Apple just opened a new live venue at its UK Battersea Power Station headquarters in London that seems tailor-made for Apple Music Live concerts and recordings. Apple Music Hall is designed as an “intimate concert hall” with space for up to 600 people in standing and seating configurations, the company said. As you’d expect, it’s also one of the most state-of-the-art in the world with 48 speakers, 16 camera locations and a Spatial Audio live-recording facility.
“Today, with the opening of Apple Music Hall, we are once again taking an unprecedented step further in our commitment to artists and fans by supporting live music in ways only Apple can do,” said Apple’s VP of Apple Music and International Content, Oliver Schusser.
The new venue’s interior design takes cues from the Battersea Power Station with “heritage brickwork, fluted arches and bronze balconies” along with a glass wall, Apple noted. The main and balcony seating is designed to provide audience intimacy, while the 38-foot-wide stage can be reconfigured for traditional front-facing sets or in-the-round experiences.
The venue is also designed for audiences that can’t make it to the live shows. With a 48-speaker Spatial Audio with Dolby Atmos sound system and 16 camera mounting locations along with a full live streaming facility, it can beam high-quality live music and video around the world. It’s equipped with two dedicated recording and mix studios so that performances can be captured in multitrack recordings mixed in Spatial Audio, “live or after the fact,” Apple said. For video, there’s a purpose-built broadcast control room with “infrastructure to support iPhone video capture” and presumably other, higher-quality cameras.
Advertisement
It’s liable to be popular with musicians thanks to the high-end dressing rooms for bands and crews offering views over Battersea Power Station’s shopping and dining facilities. Apple will certainly be the primary beneficiary of the new venue, though up-and-coming artists will too.
“It’s important for us to help and provide smaller artists with a smaller space, that has state-of-the-art technology and is really plug-and-play,” Schusser told Wallpaper. “You can come in, do an interview…, get your photography and social media done, play a show, broadcast worldwide, and get a high-quality Spatial Audio recording out of it. That’s a phenomenal setup for artists to do great work.”
Anthropic and OpenAI have asked Australian lawmakers to reconsider rules that stop them from training AI models on the country’s creative work, Reuters reported on Tuesday, citing the companies’ submissions to a parliamentary inquiry into AI laws.
In October 2025, the Australian government stated that it would not include a text and data mining exception in its copyright legislation.
In effect, this means that AI developers must obtain permission from copyright holders to train their machines on those works, a situation that in practice prevents mostly US-based laboratories from training models in the country.
Both companies have acknowledged that decision in their submissions but are asking for some margin around it. Anthropic has acknowledged that broad copyright exceptions have been ruled out and has therefore suggested a ‘narrow form of conditional approval’ for the purpose of model training.
Advertisement
Also, it stated that it would be open to conditions such as investment or other measures intended for the support of Australian creators and cultural work; OpenAI requested a balanced framework which would enable the models to learn from publicly available information while at the same time providing rights holders with opportunities to work together with AI companies.
Both companies connected the question to their intended data center plans in Australia; OpenAI has a power purchase agreement with NextDC for a site it plans to build in Sydney, and Anthropic was announced last week as a partner in a data center project in Queensland.
Anthropic has established that connection previously; when briefing notes were made public as a result of a request under the Freedom of Information Act, it was stated that Anthropic’s chief executive, Dario Amodei, had raised the issue of copyright with Treasurer Jim Chalmers in April, according to AFP.
The officials noted that Anthropic would claim its investment in Australia depended on there being clarity regarding copyright settings.
Advertisement
The creative industries, on the contrary, have made a strong effort. In July, Sarah Hanson-Young, a Green senator and chairwoman of a Senate inquiry into AI and data centers, stated that AI companies wishing to train on copyrighted material “should pay for it just as everyone else does”.
Anthropic has also encountered this problem in court. In the United States, it agreed in 2025 to pay $1.5 billion to settle a class action brought by authors over books that had been pirated and used in its training data, following a ruling by a judge that training on lawfully acquired books could be considered fair use.
The submissions were handed to a joint select committee on AI which both houses of parliament established in August. At the same time, Australia intends to introduce more comprehensive AI and data center regulations next year.
For example, GoPro sent a Laowa 7.5-mm lens for me to test with. When HyperSmooth is on, that’s the equivalent of shooting with a 23-mm lens on a full-frame camera. With HyperSmooth off, it becomes a 20-mm lens. I bring this up mainly because if you want to go really wide on the ILS, you’ll need a very, very wide lens (fisheye lenses are probably your best bet).
Now for the downside to the ILS: There are no electrical contacts, which means lenses that rely on electronic focus or aperture control probably won’t work. For example, my all-time favorite MFT lens, Panasonic’s original 20-mm pancake, won’t work on the ILS because there’s no manual aperture ring.
Your best bet is to stick with fully manual lenses that have a mechanical aperture ring. There aren’t many, but there are enough with quality glass to cover a good range of focal lengths. GoPro’s Abe Kislevitz put together a nice collection of lenses that he has tested with the Mission 1 Pro ILS, along with his recommendations for various shooting scenarios. Be aware that the camera is sold body-only, and so far, we haven’t seen any bundles from GoPro or resellers that include a lens.
And yes, you have to manually focus. I could drop some jokes here about kids today not knowing how to do it, but the truth is, I shoot vintage manual-focus lenses all the time on my Sony A7R II. While I’ve shot sports and wildlife with these lenses and had a pretty high success rate, I struggled to focus on the ILS.
Advertisement
The problem with focusing on the ILS is the small screen. It’s hard to see, not just in bright daylight. It’s just really small. There is focus peaking, which uses color banding to indicate what’s in focus, but it can be hard to see exactly where it ends, and I’ve learned from my Sony not to fully rely on peaking.
You can zoom in to get very precise focus, which is what I do on the Sony, but again the small screen makes it hard to see. Worse, for filmmakers especially, you have to have the camera at eye level to focus it well, which limits your shooting ability (or you get to contort into all sorts of weird poses). I would love to see the next Mission 1 Pro ILS get a tilting screen; it’s not waterproof anyway, so it doesn’t seem like there would be a need to reengineer. GoPro no doubt would suggest using the app on my phone, as it does make it considerably easier to focus, but then you need a cage, and then a handle, and at that point most of the Mission 1 Pro ILS’ size advantage is gone; you might as well get a Panasonic GH7, which has an even larger sensor.
Ultimately, while focusing on the small screen is challenging, using a phone or other external monitor sidesteps that issue (and is what pro filmmakers do anyway), but the inability to control the lens iris electronically feels like a bigger limitation since it eliminates a significant number of lenses. It would be nice to see a future Mission 1 Pro ILS support at least electronic connectors for aperture and manual focusing on lenses that require it.
Shooting With the Mission 1 Pro ILS
Once you get past the hurdle of manual focusing, there’s a lot to love about the ILS footage. Testing it reminded me more than anything of the Blackmagic Pocket Cinema Camera from several years ago. I can’t believe this tiny little thing can match the quality of those early Blackmagic cameras.
In a recent video [Jeff Geerling] addresses an issue discovered with the Raspberry Pi firmware, specifically how since around 2024 the firmware locks down what RAM size and even module is supported. This isn’t an issue that is widely known, probably because most people just use the board as-is, but it can be an unpleasant surprise for those looking to upgrade or repair their Pi.
Naturally there is a valid reason for wanting to prevent unscrupulous RAM module changes, with a [Geekworm] blog post from earlier this year detailing this exact issue and how each board is marked with a specific code that identifies the model, RAM size, RAM manufacturer and such. Based on the earlier linked forum post and also a 2025-era GitHub ticket on the rpi-eeprom project, the resulting symptoms seem to vary from not seeing the additional RAM to the board not booting at all.
Although you can go back to an older EEPROM firmware image to work around this, it’s still very annoying that this is even a thing. As also noted by [Jeff], the primary frustration here is probably one of ownership. When you can upgrade the RAM on just about any device you can buy, including a modern GPU and even Apple computer, but not on a Raspberry Pi board that loves to flaunt its open source/hardware credentials, then something is very much off.
Advertisement
In the end it’s highly unfortunate that Raspberry Pi has chosen this path that feels a bit too much like the hardware pairing that companies like Apple got rightfully called out on.
Newly minted Apple CEO John Ternus has praised the Apple Vision Pro, calling it an amazing device that is finding more users, but also that it’s in its very earliest days.
John Ternus has been criticized for laying off workers in the company’s Apple Vision Pro division, but in a new interview for French television, he says he’s enthused about the device’s future. The Canal+ arts show Clique TV asked him directly whether or not he considered the Apple Vision Pro to be a failure.
“You know, Vision Pro, to me, is an amazing device, right, it’s an absolutely amazing device, but I think of it as, like, the early days of computers,” he said. “It is the early days of a long journey, that’s how I feel about Vision Pro.”
“What you’re seeing with Vision Pro now is, certainly, there’s early adopters who love it and they’re using it, they’re enjoying it,” he continued, “but you also [see] surgeons are starting to use it in surgery, because it’s just a fundamentally better tool for them than a monitor that’s kind of sitting over there.”
Advertisement
Ternus claimed that people are finding more uses for the Apple Vision Pro and that this is where he sees a “very bright future” for the device.
He wasn’t pressed for any commitment over whether the Apple Vision Pro would continue to be developed. But he was asked what difference it makes to Apple that the company’s new CEO is an engineer.
“I don’t think anything’s really changed,” he said. “I think, sure, I’m new in this job, but the focus on innovation, the focus on products, the focus most importantly on our customers, that has never changed, that’s been here from the beginning.”
“I am super passionate about products, I love building things, that’s why I’ve been here for so long [and] that’s why I love what I do,” Ternus continued. “I don’t think of it as some radical change, I just couldn’t be more excited about the future.”
Advertisement
This issue of him being an engineer has been repeatedly brought up since his predecessor Tim Cook was famously “not a product person.” But Apple today is far from the computer product firm it originally was, and Ternus is presiding over a $5 trillion company with multiple services as well as hardware.
Disclaimer: Unless otherwise stated, any opinions expressed below belong solely to the author. Data sourced from the Ministry of Manpower.
While Singapore’s latest labour market figures point to a slowdown in hiring, with retrenchments rising last quarter and re-entry into employment becoming tougher, there are still plenty of job openings available.
There are close to 70,000 vacancies in Singapore, including almost 40,000 PMET positions—jobs for professionals, managers, executives and technicians.
These roles also tend to pay significantly more. Last year, the median monthly income for resident PMETs was S$7,600, compared with S$5,755 across all resident workers and less than half that for non-PMET workers.
Advertisement
With the Ministry of Manpower releasing its second-quarter labour market report on Sept 21, we now have a clearer picture of which industries and occupations are still hiring—and where those nearly 40,000 PMET opportunities are.
Where to look for work in Singapore?
While the number of vacancies has dropped by around 8.6% compared to Q1, there are still thousands of jobs available, across all industries, including some of the best paying ones like Finance or IT.
Number of PMET vacancies in Singapore in 2026, by industrial group
Q1 2026
Q2 2026
TOTAL
43,000
39,300
Community, Social and Personal Services
11,900
12,400
Manufacturing
4,900
5,000
Professional Services
5,000
4,700
Financial and Insurance Services
6,300
4,500
Information and Communications
4,600
3,900
Construction
3,300
3,000
Wholesale and Retail Trade
2,900
2,500
Accommodation and Food Services
900
900
Real Estate Services
600
800
Transportation and Storage
1,200
700
Administrative and Support Services
1,000
400
OTHERS
400
400
The government leads the pack
For finer detail, we can look at specific industries within each larger grouping, which reveal that the government continues to be the most eager employer, offering over 8,000 openings—up by 20% from the first quarter.
In this breakdown, Financial Services and IT jump up to 2nd and 3rd place, respectively, showing that there’s continuous demand for qualified workers, even amid the fears that AI is going to take many high-paying jobs there.
Advertisement
Number of PMET vacancies in Singapore in 2026, by specific industry
Q1 2026
Q2 2026
TOTAL
43,000
39,300
Public Administration & Education
7,000
8,400
Financial Services
5,500
3,900
IT & Other Information Services
4,300
3,600
Health & Social Services
3,800
3,200
Construction
3,300
3,000
Legal, Accounting & Management Services
2,800
2,500
Wholesale Trade
2,300
2,000
Electronic, Computer & Optical Products
1,600
1,700
Fabricated Metal Products, Machinery & Equipment
1,200
1,400
Architectural & Engineering Services
1,200
1,100
Other Professional Services
1,100
1,100
Real Estate Services
600
800
Petroleum, Chemical & Pharmaceutical Products
700
600
Transport Equipment
600
600
Insurance Services
700
600
Other Community, Social & Personal Services
900
600
Retail Trade
600
500
Food & Beverage Services
600
500
Accommodation
300
400
Food, Beverages & Tobacco
200
300
Other Manufacturing Industries
500
300
Water Transport & Supporting Services
400
300
Other Transport & Storage Services
300
300
Telecommunications, Broadcasting & Publishing
400
300
Other Administrative & Support Services
700
300
Arts, Entertainment & Recreation
200
200
Paper/Rubber/Plastic Products & Printing
100
100
Land Transport & Supporting Services
200
100
Air Transport & Supporting Services
300
100
Cleaning & Landscaping
200
100
OTHERS
400
400
With 40% of the offers concentrated in the Top 3, it seems that quality follows quantity. Public jobs are not known to pay poorly, while finance and tech are even more generous.
There certainly is some disconnect between the very high pace of economic growth, with GDP hitting close to 6% year-on-year, and the job market, which seems far less optimistic. However, the number of PMET vacancies today is still roughly 50% higher than it used to be before the pandemic.
It might be harder to get a job than it was during the rapid, post-COVID revival, but most still succeed, and there are many options to choose from. Of course, your individual situation depends on your qualifications, career goals and the industry you’re in.
Read other articles we’ve written on Singapore’s job landscape here.
It wants to be treated as a financial services platform.
PJ McDonnell/Shutterstock
Polymarket has been speaking with regulators in the European Union and the UK to persuade them to treat it as a financial services group, according to the Financial Times. That way, it wouldn’t be subject to gambling laws and could overturn its ban in Spain and France. Polymarket, if you’re not familiar with it, is a “prediction market” website that offers users a way to bet on the outcome of future real-world events, including elections, sports matches and tournaments, box office openings and even international conflicts.
The company reportedly talked to the European Commission and the European Securities and Markets Authority (ESMA), in hopes that they would agree to regulate it under MiFID rules. MiFID, or Markets in Financial Instruments Directive, is the EU law with standardized rules for investment services. EU nations have different gambling laws, which would make it difficult for Polymarket to operate in the region. The company’s representatives have also reportedly met with Nikhil Rathi, the chief executive of Financial Conduct Authority (FCA), the UK’s regulator for financial services firms and markets.
Spain blocked both Polymarket and Kalshi in the country back in May, while it investigates their legality to operate without a gambling license. In July, France ordered ISPs to block locals’ access to Polymarket in its country. Under current rules, Polymarket is required to secure a gambling license in EU countries. The UK’s FCA previously said that while it has the power to oversee prediction markets on “financial or certain climactic events,” those that offer trades on political outcomes and sports would be under the authority of the Gambling Commission.
Advertisement
ESMA, as the Times notes, doesn’t seem enthused with loosening EU rules on prediction markets and recently issued a warning that they’re “rife with insider trading.” Indeed, within just the past few months, a Google employee, three political candidates and a White House staff member were caught trading on insider information on the platforms. It’s also worth noting that Polymarket has allegedly been paying social media influencers to post fake betting videos as advertisements. According to a previous report by The Wall Street Journal, half of the “winning” bets placed in those fake videos would have lost in real life.
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates.
The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates.
“Made a funny tool, completely denies defender from updating so you’re stuck with your current version if the tool is running in the background,” he said.
Advertisement
“This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea.”
Since April 2026, Naceri has released almost a dozen zero-day exploits as part of an ongoing dispute with Microsoft over their alleged unfair termination in March 2025.
Two weeks ago, they released another Defender zero-day exploit that grants SYSTEM access (known as ‘ShieldCrash‘) right after Microsoft rolled out this month’s Patch Tuesday security updates.
According to Naceri, ShieldCrash bypasses another ShieldBreak Defender privilege escalation flaw patched a week earlier, which itself bypassed RoguePlanet, another Defender flaw the security researcher disclosed in June and Microsoft patched in July.
Microsoft initially responded with warnings of legal action against anyone engaging in “malicious activity causing real harm” to the company’s customers, leading many in the infosec community to believe that Microsoft was directly threatening the security researcher.
While Microsoft has fixed some of the security flaws Naceri disclosed (such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws), the other security issues still lack an official patch.
A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the BigDiskBuster denial-of-service zero-day.
Advertisement
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
A controller at this level from Microsoft rarely dips under forty pounds, which makes the current price feel less like a routine discount and more like a rare window worth acting on before it closes.
Advertisement
More than three thousand people bought this exact controller in the past month, and it currently ranks as the best selling controller for Xbox Series X and S, backed by a 4.6 star rating from 3,114 global ratings.
Every surface a thumb or finger actually touches during a session has been redesigned with a textured grip, from the triggers and bumpers to the back case, so the pad stays planted in your hands through long, sweaty sessions.
Advertisement
The new hybrid D-pad brings a level of precision that fighting game and platformer fans notice the moment they line up a combo or a jump. Plugging in over USB-C means it charges and plays through the same cable, so there is no separate dock cluttering the desk.
Advertisement
A dedicated Share button on the Xbox Wireless Controller lets you capture and send off a screenshot or a clip the instant something worth keeping happens on screen, without ever pausing the action to dig back through menus to find it.
Xbox Wireless and Bluetooth support mean the same pad pairs with a Series X|S console, an Xbox One, a Windows PC, or a compatible phone or tablet without buying a separate adapter, and the Xbox Accessories app lets you remap every button to taste.
If you are still gaming on the pad that came in the box, or nursing a worn-out controller that no longer feels reliable, £39.99 makes the Xbox Wireless Controller in Carbon Black an easy upgrade to make now.
Ireland was among the countries considered by the European Court of Auditors.
A new report published by the European Court of Auditors (ECA) has found that information sharing, or rather the lack thereof, among EU member states, is creating gaps in cybersecurity for the region.
Among the countries investigated for the purpose of research were Ireland, Greece and Italy.
The ECA’s research found that cybersecurity incidents have the potential to disrupt public services, businesses, critical infrastructure and the EU’s internal market. Largely, the responsibility for responding to cyber incidents is placed on member states, but the wider EU community plays a critical role.
Advertisement
The ECA in a statement said, “This is the case particularly when such incidents cause major disruption, significant financial losses, or substantial harm to people or organisations (significant cybersecurity incidents), or when they affect several member states and go beyond the capacity of a single country to respond effectively, (large-scale cybersecurity incidents).”
According to the report, the EU has been increasingly investing in stronger cybersecurity via the 2021-2027 EU budget and the Digital Europe Programme, which has provided funding of €1.4bn, the main source of cybersecurity funding.
Despite this however, the ECA auditors are of the opinion that there is a clear ‘Achilles heel’ element, in that the system is too dependent on an insufficient exchange of information.
The ECA said, “The Cyber Blueprint, which was adopted in 2025, largely clarifies roles and responsibilities by setting out how the EU should manage major cybersecurity crises. However, the way the two EU cyber networks work together has still not been formally defined.
Advertisement
“This hampers the cooperation of the CSIRTs network, which brings together national teams dealing with cyber incidents and EU-CyCLONe, an EU network for cyber crisis cooperation.”
Additionally, some EU countries are still in the process of updating their cybersecurity policies in a landscape where national security rules are limiting the level of information that can be shared. The ECA claims this is resulting in an environment in which EU networks may struggle to detect threats early on, or coordinate an effective response.
This is further exacerbated by an overlap in EU bodies responsible for monitoring cybersecurity threats.
Commenting on the findings, George-Marius Hyzler, the ECA member in charge of the audit, said, “The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should.
Advertisement
“When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value.”
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
In March, Google moved its own post-quantum cryptography (PQC) migration deadline forward to 2029, a full six years ahead of NIST’s guidance, and two ahead of the NSA’s requirement for national security systems. It was a terrific bit of security signaling, but now it is backed up by a new product-by-product roadmap organized around three risk domains, with milestones attached to named services.
Jason Soroko
Jason Soroko is the SVP of Product at Sectigo.
Advertisement
For anyone whose job touches digital trust, the most significant of those three domains is Google’s attempt at enhancing foundational capabilities for cryptographic agility: building flexible systems that can adopt new cryptographic standards with minimal engineering effort as those standards evolve.
The message is that organizations should prepare for a future in which standards, certificate formats, and operational requirements continue to evolve, and evolve regularly, requiring cryptographic agility.
Latest Videos FromTechRadar
Advertisement
Why quantum risk is already a digital trust problem
Adversaries are already harvesting and storing encrypted data today on the assumption that a future quantum computer will decrypt it (harvest now, decrypt later). Anything with a long confidentiality tail, from health records to national archives to intellectual property, is already exposed to a machine that does not yet exist.
Quantum-resistant algorithms, like ML-DSA, solve the cryptographic problem, but they introduce much larger keys and signatures. Deployed through today’s public key infrastructure (PKI), they would inflate or possibly break the systems behind secure connections. Legacy systems and high-latency networks would feel it most.
What is a Merkle Tree Certificate (MTC)?
At the time this article is being written, the most significant development in Google’s roadmap may be the easiest to miss. Under Domain 2, Integrity and non-repudiation, a single line reads:
“Google Trust Services, Merkle Tree Certificates, 2028”.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Advertisement
Merkle Tree Certificates (MTCs) are a new kind of website domain certificate designed to keep secure connections fast in the coming era of quantum computers. Today a website proves its identity by presenting a certificate that carries several digital signatures, and the quantum-resistant versions of those signatures are so bulky they would slow down every secure connection on the internet.
MTCs solves this by having the certificate authority (CA) record everything it issues in a public, tamper-evident log, organized as a Merkle tree. Rather than carrying heavy signatures, the website presents a short trail of digital fingerprints showing its certificate sits in that log, and the browser checks the trail against a summary of the log it already received through its normal software updates.
Of note, MTCs do not abandon X.509. They are X.509 certificates, carrying a proof where a signature used to sit, issued alongside conventional directly-signed certificates rather than replacing them.
The result is a certificate that stays small, stands up to quantum computers, and is publicly verifiable by default. For the regular everyday person: we get to keep using the internet fast and uninterrupted with quantum resistance underneath.
MTCs make transparency structural
In today’s web PKI, transparency is bolted onto issuance as a separate step. The CA signs a certificate, submits it to independent CT logs, and collects SCTs, each of which is a log’s signed promise to publish the certificate within a fixed window. A misbehaving or compromised log can vouch for a certificate that never becomes visible to the monitors watching for misissuance.
MTCs change that relationship. The CA certifies by logging, and a certificate is literally a proof that its entry appears in the CA’s public issuance log, verified by the browser on every connection. If it is not in the log, it is not a certificate. Under MTC, transparency does not merely survive the post-quantum transition. It comes out stronger.
Advertisement
Who is developing Merkle Tree Certificates
When the vendor with the dominant browser share proposes a new certificate format and a new root store to hold it, it is reasonable to ask whether the rest of the ecosystem is being consulted or simply informed.
However, MTCs are not Google’s alone. At the time of writing, the IETF draft’s authors span Google, Apple, Cloudflare, and Geomys. Cloudflare has been involved from the outset, CAs including Sectigo have contributed to the underlying research, and Let’s Encrypt publicly committed to MTCs in June 2026. The result will be an open standard any CA can implement, controlled by no single vendor.
The organizations that will shape post-quantum web trust are the ones in the working group now. Root programs, CAs, and large implementers who stay outside it will inherit decisions rather than influence them. That choice is available to everyone, and the window is open today.
Advertisement
How organizations should prepare for MTCs
Google’s 2028 date for MTCs deserves a roadmap’s usual caveats. Google ties it to standardization work still in progress at the IETF, and dates like these move. The direction, however, resembles something that seems settled.
Chrome’s planned Quantum-resistant Root Store will support quantum-resistant certificates only in the MTC format, not as post-quantum signatures bolted into traditional X.509. Compact classical signatures and X.509 served the web extraordinarily well for three decades, but with the dawn of quantum computing, we are due for a redesign.
For everyone else, the practical implication of Google’s roadmap is not that you need MTCs. It is that you need to be capable of adopting them (or whatever else emerges) without a multi-year engineering program. Which is precisely the cryptographic agility Google put at the foundation of its own plan.
Advertisement
In concrete terms, organizations should focus on:
A complete inventory of certificates and cryptographic assets, because you cannot migrate what you cannot see
Automated certificate lifecycle management, because shorter certificate lifetimes will make manual processes untenable well before quantum computers arrive
A written post-quantum roadmap from your CA, which every organization should be asking for
The full scope of what MTCs can do is still coming into focus, and they may not be the only answer the industry ultimately adopts. What is already clear is that organizations that invest in cryptographic agility, certificate lifecycle management, and complete visibility today will be best positioned to adapt as post-quantum standards mature.
The future of digital trust will belong to organizations that can evolve as quickly as the cryptography they depend on.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
Advertisement
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
You must be logged in to post a comment Login