/p>
&lt;h2 id="available-solutions-whats-already-moving-from-research-to-standards">Available Solutions: What’s Already Moving from Research to Standards
&lt;/h2>&lt;p>The cryptography community has been preparing for the quantum era long before practical quantum computers became a reality.&lt;br>
Anticipating the threat to existing public-key systems, researchers have spent years designing and analyzing new algorithm families capable of &lt;strong>withstanding quantum attacks&lt;/strong>.&lt;/p>
&lt;p>To coordinate this effort, the &lt;strong>U.S. National Institute of Standards and Technology (NIST)&lt;/strong> launched a global, multi-round competition in 2016, inviting academics, industry experts, and governments to propose and evaluate potential replacements.&lt;br>
After several years of testing, cryptanalysis, and performance evaluation, NIST announced a small set of algorithms that will form the foundation of &lt;strong>post-quantum cryptography (PQC)&lt;/strong> standards.&lt;/p>
&lt;p>Two main families stand out in these efforts:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Lattice-based cryptography&lt;/strong>: relies on the difficulty of finding short vectors in high-dimensional lattices. These schemes are efficient, scalable, and currently among the &lt;strong>most practical and widely recommended&lt;/strong> approaches to PQC.&lt;/li>
&lt;li>&lt;strong>Hash-based cryptography&lt;/strong>: built on the one-way properties of cryptographic hash functions. Hash-based signature schemes are conservative and simple in principle. Although they often have larger signature sizes, they provide &lt;strong>strong and well-understood security guarantees&lt;/strong>.&lt;/li>
&lt;/ul>
&lt;p>From this process, &lt;strong>NIST selected four algorithms&lt;/strong> for standardization and deployment:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>CRYSTALS-Kyber&lt;/strong>, for &lt;strong>key establishment&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CRYSTALS-Dilithium&lt;/strong>, for &lt;strong>digital signatures&lt;/strong>&lt;/li>
&lt;li>&lt;strong>FALCON&lt;/strong>, for &lt;strong>digital signatures&lt;/strong> with &lt;strong>compact outputs&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SPHINCS+&lt;/strong>, a &lt;strong>hash-based digital signature&lt;/strong> scheme&lt;/li>
&lt;/ul>
&lt;p>These four represent the &lt;strong>leading edge of quantum-resistant cryptography&lt;/strong> and are expected to become the backbone of secure communication in a post-quantum world.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/introduction_to_post_quantum_cryptography/intro_to_pqc_lattice.png"
loading="lazy"
alt="Lattice and hash illustration"
>&lt;/p>
&lt;p>Credit: N. Hanacek/NIST&lt;/p>
&lt;h2 id="how-organizations-can-prepare">How Organizations Can Prepare?
&lt;/h2>&lt;p>Preparing for the post-quantum era doesn’t require access to a quantum computer. The most effective steps security teams can take today are practical measures that lay the groundwork for a smooth transition. The goal is to build &lt;strong>awareness&lt;/strong>, &lt;strong>flexibility&lt;/strong>, and &lt;strong>resilience&lt;/strong> into your cryptographic infrastructure before the standards fully mature.&lt;/p>
&lt;p>Here are eight concrete actions IT and security leaders can start implementing now:&lt;/p>
&lt;ol>
&lt;li>
&lt;p>&lt;strong>Inventory your cryptography&lt;/strong>&lt;br>
Map out where public-key algorithms are in use across your environment: TLS handshakes, VPNs, code-signing systems, firmware updates, S/MIME, SSH keys, PKI infrastructures, and certificates. Visibility is critical, as you can’t protect what you don’t know exists.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Classify data and lifetimes&lt;/strong>&lt;br>
Identify sensitive data that needs to remain confidential for years or decades, such as intellectual property, medical records, or government archives. Adversaries could be harvesting encrypted traffic today to decrypt later, a concept called “store now, decrypt later.” Long-lived secrets deserve priority protection.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Adopt crypto agility&lt;/strong>&lt;br>
Design systems so algorithms can be swapped or added without disruptive refactoring. Modular TLS stacks, configurable key management services, and dual-stack or layered deployments make future migrations less painful.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Start hybrid deployments&lt;/strong>&lt;br>
Begin experimenting with hybrid key exchange: combining a classical algorithm (e.g., ECDH) with a PQC algorithm. This ensures an attacker would need to break &lt;strong>both&lt;/strong> to succeed. Hybrid deployments reduce risk and give teams hands-on experience. Many vendors already offer hybrid libraries and prototypes.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Track vendor roadmaps and standards&lt;/strong>&lt;br>
Monitor NIST publications, FIPS updates, and announcements from cloud providers, OS vendors, and open-source libraries like OpenSSL or OpenSSH. Aligning with vendor support and emerging standards ensures smoother adoption.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Test in staging&lt;/strong>&lt;br>
Integrate PQC-enabled libraries into test environments and measure their real-world impact. Check performance, key sizes, signature sizes, and interoperability. Lattice-based schemes are generally efficient but come with different tradeoffs compared to RSA or ECC.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Update policies and procurement&lt;/strong>&lt;br>
Require suppliers to report cryptographic dependencies, ask about PQC roadmaps during RFPs, and add clauses mandating crypto agility in new contracts. This ensures your ecosystem evolves alongside your own readiness.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Train your team&lt;/strong>&lt;br>
Educate developers, operations teams, and leadership with targeted briefings. Everyone should understand both the risks and the migration strategy. This builds confidence and avoids bottlenecks later in the transition.&lt;/p>
&lt;/li>
&lt;/ol>
&lt;p>By taking these steps, organizations can begin their &lt;strong>quantum-readiness journey&lt;/strong> without needing to become quantum researchers themselves. The key is positioning your infrastructure so that when NIST standards are finalized and vendor tooling matures, you’ll be ready to move &lt;strong>quickly&lt;/strong> and &lt;strong>securely&lt;/strong>.&lt;/p>
&lt;h2 id="conclusion--short-and-practical">Conclusion – Short and Practical
&lt;/h2>&lt;p>Quantum computers pose a real threat to today’s &lt;strong>public-key cryptography&lt;/strong>, but &lt;strong>post-quantum cryptography (PQC)&lt;/strong> offers a path forward. NIST has already standardized algorithms like &lt;strong>Kyber&lt;/strong>, &lt;strong>Dilithium&lt;/strong>, &lt;strong>FALCON&lt;/strong>, and &lt;strong>SPHINCS+&lt;/strong> to help secure communications against future quantum attacks.&lt;/p>
&lt;p>As Benjamin Lesieux, developer at Alice and Bob, notes:&lt;/p>
&lt;blockquote>
&lt;p>&amp;ldquo;We will have quantum computers powerful enough to break RSA or ECC by the end of the 2030s. It’s impossible to achieve zero risk. Lattice-based cryptography is considered safe, but we can never be certain it’s unbreakable. That’s why it’s crucial to keep following innovations and scientific publications.&amp;rdquo;&lt;/p>&lt;/blockquote>
&lt;p>The message is clear: &lt;strong>don’t wait&lt;/strong>. Start by &lt;strong>inventorying your cryptography&lt;/strong>, classify &lt;strong>long-lived data&lt;/strong>, build systems with &lt;strong>crypto agility&lt;/strong>, and test PQC options, ideally in &lt;strong>hybrid mode&lt;/strong>.&lt;br>
Think of current cryptography as a &lt;strong>padlock&lt;/strong> and quantum computers as a developing &lt;strong>master key&lt;/strong>. PQC is the &lt;strong>next-generation lock&lt;/strong> you’ll want in place before the threat arrives.&lt;/p>
&lt;h2 id="sources-and-further-reading">Sources and Further Reading
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms" target="_blank" rel="noopener"
>NIST – NIST Announces First Four Quantum-Resistant Cryptographic Algorithms (July 5, 2022)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards" target="_blank" rel="noopener"
>NIST Releases First 3 Finalized Post-Quantum Encryption Standards (August 2024)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="noopener"
>NIST PQC Overview and FAQs (CSRC)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips" target="_blank" rel="noopener"
>NIST Announcements and FIPS Approvals (August 13, 2024)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.redhat.com/en/blog/post-quantum-cryptography-lattice-based-cryptography" target="_blank" rel="noopener"
>Intro to Lattice-Based Cryptography (Red Hat explainer)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://quantum.cloud.ibm.com/learning/fr/courses/quantum-safe-cryptography/quantum-safe-cryptography" target="_blank" rel="noopener"
>Quantum-Safe Cryptography – IBM Quantum Cloud Courses&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://csrc.nist.gov/news/2023/three-draft-fips-for-post-quantum-cryptography" target="_blank" rel="noopener"
>NIST – Comments Requested on Three Draft FIPS for Post-Quantum Cryptography (2023)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://alice-bob.com/quantum-computing/" target="_blank" rel="noopener"
>Alice &amp;amp; Bob – Quantum Computing Insights&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://alice-bob.com/roadmap/#whitepaper-think-inside-the-box" target="_blank" rel="noopener"
>Alice &amp;amp; Bob – Roadmap Whitepaper&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.usherbrooke.ca/iq/fr/a-propos" target="_blank" rel="noopener"
>Quantum Institute, Université de Sherbrooke, Canada&lt;/a>&lt;/li>
&lt;/ol></description></item><item><title>INCYBER Forum Japan: Senthorus at the Heart of Japan's Cybersecurity Conversation</title><link>https://blog.senthorus.ch/posts/incyber_forum_japan_2025/</link><pubDate>Fri, 02 Jan 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/incyber_forum_japan_2025/</guid><description>&lt;img src="https://blog.senthorus.ch/incyber_forum_japan_2025/fic_japon_5.png" alt="Featured image of post INCYBER Forum Japan: Senthorus at the Heart of Japan's Cybersecurity Conversation" />&lt;h2 id="where-cybersecurity-meets-strategy-in-tokyo">Where Cybersecurity Meets Strategy in Tokyo
&lt;/h2>&lt;p>At &lt;strong>Senthorus&lt;/strong>, our mission is to stay ahead of threats and translate cybersecurity into a business reality. This December, two of our SOC analysts had the privilege of traveling to Tokyo to attend the very first Japanese edition of the &lt;strong>INCYBER Forum&lt;/strong>. For them, it was the perfect opportunity to combine two passions: &lt;em>Cybersecurity and Japan&lt;/em>.&lt;/p>
&lt;p>Japan today stands at a critical turning point in its digital defense. The past years have seen a rise in highly disruptive cyber incidents, such as the ransomware attack that paralyzed the Port of Nagoya in 2023. On July 4th, the port was forced to halt operations after its terminal management system, the &lt;strong>Nagoya United Terminal System (NUTS)&lt;/strong>, was crippled by a &lt;strong>LockBit 3.0 ransomware attack&lt;/strong>. The incident paralyzed container loading and unloading, with full recovery taking about two days as terminals gradually resumed operations.&lt;/p>
&lt;p>Recognizing the gravity of such threats, Japan’s government elevated cybersecurity to a national security priority in its revised &lt;strong>National Security Strategy&lt;/strong>. Alongside large-scale investments in digital sovereignty and international partnerships, these developments highlight a country determined to strengthen resilience in the face of growing risks.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>&amp;ldquo;Cyber defense is no longer optional. It is Japan’s next frontier.&amp;rdquo;&lt;/strong>&lt;br>
&lt;em>From InCyber Forum Edito&lt;/em>&lt;/p>&lt;/blockquote>
&lt;p>&lt;img src="https://blog.senthorus.ch/incyber_forum_japan_2025/fic_japon_1.png"
loading="lazy"
alt="INCYBER Forum Japan"
>&lt;/p>
&lt;p>&lt;em>Senthorus SOC analysts Guillaume DUMAS (left) and Adam LARABI (right), with Alexis NARDONE (middle), Director of Forward Global (Event organizer)&lt;/em>&lt;/p>
&lt;hr>
&lt;h2 id="the-incyber-forum-a-global-hub-for-cybersecurity">The INCYBER Forum: A Global Hub for Cybersecurity
&lt;/h2>&lt;p>The &lt;strong>INCYBER Forum&lt;/strong> (formerly &lt;em>International Cybersecurity Forum&lt;/em>) is an established event first organized in 2007 and has since become a major international gathering dedicated to digital security and trust.&lt;/p>
&lt;p>Its core mission: to bring together governments, industry leaders, solution providers, and academics around the same table to share insights and shape the future of cybersecurity.&lt;/p>
&lt;p>The forum has expanded beyond its European roots: in 2022, it launched in Canada, and this year it marked a new milestone: its very first edition in Japan.&lt;/p>
&lt;hr>
&lt;h2 id="the-incyber-forum-in-japan">The INCYBER Forum in Japan
&lt;/h2>&lt;p>The inaugural &lt;strong>INCYBER Forum Japan&lt;/strong> took place on &lt;strong>December 4, 2025&lt;/strong>, at &lt;strong>The Prince Park Tower in Tokyo&lt;/strong>. Organized by &lt;strong>Forward Global&lt;/strong>, &lt;strong>Nikkei Inc.&lt;/strong>, and &lt;strong>Dentsu Soken&lt;/strong>, the event gathered key players from Japan’s government, private sector, and research institutions.&lt;/p>
&lt;p>The structure of the event reflected its &lt;strong>triple ambition&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>
&lt;p>&lt;strong>A trade exhibition&lt;/strong> where some 40 partners and vendors showcased the latest solutions in cybersecurity, offering opportunities to connect directly with end users.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>A conference program&lt;/strong> featuring more than 30 speakers covering topics from risk management and incident response to identity protection, cybercrime prevention, and defense strategy.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Leadership and operational structure&lt;/strong> involving key international and local figures: the event was chaired by &lt;strong>Mr. Atsushi ANDO&lt;/strong>, Director General for Active Cyber Defense and Cyber Intelligence at the National Cyber Office, with strategic and operational leadership provided by &lt;strong>Mr. Shigeru KITAMURA&lt;/strong>, Executive Director of the DENTSU SOKEN Center for Economic Security Research (DCER) and former Secretary General of the National Security Secretariat, alongside &lt;strong>Mr. Guillaume TISSIER&lt;/strong>, General Director of the INCYBER Forum at Forward Global.&lt;/p>
&lt;/li>
&lt;/ul>
&lt;p>For &lt;strong>Senthorus&lt;/strong>, it was not just an occasion to observe, but an opportunity to engage with peers worldwide, exchange perspectives, and better understand Japan’s unique cybersecurity landscape.&lt;/p>
&lt;hr>
&lt;h2 id="speakers-and-workshops-key-insights">Speakers and Workshops: Key Insights
&lt;/h2>&lt;p>While the full agenda was rich and diverse, several highlights stood out:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Government perspectives&lt;/strong> on Japan’s national cybersecurity strategy, especially critical infrastructure protection and international cooperation.&lt;/li>
&lt;li>&lt;strong>Industry-led discussions&lt;/strong> on ransomware trends, digital identity security, and supply chain protection.&lt;/li>
&lt;li>&lt;strong>Workshops&lt;/strong> focused on operational best practices, from incident response to threat intelligence sharing.&lt;/li>
&lt;/ul>
&lt;p>The diversity of participants, ranging from Japanese institutions to international experts, illustrated the global, interconnected nature of today&amp;rsquo;s cyber challenges.&lt;/p>
&lt;hr>
&lt;h2 id="on-the-main-stages">On the Main Stages
&lt;/h2>&lt;p>The main stages hosted keynote sessions organized by &lt;strong>Forward Global&lt;/strong>, &lt;strong>Nikkei Inc.&lt;/strong>, and the &lt;strong>Dentsu Soken Center for Economic Security Research&lt;/strong>. It served as a platform for leaders from politics, industry, and major institutions to address critical cybersecurity issues such as active cyber defense, government policy, and economic security.&lt;/p>
&lt;p>Notable sessions included:&lt;/p>
&lt;ul>
&lt;li>
&lt;p>&lt;strong>Mr. Toshikazu OKUYA, Ministry of Economy&lt;/strong>, examined the growing convergence of economic and cyber security, highlighting policy tools and public-private cooperation to protect critical industries, supply chains, and economic sovereignty.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Mr. Shigeru KITAMURA, Former Secretary General of National Security Secretariat and National Security Advisor to the Cabinet&lt;/strong>, focused his session named &lt;em>Cyber Intelligence Sharing and Security Clearance&lt;/em> on the need for trust and secure information exchange between public and private sectors. He underlined how intelligence sharing enhances situational awareness and enables faster, more effective responses to sophisticated cyber threats.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Mr. Norihiko ISHIHARA, CEO of VLC Security Co., Ltd., Member of the Cybergym Advisory Board&lt;/strong>, explored in his session named &lt;em>Latest Developments in AI-Driven Cyber Offense and Defense&lt;/em> how artificial intelligence is reshaping both attack techniques and defensive capabilities. He highlighted the growing use of AI for automation, reconnaissance, and evasion on the offensive side, while emphasizing its parallel role in improving detection, correlation, and response within modern security operations.&lt;/p>
&lt;/li>
&lt;/ul>
&lt;p>&lt;img src="https://blog.senthorus.ch/incyber_forum_japan_2025/fic_japon_2.png"
loading="lazy"
alt="Mr. Norihiko ISHIHARA"
>&lt;/p>
&lt;p>&lt;em>Mr. Norihiko ISHIHARA during his conference&lt;/em>&lt;/p>
&lt;p>These sessions provided deep insights into Japan’s cybersecurity priorities, strategies, and operational best practices from both national and industrial perspectives.&lt;/p>
&lt;hr>
&lt;p>The forum concluded with a closing keynote by &lt;strong>Mr. François FILLON&lt;/strong>, &lt;strong>Former French Prime Minister&lt;/strong>, who reflected on the &lt;em>brutalization of international relations&lt;/em> and its implications for global stability. His remarks emphasized how increasing geopolitical polarization and the erosion of structured dialogue between states are reshaping international dynamics, including in cyberspace. He highlighted the limitations of simplified narratives and stressed the importance of strategic nuance and balanced alliances in an increasingly fragmented world.&lt;/p>
&lt;p>This broader geopolitical perspective provided a fitting conclusion to the forum, underlining the close interconnection between cybersecurity, diplomacy, and global power relations, while also opening the outlook toward the 2026 edition of INCYBER in France.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/incyber_forum_japan_2025/fic_japon_3.png"
loading="lazy"
alt="Mr. François FILLON"
>&lt;/p>
&lt;p>&lt;em>Mr. François FILLON during his conference&lt;/em>&lt;/p>
&lt;hr>
&lt;h2 id="exhibition-area-a-showcase-of-innovation-and-expertise">Exhibition Area: A Showcase of Innovation and Expertise
&lt;/h2>&lt;p>The exhibition area was one of the &lt;strong>highlights&lt;/strong> of the forum, offering the opportunity to engage directly with a wide range of &lt;strong>cybersecurity players&lt;/strong>. International and Japanese vendors such as GMO Internet Group, PwC, Abnormal Security, Cybergym, Filigran, VLC Security, and NEC Security presented their solutions, covering domains from &lt;strong>threat detection&lt;/strong> and identity protection to cyber range training and intelligence-driven defense.&lt;/p>
&lt;p>Walking through the stands allowed for &lt;strong>in-depth discussions&lt;/strong> on concrete operational challenges with solution providers, comparison of different approaches, and a clearer understanding of how cybersecurity tools are adapted to the specific needs of the &lt;strong>Japanese market&lt;/strong>. These exchanges, both technical and strategic, illustrated the &lt;strong>maturity of the ecosystem&lt;/strong> and the strong willingness of Japanese and international actors to collaborate across borders.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/incyber_forum_japan_2025/fic_japon_5.png"
loading="lazy"
alt="Exhibition Area"
>&lt;/p>
&lt;p>&lt;em>Exhibition area, where vendors and partners showcased solutions and engaged with attendees throughout the day. (Credit: @INCYBER_Japan)&lt;/em>&lt;/p>
&lt;hr>
&lt;h2 id="conclusion-why-incyber-japan-matters">Conclusion: Why INCYBER Japan Matters
&lt;/h2>&lt;p>The Japanese edition of the INCYBER Forum comes at a &lt;strong>pivotal moment&lt;/strong> as Japan seeks to turn &lt;strong>cybersecurity awareness&lt;/strong> and policy into effective action amid rising threats and strategic transformation. As &lt;strong>Japan’s Prime Minister Ms. Sanae TAKAICHI&lt;/strong> emphasized, the country is at a turning point in strengthening its cybersecurity capabilities.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>&amp;ldquo;To ensure a coordinated response to change from both the public and private sectors, the government intends to develop a general policy based on the law on strengthening cyber response capabilities [&amp;hellip;]. In this context of increasing security tensions, the first INCYBER Forum held in Japan comes at a particularly timely moment.&amp;rdquo;&lt;/strong>
&lt;em>From Ms. Sanae TAKAICHI, Prime Minister of Japan&lt;/em>&lt;/p>&lt;/blockquote>
&lt;p>For our analysts, attending INCYBER Forum Japan was a way to witness firsthand how Japan is transforming its &lt;strong>cybersecurity strategy&lt;/strong> at a crucial moment. The forum offered &lt;strong>invaluable insights&lt;/strong> but also confirmed something we at Senthorus strongly believe: effective cybersecurity depends on &lt;strong>collaboration across borders&lt;/strong>, industries, and disciplines.&lt;/p>
&lt;p>As Japan strengthens its defenses and forges &lt;strong>new partnerships&lt;/strong>, events like this will play a key role in aligning &lt;strong>strategy with operational realities&lt;/strong>. For MSSPs like Senthorus, they are also reminders that our work in SOCs is part of a &lt;strong>larger global effort&lt;/strong> to protect the digital world.&lt;/p>
&lt;hr>
&lt;h2 id="credits">Credits
&lt;/h2>&lt;p>&lt;strong>Photos:&lt;/strong>&lt;br>
Guillaume DUMAS and Adam LARABI&lt;/p>
&lt;h2 id="sources">Sources
&lt;/h2>&lt;h3 id="incyber-forum--japan-edition">INCYBER Forum – Japan Edition
&lt;/h3>&lt;ul>
&lt;li>Editorial &amp;amp; Introduction: &lt;a class="link" href="https://japan.forum-incyber.com/edito/" target="_blank" rel="noopener"
>https://japan.forum-incyber.com/edito/&lt;/a>&lt;/li>
&lt;li>Program &amp;amp; Speakers: &lt;a class="link" href="https://japan.forum-incyber.com/program/" target="_blank" rel="noopener"
>https://japan.forum-incyber.com/program/&lt;/a>&lt;/li>
&lt;/ul>
&lt;h3 id="incyber-forum--history">INCYBER Forum – History
&lt;/h3>&lt;ul>
&lt;li>Forum Overview: &lt;a class="link" href="https://europe.forum-incyber.com/en/the-forum" target="_blank" rel="noopener"
>https://europe.forum-incyber.com/en/the-forum&lt;/a>&lt;/li>
&lt;li>Wikipedia: &lt;a class="link" href="https://fr.wikipedia.org/wiki/Forum_international_de_la_cybers%C3%A9curit%C3%A9" target="_blank" rel="noopener"
>https://fr.wikipedia.org/wiki/Forum_international_de_la_cybers%C3%A9curit%C3%A9&lt;/a>&lt;/li>
&lt;/ul>
&lt;h3 id="nagoya-port-attack">Nagoya Port Attack
&lt;/h3>&lt;ul>
&lt;li>Dragos Blog: &lt;a class="link" href="https://www.dragos.com/blog/industry-news/ot-cybersecurity-breach-disrupts-operations-at-the-port-of-nagoya-japan/" target="_blank" rel="noopener"
>https://www.dragos.com/blog/industry-news/ot-cybersecurity-breach-disrupts-operations-at-the-port-of-nagoya-japan/&lt;/a>&lt;/li>
&lt;li>Official Notice PDF: &lt;a class="link" href="https://s3.documentcloud.org/documents/23867021/nayoga-notice.pdf" target="_blank" rel="noopener"
>https://s3.documentcloud.org/documents/23867021/nayoga-notice.pdf&lt;/a>&lt;/li>
&lt;/ul>
&lt;h3 id="ms-sanae-takaichi-declaration">Ms. Sanae TAKAICHI declaration
&lt;/h3>&lt;ul>
&lt;li>Kyodonews: &lt;a class="link" href="https://english.kyodonews.net/articles/-/67362" target="_blank" rel="noopener"
>https://english.kyodonews.net/articles/-/67362&lt;/a>&lt;/li>
&lt;li>Japantimes: &lt;a class="link" href="https://www.japantimes.co.jp/news/2025/12/31/japan/politics/spy-law-study/" target="_blank" rel="noopener"
>https://www.japantimes.co.jp/news/2025/12/31/japan/politics/spy-law-study/&lt;/a>&lt;/li>
&lt;/ul></description></item></channel></rss>