Uploaded May 2026 | Updated September 2026, 2 weeks ago
This session of RWPQC 2026 shifts the conversation from cryptographic theory to global-scale operations. Experts from IBM, AWS, and Signal discuss the friction of migrating legacy protocols, the "Two Pizza Team" philosophy in cloud security, and the necessity of redesigning messaging systems for a post-quantum world.
In this session:
-Mike Osborne (IBM): Explains why enterprises focus on interfaces and protocols rather than algorithms. He introduces a methodology for prioritizing external data flows and managing "Protocol Agility" to handle the shift from classical to quantum-safe authentication.
-Matt Campagna (AWS): Provides a deep dive into deploying ML-KEM and ML-DSA across AWS infrastructure. He details the challenges of FIPS 140 review for hardware security modules (HSMs) and the use of "External Mu" for high-performance signature APIs.
-Rolfe Schmidt (Signal): Shares Signal’s journey in migrating to PQXDH and the "Sparse Post-Quantum Ratchet." He discusses the specific challenges of bandwidth constraints in mobile environments and Signal's research into Falcon’s message recovery modes.
Key topics you’ll hear about: Distinguishing between "Moonshot" (Passive) and "Active" attacks, managing PQC in FIPS-certified hardware, and why the industry is migrating systems, not just implementations.
Chapters:
00:00 - Introduction to Session 4
00:22 - Mike Osborne (IBM): Reframing Migration as a Business Risk
04:03 - The "Hidden" Standards: Telco, IoT, and Healthcare
08:38 - Protocol Agility vs. Product Agility
11:32 - IBM’s Quantum Roadmap: 2,000+ Logical Qubits by 2033
15:59 - Interfaces vs. Internals: Why Vendors Favor C-BOMs over S-BOMs
28:12 - Matt Campagna (AWS): The Shared Responsibility Model in PQC
31:37 - AWS Integration: S2N and AWS-LC in the Deployment Pipeline
35:22 - Challenges of Statefulness in Cloud HSMs
39:26 - Implementing "External Mu" for ML-DSA (FIPS 204)
41:13 - The "Two Pizza Team" Philosophy for Crypto Innovation
50:56 - Rolfe Schmidt (Signal): Operationalizing PQC for Millions of Users
54:12 - PQXDH: Protecting against "Harvest Now, Decrypt Later" (HNDL)
58:45 - The "Sparse Post-Quantum Ratchet": Healing Session State
01:03:11 - Moving to a Fully Post-Quantum Handshake
01:05:06 - Falcon 512: Message Recovery and Bandwidth Optimization
01:08:31 - Post-Quantum Private Groups & Zero-Knowledge Proofs
#sandboxaq
This session of RWPQC 2026 shifts the conversation from cryptographic theory to global-scale operations. Experts from IBM, AWS, and Signal discuss the friction of migrating legacy protocols, the "Two Pizza Team" philosophy in cloud security, and the necessity of redesigning messaging systems for a post-quantum world.
In this session:
-Mike Osborne (IBM): Explains why enterprises focus on interfaces and protocols rather than algorithms. He introduces a methodology for prioritizing external data flows and managing "Protocol Agility" to handle the shift from classical to quantum-safe authentication.
-Matt Campagna (AWS): Provides a deep dive into deploying ML-KEM and ML-DSA across AWS infrastructure. He details the challenges of FIPS 140 review for hardware security modules (HSMs) and the use of "External Mu" for high-performance signature APIs.
-Rolfe Schmidt (Signal): Shares Signal’s journey in migrating to PQXDH and the "Sparse Post-Quantum Ratchet." He discusses the specific challenges of bandwidth constraints in mobile environments and Signal's research into Falcon’s message recovery modes.
Key topics you’ll hear about: Distinguishing between "Moonshot" (Passive) and "Active" attacks, managing PQC in FIPS-certified hardware, and why the industry is migrating systems, not just implementations.
Chapters:
00:00 - Introduction to Session 4
00:22 - Mike Osborne (IBM): Reframing Migration as a Business Risk
04:03 - The "Hidden" Standards: Telco, IoT, and Healthcare
08:38 - Protocol Agility vs. Product Agility
11:32 - IBM’s Quantum Roadmap: 2,000+ Logical Qubits by 2033
15:59 - Interfaces vs. Internals: Why Vendors Favor C-BOMs over S-BOMs
28:12 - Matt Campagna (AWS): The Shared Responsibility Model in PQC
31:37 - AWS Integration: S2N and AWS-LC in the Deployment Pipeline
35:22 - Challenges of Statefulness in Cloud HSMs
39:26 - Implementing "External Mu" for ML-DSA (FIPS 204)
41:13 - The "Two Pizza Team" Philosophy for Crypto Innovation
50:56 - Rolfe Schmidt (Signal): Operationalizing PQC for Millions of Users
54:12 - PQXDH: Protecting against "Harvest Now, Decrypt Later" (HNDL)
58:45 - The "Sparse Post-Quantum Ratchet": Healing Session State
01:03:11 - Moving to a Fully Post-Quantum Handshake
01:05:06 - Falcon 512: Message Recovery and Bandwidth Optimization
01:08:31 - Post-Quantum Private Groups & Zero-Knowledge Proofs
#sandboxaq










