Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it?

K Karagiannis (Quantum Computing Services Leader · Pertivity)

DEF CON 33 · Day 1 · Main Stage

Overview

In a stark and urgent presentation at DEF CON, K Karagiannis, Quantum Computing Services Leader at Pertivity, delivered a sobering assessment of the impending threat posed by quantum computers to current cryptographic standards. Titled "Post Quantum Panic," the talk served as a critical alarm bell, challenging the prevailing, often complacent, timelines for post-quantum cryptography (PQC) migration. Karagiannis, with a background spanning physics and penetration testing, articulated that the long-dreaded "quantum apocalypse" is not a distant, theoretical threat, but an imminent reality, potentially arriving years ahead of official estimations.

Watch on YouTube

Visual summary for Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it? by K Karagiannis
Visual summary for Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it? by K Karagiannis

Key moments

  1. 0:00 Post-quantum panic: Why the timeline is shorter
  2. 2:00 Understanding quantum computing: Cubits, superposition, and common myths
  3. 4:00 Shor's and Grover's algorithms: The core cryptographic threats
  4. 5:00 Differentiating physical and logical qubits for practical applications
  5. 6:00 Bitcoin and cryptocurrencies' specific vulnerability to quantum attacks

Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it?

Speakers: K Karagiannis, Quantum Computing Services Leader, Pertivity

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=OkVYJx1iLNs

Overview

In a stark and urgent presentation at DEF CON, K Karagiannis, Quantum Computing Services Leader at Pertivity, delivered a sobering assessment of the impending threat posed by quantum computers to current cryptographic standards. Titled "Post Quantum Panic," the talk served as a critical alarm bell, challenging the prevailing, often complacent, timelines for post-quantum cryptography (PQC) migration. Karagiannis, with a background spanning physics and penetration testing, articulated that the long-dreaded "quantum apocalypse" is not a distant, theoretical threat, but an imminent reality, potentially arriving years ahead of official estimations.

The core message of the talk revolved around the accelerating capabilities of quantum computing hardware, particularly the aggressive roadmaps presented by companies like IonQ and IBM. These advancements, coupled with significant algorithmic optimizations, dramatically reduce the computational resources and time required to break widely used asymmetric and symmetric encryption schemes. Karagiannis highlighted that the NIST-mandated migration deadline of 2035 is dangerously optimistic, urging a radical shift in perspective and immediate action from security professionals and organizational leaders, especially CISOs who often view this as a problem for "future Fred or Mary."

This article delves into the technical underpinnings of the quantum threat, the revised timelines, the implications for data security, and the critical defensive measures that must be adopted now. It emphasizes that for the first time in computing history, we know the approximate date of a zero-day vulnerability – a looming crisis that demands proactive, rather than reactive, preparation to avert a potential economic and identity disaster.

Background

▶ Watch: Post-quantum panic: Why the timeline is shorter (0:00)

The foundation of modern cryptography relies on mathematical problems that are computationally infeasible for classical computers to solve within a reasonable timeframe. However, quantum computers leverage the peculiar phenomena of quantum mechanics, such as superposition, entanglement, and coherence, to process information in fundamentally different ways. Unlike classical bits (which are either 0 or 1), qubits can exist in multiple states simultaneously, theoretically allowing quantum computers to explore many possibilities concurrently. While this doesn't mean they do "everything at the same time" as often misunderstood, it enables specific algorithms to achieve exponential or quadratic speedups for certain problems.

Two quantum algorithms are of paramount concern to current cryptographic security:

  1. Shor's Algorithm: Developed by Peter Shor in 1994, this algorithm can efficiently factor large numbers and solve the discrete logarithm problem. These problems are the bedrock of widely used asymmetric encryption schemes like RSA (Rivest–Shamir–Adleman) and ECC (Elliptic Curve Cryptography), which are fundamental for secure key exchange in protocols like TLS. The ability to factor large numbers would allow an attacker to derive private keys from public keys, effectively compromising the confidentiality and authenticity of communications.
  2. Grover's Algorithm: This is a quantum search algorithm that provides a quadratic speedup for unstructured search problems. For cryptography, this translates to a significant reduction in the time required to brute-force symmetric encryption keys. Instead of needing, on average, half of the total keyspace to find a key, Grover's algorithm can find it in approximately the square root of the keyspace. This directly impacts algorithms like AES (Advanced Encryption Standard).

A crucial distinction in quantum computing is between physical qubits and logical qubits. Physical qubits are the actual hardware components, highly prone to errors caused by environmental factors like temperature, vibration, or even cosmic particles. To perform useful computations, multiple physical qubits are chained together with error-correcting codes to form a single, more stable logical qubit. The number of physical qubits required per logical qubit can be substantial, often in the thousands or even millions, making the reduction of logical qubit requirements a critical metric for assessing the quantum threat.

Historically, the timeline for quantum computers reaching cryptographic breaking capabilities was a nebulous "10 to 20 years away." This changed when NIST (National Institute of Standards and Technology) initiated its Post-Quantum Cryptography (PQC) standardization process. In August 2023, NIST released the first set of PQC finalists, establishing a concrete timeline: current vulnerable ciphers should be deprecated by 2030 and entirely phased out by 2035. This timeline was intended to provide a clear roadmap for migration, similar to past transitions like the deprecation of SSL in favor of TLS. However, as Karagiannis highlighted, many CISOs and organizational leaders exhibit a dangerous complacency, viewing the 2035 deadline as a distant problem, akin to the "future Fred or Mary's problem" mentality, rather than an urgent call to action. This inertia is particularly concerning given the unprecedented nature of the quantum threat, which Karagiannis likens to a "zero-day that we know is coming," with potential for an economic disaster if not addressed proactively.

Key Findings

▶ Watch: Understanding quantum computing: Cubits, superposition, and common myths (2:00)

The central and most alarming finding presented by Karagiannis is the critical disconnect between NIST's projected PQC migration timeline and the actual, rapidly accelerating advancements in quantum computing hardware and algorithms. The widely accepted 2035 deadline for completely phasing out vulnerable cryptography is, according to the speaker, dangerously optimistic and likely to be missed by several years, leaving a significant window of vulnerability.

Specifically, the talk highlighted:

  • Accelerated Hardware Roadmaps: Quantum hardware manufacturers, particularly IonQ and IBM, are projecting capabilities that far outpace the NIST timeline.
  • IonQ's Timeline: IonQ, leveraging acquisitions like Oxford Ionics (for electronic gates) and LightSync (for quantum module interconnectivity), projects significant logical qubit counts much sooner than anticipated.
  • 2027: 10,000 physical qubits, 800 logical qubits.
  • 2028: Capabilities sufficient to run the most advanced Shor's algorithm papers (e.g., Gidney's 2025 paper).
  • 2029: Ability to run literally any of the discussed quantum attack algorithms.
  • 2030: Two million physical qubits, enabling even "sloppiest, laziest algorithm" to crack encryption. This places IonQ's projected breaking capability a full five years ahead of NIST's 2035 "stop using" deadline.
  • IBM's Timeline: While less aggressive than IonQ, IBM's roadmap also indicates that they will be capable of cracking encryption well before 2035.
  • 2029: 200 logical qubits (insufficient for large-scale RSA cracking but significant for other quantum advantages).
  • 2033: 2,000 logical qubits, which would enable large-scale encryption cracking. This still places IBM's capability two years ahead of the NIST deadline. Karagiannis noted IBM's historical record of meeting its deadlines, reinforcing the seriousness of this projection.
  • Dramatic Algorithmic Optimizations: The number of logical qubits required to execute Shor's algorithm for a cryptographically relevant task like cracking 2048-bit RSA has seen a phenomenal reduction in recent years.
  • Early estimates ranged into billions of physical qubits.
  • A 2019/2021 paper ("How to factor 2048-bit RSA integers in 8 hours using 20 million noisy cubits") brought this down to 20 million noisy physical qubits and 6,000 logical qubits with an 8-hour runtime.
  • Gidney's 2025 solo work ("How to Factor 2048 RSA integers with less than a million noisy cubits") further refined this, projecting a requirement of less than 1 million noisy physical qubits and a mere 1,399 logical qubits for 2048-bit RSA, albeit with a 5-day runtime. This represents a reduction of over 75% in logical qubit requirements from just a few years prior, making the threat significantly more "approachable."
  • Impact on Symmetric Encryption: Grover's algorithm effectively halves the security strength of symmetric keys. For instance, AES-128 encryption, often considered robust, would be reduced to an effective AES-64 security level, which is demonstrably insufficient and was "practically cracking that during the crypto wars" (referencing the EFF's DES cracker). The speaker strongly recommended migrating to AES-256 as a minimum, as its security would be reduced to an effective AES-128, still considered acceptable.
  • Moscow's Theorem and Harvest Now, Decrypt Later: The concept of "Moscow's Theorem" (X > Y + Z, where X is data shelf-life, Y is migration time, Z is time to quantum computer) underscores that data harvested today could be decrypted in the near future. Any secret with a shelf-life exceeding 5 years (e.g., state secrets, proprietary designs, personal financial data, Bitcoin private keys) is already vulnerable to the "harvest now, decrypt later" threat. The speaker warned that a single "Elon Musk" tweet about quantum Bitcoin vulnerability could plummet its value to zero overnight.
  • Low PQC Adoption: Despite the looming threat, current adoption rates for Post-Quantum Cryptography (PQC) are alarmingly low. Forescout's analysis found that less than 20% of internet servers are running TLS 1.3 (a prerequisite for PQC), and a mere 6% of surveyed boxes use OpenSSH 10, which defaults to PQC. This indicates a massive gap between the impending threat and current defensive postures.

In summary, the key finding is that the "quantum era of uncertainty" or "Q-day" is not a distant future event but is rapidly approaching, potentially within the next 5-10 years, making the NIST 2035 deadline an inadequate and dangerous target.

Technical Deep Dive

▶ Watch: Shor's and Grover's algorithms: The core cryptographic threats (4:00)

The technical core of the quantum threat lies in the specific mechanisms by which Shor's algorithm and Grover's algorithm exploit the properties of quantum mechanics to undermine classical cryptographic primitives.

Shor's Algorithm: Factoring Large Numbers

Shor's algorithm is a hybrid classical-quantum algorithm, often described as an "Oreo" with classical "cookies" on the outside and a quantum "creamy center." Its primary target is RSA, which relies on the computational difficulty of factoring large composite numbers (N) into their prime factors (p and q).

The algorithm proceeds in several steps:

  1. Classical Pre-processing: A classical computer picks a random integer a such that 1 < a < N and gcd(a, N) = 1. It also checks for trivial factors.
  2. Modular Exponentiation (Quantum Core): The quantum computer is tasked with finding the period (r) of the function f(x) = a^x mod N. This is where quantum parallelism comes into play.
  • The quantum computer creates a superposition of all possible x values.
  • It then performs the a^x mod N calculation on all these superposed values simultaneously. This is not a parallel computation in the classical sense but rather an interference pattern.
  • The result is a superposition of states where the phase information encodes the period r.
  • Karagiannis illustrated this with a simple example: a=4, N=21.
  • 4^1 mod 21 = 4
  • 4^2 mod 21 = 16
  • 4^3 mod 21 = 64 mod 21 = 1
  • 4^4 mod 21 = 4
  • The pattern 4, 16, 1 repeats, so the period r is 3. For large RSA numbers, this period is astronomically large and computationally intractable for classical computers.
  1. Quantum Fourier Transform (QFT): An inverse quantum Fourier transform is applied to the quantum register. This step effectively makes the hidden period r visible by amplifying the probability amplitudes corresponding to multiples of r.
  2. Classical Post-processing: The quantum computer measures the state, which yields a multiple of 1/r with high probability. Classical algorithms then use this information to calculate r. Once r is known, the factors of N can be efficiently derived using gcd(a^(r/2) ± 1, N).

The evolution of Shor's algorithm's resource requirements has been dramatic:

  • Early Estimates: Initially, estimates for cracking 2048-bit RSA required billions of physical qubits.
  • 2019/2021 Paper (Gidney & Ekerå): This seminal paper, "How to factor 2048-bit RSA integers in 8 hours using 20 million noisy cubits," significantly reduced the requirements to 20 million noisy physical qubits and 6,000 logical qubits. Key optimizations included windowed arithmetic and other techniques to minimize the number of multiplications, leading to a 100-fold reduction in "spacetime" (a measure combining qubit count and execution time).
  • 2023/2024 (Regg): An attempt to break Shor's into smaller, distributed quantum jobs using lattice-based approaches was proposed. While interesting, it faced scalability issues in smaller ranges (like 2048-bit RSA) and might require too many gates, making its practical applicability for current targets questionable.
  • 2025 Paper (Gidney): Gideon Gidney's solo work, "How to Factor 2048 RSA integers with less than a million noisy cubits," represents the current state-of-the-art. It achieved a further massive reduction, requiring less than 900,000 noisy physical qubits and only 1,399 logical qubits to crack 2048-bit RSA. This was accomplished through advancements in approximate residue arithmetic and optimizations in magic state distillation (a process to create high-fidelity logical qubits from noisy physical qubits), which reduced the space required for distillation. The estimated runtime is around 5 days, involving repeated runs of 12 hours each.

Grover's Algorithm: Speeding Up Search

Grover's algorithm offers a quadratic speedup for searching an unstructured database, making it highly relevant for brute-forcing symmetric encryption keys. If a classical computer needs N operations to find an item, Grover's algorithm can find it in approximately sqrt(N) operations.

The algorithm relies on two main components:

  1. Oracle: This is a "black box" quantum function that marks the target state (e.g., the correct encryption key). When a state matches the target, the oracle flips its amplitude to -1. The challenge is knowing when to observe the quantum state, as looking too early or too late will not yield the desired result. Mathematical proofs guide the optimal number of iterations.
  2. Amplifier/Diffuser: This component repeatedly amplifies the amplitude of the marked target state while suppressing the amplitudes of other states. Through repeated application of specific quantum gates (like Hadamard and Pauli-X or NOT gates), the probability of measuring the correct key increases significantly with each iteration.

For example, to crack an AES-128 key, a classical brute-force attack would need 2^127 operations on average. Grover's algorithm reduces this to sqrt(2^128) = 2^64 operations. This effectively reduces the security strength of AES-128 to that of AES-64, which is considered highly vulnerable. For AES-256, the security would be reduced to 2^128, still generally considered secure for now, hence the strong recommendation for AES-256.

Potential Further Optimizations

Karagiannis also noted that further optimizations could emerge, potentially accelerating the timeline even more:

  • Denser idle qubits: More efficient use of qubits when not actively computing.
  • Distributed quantum systems/Interconnect: Linking multiple quantum computers to work as one, as IonQ is planning with its LightSync technology.
  • Mathematical trickery: New algorithms or refinements not yet discovered.
  • Artificial Intelligence (AI): AI, as demonstrated by AlphaFold improving matrix multiplication for the first time since 1969, could discover novel, more efficient quantum algorithms or optimize existing ones, potentially finding "one little piece of the math" that drastically improves performance.

These technical advancements, combined with the aggressive hardware roadmaps, paint a picture of an imminent threat that demands immediate and comprehensive PQC migration strategies.

Demo / Proof of Concept

▶ Watch: Differentiating physical and logical qubits for practical applications (5:00)

The talk "Post Quantum Panic" did not feature a live demonstration or proof of concept of a quantum computer actively cracking modern encryption. The speaker explicitly stated, "no one's done this yet," referring to the actual breaking of military-grade or real-world encryption by a quantum machine. This is largely due to the current immaturity of quantum hardware, which, while rapidly advancing, has not yet reached the logical qubit counts, coherence times, and gate fidelities required for such large-scale attacks.

Instead of a practical demonstration, Karagiannis's presentation served as a theoretical yet urgent "proof of concept" of the imminence of such attacks. The entire talk detailed the algorithmic advancements (Shor's, Grover's) and hardware roadmaps (IonQ, IBM) that illustrate how such attacks will become feasible in the near future. The "panic" articulated by the speaker stems from the analytical projection that these capabilities are converging much faster than conventional wisdom or official timelines suggest.

The hypothetical "demo" of quantum cracking was illustrated through:

  • The simplified mathematical example of Shor's algorithm for factoring N=21, demonstrating the principle of period finding.
  • Diagrams showing the repetitive gate operations of Grover's algorithm (Hadamard, Pauli-X) which would be indicative of a search operation.
  • The stark comparison of logical qubit requirements across different Shor's algorithm papers, showcasing the dramatic reduction in resources needed.

The absence of a live hack should not be interpreted as a lack of threat. Rather, it underscores the current critical window for preparation before the theoretical capabilities become practical realities. The speaker's call to action is precisely to prevent a future where such a demonstration could be easily performed by malicious actors.

Defensive Implications

▶ Watch: Bitcoin and cryptocurrencies' specific vulnerability to quantum attacks (6:00)

The implications of an accelerated quantum timeline are profound and necessitate an immediate, aggressive shift in defensive strategies. Karagiannis outlined several critical areas where defenders must focus their efforts:

  1. The "Harvest Now, Decrypt Later" Threat: This is the most immediate and pervasive threat. Adversaries (primarily nation-states and organized crime) are currently collecting vast amounts of encrypted data – communications, financial records, intellectual property, and even Bitcoin transactions – with the intent to store it and decrypt it once powerful quantum computers become available. Any data with a shelf life of more than 5-10 years (e.g., military intelligence, long-term financial contracts, personal health records) is already compromised under this paradigm. This necessitates a review of data retention policies and immediate migration of critical, long-lived data to Post-Quantum Cryptography (PQC).
  1. Detection Challenges: Quantum attacks generally won't "enter your networks." Quantum computers are typically massive, refrigerated systems that operate remotely. Attackers will either use their own machines (nation-states, organized crime) or leverage cloud-based quantum computing services. This means:
  • Local Detection is Difficult: Defenders won't see a "giant refrigerated thing" on their network. Instead, they might observe large exfiltrations of encrypted data, which could be a precursor to a quantum decryption attempt.
  • Quantum Stack Detection: While direct network detection is unlikely, it is theoretically possible to detect quantum attacks at various levels of the quantum computing stack:
  • Code and Circuit Level: Specific routines for Shor's (quantum Fourier transform, modular exponentiation) and Grover's (repeated two-block applications) would be highly recognizable.
  • Compiler and Transpiler Level: Analysis of OpenQASM or similar intermediate representations could reveal the characteristic structures of these algorithms.
  • Circuit Graph Analysis: Specific mixes of C-NOT gates, rotation gates, and other structural motifs could be identified.
  • Pulse Control Level: Even at the lowest level of microwave pulses (e.g., in IBM's transmon qubits), pulse sequence analysis could potentially detect the unique patterns of these algorithms.
  • Cloud Management/Metadata: Logs and metadata from cloud quantum computing providers could theoretically show unusual or suspicious usage patterns indicative of cryptanalytic attacks.
  1. Cloud Provider Dilemma: A significant hurdle to detection is the current policy of quantum cloud providers. IonQ, for example, explicitly told Karagiannis that they are "literally not allowed to look at what you're doing," echoing AWS's general stance of not monitoring customer activity. This creates a "wild west" scenario where, if a machine capable of cracking encryption were available today, an attacker could theoretically log in, pay the (admittedly high) computational cost, and perform attacks without any oversight or detection by the provider. This highlights the urgent need for:
  • New License Agreements and Terms of Service: Cloud quantum providers will need to implement new policies and legal frameworks that prohibit cryptanalytic attacks and potentially allow for monitoring of suspicious activity, similar to how cloud providers stop botnets or illegal activities.
  • Attacker Profile: The primary attackers are expected to be nation-states (with their own quantum computers) and organized crime (who might invest in acquiring or renting quantum resources). Individual "hoodie man" attackers might have a short window, but eventually, access will likely be restricted.
  1. PQC Migration Urgency: The NIST PQC migration timeline (2030 deprecation, 2035 stop) is obsolete. Organizations must accelerate their PQC adoption significantly.
  • NIST Finalists: The first PQC standards released by NIST are ML-KEM (Module-Lattice-based Key Encapsulation Mechanism) for key exchange and ML-DSA (Module-Lattice-based Digital Signature Algorithm) for digital signatures, both based on lattice-based cryptography. HQC (Hash-based Quasi-Cyclic codes), a code-based cryptography algorithm, is expected next year.
  • Current Adoption: The current state of PQC readiness is abysmal:
  • Less than 20% of internet servers are running TLS 1.3, which is a prerequisite for PQC implementation.
  • Only 6% of surveyed boxes use OpenSSH 10, which defaults to PQC. Karagiannis emphasized that simply updating to OpenSSH version 10 is all that's required for PQC readiness in this context, making the low adoption rate particularly concerning.
  • Symmetric Key Strength: Defenders must immediately migrate from AES-128 to AES-256. While AES-128 offers 128 bits of security classically, Grover's algorithm effectively reduces this to 64 bits, which is easily breakable. AES-256, reduced to 128 bits of effective security by Grover's, remains a viable option. Simple steps like ensuring BitLocker defaults to 256-bit encryption on new machines can make a difference.
  • Migration Cycle: Organizations need to establish a continuous migration cycle, encompassing discovery of cryptographic assets, assessment of their vulnerability, prioritization based on data shelf-life, and phased implementation of PQC solutions.

The overall defensive posture must shift from a long-term planning mindset to an urgent, proactive implementation phase. The "post-quantum panic" is not a drill; it's a rapidly approaching reality that demands immediate and decisive action.

Key Takeaways

  • NIST's PQC Timeline is Critically Outdated: The official NIST deadlines of 2030 for deprecating vulnerable crypto and 2035 for stopping its use are dangerously optimistic. Quantum hardware roadmaps (IonQ, IBM) indicate cryptographically significant capabilities could arrive as early as 2028-2033, creating a multi-year gap of extreme vulnerability.
  • Drastic Reduction in Qubit Requirements: Recent algorithmic advancements, particularly Gidney's 2025 work, have reduced the logical qubit count required to break 2048-bit RSA from 6,000 to approximately 1,399, making the quantum threat significantly more "approachable" and immediate.
  • Symmetric Encryption is Also Vulnerable: Grover's algorithm effectively halves the security strength of symmetric keys. AES-128 becomes equivalent to AES-64, which is easily breakable. A minimum of AES-256 (providing 128 bits of post-quantum security) is strongly recommended for all new implementations and migrations.
  • "Harvest Now, Decrypt Later" is a Present Threat: Any sensitive data with a shelf life exceeding the next 5-10 years, if encrypted with current standards, is already vulnerable to collection by adversaries for future decryption by quantum computers. This includes financial, state, and personal secrets.
  • PQC Adoption is Alarmingly Low: Despite the impending threat, PQC readiness is minimal, with less than 20% of internet servers supporting TLS 1.3 and only 6% using PQC-enabled OpenSSH 10. Immediate, widespread migration to NIST-approved PQC algorithms like ML-KEM and ML-DSA is crucial.
  • Cloud Quantum Computing Poses New Risks: Current cloud quantum computing providers often have policies against monitoring customer activity, creating a potential "wild west" scenario where nation-states or organized crime could conduct cryptanalytic attacks undetected. New terms of service and monitoring capabilities are urgently needed.

About the Speaker(s)

K Karagiannis is the Quantum Computing Services Leader at Pertivity, a role that places him at the forefront of understanding and addressing the practical implications of quantum technology. His career path is notably diverse, beginning in the foundational science of physics before transitioning into the practical realm of penetration testing. This unique blend of theoretical and applied experience provides him with a comprehensive perspective on the quantum threat, allowing him to bridge the gap between complex quantum mechanics and real-world cybersecurity challenges. Beyond his work at Pertivity, Karagiannis hosts a podcast for the company, where he engages with leading experts in the quantum field, including figures like Dean Casman from IonQ, whose company's aggressive roadmap plays a significant role in Karagiannis's urgent warnings. At DEF CON, he holds the esteemed title of "quantum village elder," underscoring his deep expertise and commitment to educating the security community on this critical, evolving threat.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-structured PQC threat briefing that synthesizes hardware roadmaps and algorithmic progress into an accessible urgency narrative. The material is solid but largely derivative — Gidney's papers, NIST timelines, and harvest-now-decrypt-later are well-trodden ground at this point. The detection angle is the only genuinely novel hook, and it's underdeveloped.

Heather Calloway (CISO) — SOLID

Karagiannis makes a credible and timely case that the NIST migration timeline is already obsolete, and the hardware/algorithm data he marshals is genuinely useful for anyone trying to pressure an organization into action. But the talk is pitched at awareness, not decision — it tells CISOs the house is on fire without giving them the keys to the fire truck.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33