Kirk Baird joins Amy-Rose Goodey on The House is Digital for a deep dive into cybersecurity, blockchain infrastructure and the emerging risks facing an increasingly digital economy.

As Senior Executive Director at Sigma Prime, Kirk has spent years examining vulnerabilities across blockchain systems and helping secure critical Web3 infrastructure.

The conversation explores how cryptography protects the internet, where vulnerabilities emerge, why humans are increasingly becoming the weakest point in otherwise secure systems, and what major digital asset hacks can teach us about managing risk.

Kirk also explores the rapidly developing quantum computing challenge, post-quantum cryptography, AI-enabled security, scams and the importance of building redundancy into critical digital infrastructure.

A fascinating look beneath the surface of the digital economy at the systems, people and technology responsible for keeping it secure.

speaker-1: The Houses Digital podcast is where Australia’s tech future takes shape. Welcome to the front line of Australia’s digital revolution. Today we’re joined by Kirk Baird, the Senior Executive Director at Sigma Prime, one of Australia’s leading cybersecurity and blockchain infrastructure firms. He has spent more than eight years leading security audits across the Web3 ecosystem, protecting critical systems and contributing to the Ethereum infrastructure. Kirk, welcome to the House is Digital Podcast. It’s a pleasure to have you here. You are coming to us today from Sigma Prime. And you are pretty you’re neck deep in hacks, scams, cybersecurity. How did you get here though? And why would you want to be neck deep in cybersecurity? Tell us what how that happened.

speaker-0: Yes. So how did I actually get here? ⁓ I started off by working as an accountant, ⁓ of all things. ⁓ goodness. ⁓ yeah. Worked as an accountant for a number of years and then I was taking a cybersecurity course, which I found very interesting. And my lecturer also ran a cybersecurity company. And so at the end of the course they were looking for interns and they’re like, Well, would you like to do that? And I of course was quite eager to see what it was like in practice. ⁓ so I moved shipped from accounting over to cybersecurity and ⁓ I’ve been working at Sigma Prime ever since. It’s just a good place to work. ⁓ I think it’s been eight years now of cybersecurity.

speaker-1: Wow, eight years. So you’ve got a pretty good landscape view on Australia, our digital economy, our systems, our platforms. Where do you think we’re the most fragile?

speaker-0: Yeah, it’s it’s a really good question. so cybersecurity, especially in the blockchain space, can kind of be categorized into a few layers. ⁓ the first layer would be like the actual cryptographic primitives themselves. ⁓ this is the maths of hash functions, elliptic curves, ⁓ the actual encryption. ⁓ this is generally done by cryptographers, mathematicians. ⁓ you really need a sort of PhD in math to be able to to work with this stuff. ⁓ and so we have trust that these cryptographic primitives are secure. ⁓ we really hope they are. ⁓ these are the same cryptographic primitives that are used well wide across the internet. The internet wouldn’t work without them. ⁓ there’d be no way to know who you’re talking to. Anyone could send you whatever message they want. ⁓ these are things like ⁓ encrypting your data, digital signatures to prove who you are ⁓ are the main two we use. ⁓ and then hash functions are are used all through all through these as well. So at the cryptographic primitive layer, ⁓ if one of these is broken, ⁓ it would make Y two K look like a blip.

speaker-1: What are the chances of that happening? Let’s say across banking let’s say across ⁓ is there a risk that

speaker-0: There is there is absolutely a risk there. ⁓ but we’ve had a lot of mathematicians spending decades on these problems. ⁓ the discrete logarithm’s been around ⁓ in ⁓ cryptography setting for at least ⁓ fifty years now. ⁓ and no one’s so far found a solution that can do it in ⁓ logarithmic time. ⁓ there have been a few advances which have ⁓ made cracking it faster and so now our signatures have to be bigger than they used to be. ⁓ But there’s there’s been nothing that’s completely ⁓ broken it. So they’re just small breaks, partial breaks.

speaker-1: I we didn’t plan for this question, but I do have a a quantum question for you. There is a rumour, ⁓ not just with blockchain but all cryptography, that in the event that quantum is advanced enough to be able to break some of that cryptographic those hashes.

speaker-0: Correct. So ⁓ the first one to go is elliptic curves. ⁓ quantum computers can break those far faster than it can ⁓ anything else really. it I think the second one to go is the discrete logarithm problem. And I think hashes remain secure afterwards. so elliptic curves right now what we use them for is that’s your private key. So if if you could break elliptic curves you can take anyone’s private key. So that would be critical. Absolutely. This is probably what I’m most concerned.

speaker-1: About that. Yeah, okay.

speaker-0: There are some solutions around it, but they there would be like Y2K level of having to reorganize the entire system. ⁓ and these are the same things that ⁓ are used in TLS certificates. So when you speak to Google, ⁓ they will often use an elliptic curve to prove that they are Google and send you back data from Google. So essentially the whole internet would need to be completely redone if if these things were broken. and blockchain, especially. Done because they rely heavily on this. There are ⁓ quantum resistant ⁓ security algorithms, encryption algorithms, ⁓ specifically hash functions as and lattices. ⁓ both of these two problems are actually quantum resistant, and so they we’d still be able to do the required work, ⁓ providing digital signatures or encrypting your data, whatever needs to be done. But We’re going to have to do them with an alternate. Underlying error.

speaker-1: Okay. So ⁓ one of my favorite sayings is an ounce of prevention is a pound of cure. And it would be wonderful if this was being applied already as a preventative measure to some of the impending ⁓ quantum risks.

speaker-0: Correct. Yes. ⁓ it absolutely is. Luckily the Ethereum Foundation, ⁓ I think Justin Drake might be leaving this initiative, has gotten very deep into the ⁓ post quantum ⁓ world and they’re working out what would we do in Ethereum to make sure that it is post quantum secure by ⁓ I think their plan is twenty thirty or someone, might even be twenty twenty nine. ⁓ so they are planning to phased roll out ⁓ Quantum proof. ⁓ the reason why this has gotten so ⁓ important recently is because of a recent advance in quantum computing algorithms, ⁓ which allowed us to do it in like a thousandth of of what we used to do. And so what we thought was twenty years ago, twenty years away from being broken became about ten. And and these these are estimates, yeah.

speaker-1: Or even sooner. Yeah. Well my I have concerns because ⁓ there for quantum computing to progress, there needs to be solutions to certain problems for that to happen. And solutions to certain problems come about at the moment because of AI and asking questions and doing your own research within the AI platforms. And so people are coming up with all sorts of ideas with quantum. And so when we say twenty twenty nine is the goalpost, I don’t know if it’s factored in artificial intelligence solutions to quantum computing problems.

speaker-0: Yeah, that’s that’s a really good question. I I have no idea if they have factor that in or not. ⁓ but it’s probably realistically is is about as fast as we could move and make the right choices. ⁓ because changing all of these underlying algorithms is such a huge engineering burden, ⁓ you kind of want to get it right so we don’t have to do it again.

speaker-1: Are there other blockchain I think is at risk? Are there for everyday Australians who are watching, ⁓ when it comes to risk, when it comes to encryption, can you paint a picture as to where encryption lies in our everyday lives ⁓ across digital systems? Where do we see it when we interact with the digital world?

speaker-0: Yeah. Yeah. That’s great. ⁓ so the the probably the most important one is the S of HTTPS. ⁓ the S stands for secure. Okay. Because before that ⁓ we didn’t have TLS certificates. And so you were just kind of trusting your ⁓ internet service provider to give you the right stuff ⁓ from the right people. ⁓ and so what this S does is this S gives you ⁓ a digital signature from the other party so they can prove who they are. And then on top of that, it allows you to then encrypt all of your following messages between each other. So we’d use what’s called AES encryption, which just turns your data from a nice readable message into garbage bits. ⁓ you’d have absolutely no idea what those bits mean. and so from there, that’s that’s probably the very first one that we use we use every day, every single message that you’re sending on your phone every text to people. Well not text unless you’re using iMessage. ⁓ every single ⁓ internet request that you make will now almost certainly be done by HTTPS. There are a few other protocols that will also use similar sorts of encryptions as well.

speaker-1: And when you think about risk for everyday Australians, what do you see as the most prominent problem or w where are the scams, where are the hacks, where are the issues unfolding within Australia?

speaker-0: Yeah, great, great. So this kind of ties a bit back into what was happening before. ⁓ there’s a few layers to security, and that was the first one. ⁓ we’ve discussed. We’ve discussed the cryptographic primitives. Below that is the actual implementation of it. ⁓ so that’s the rest of the code. Well, if we’re trying to write a blockchain, it’s not enough to just have an encryption algorithm, right? Like a blockchain or a cryptocurrency. This is where the crypto comes from. Is a whole bunch of other implementation details as well, like how do we choose which is the right block. ⁓ how do you process transactions? How do you make sure everyone’s balances are tracked correctly? All that sort of code is is the next level. And that’s the ⁓ implementation. ⁓ and this is probably where we would come in at Sigma Prime and do most of our work. It’s in the implementation, making sure your code is doing exactly what you wanted your code to do, right? Like if you’re lacking a check to make sure someone has enough ⁓ funds when they transfer money from A to B. ⁓ What will happen if you didn’t have the check to make sure they had balance? Well, then they’re sending money to someone that they don’t have, and that’s kind of an infinite mintic problem. So there’s a lot of checks that we do in the code level there. And that’s what would be the implementation. that applies for every piece of software. ⁓ after you get past the cryptographic primitive levels, then you move into the implementation level. ⁓ and that’s all of your source code. ⁓ next up would be the level below that, which is the humans operating it. And obviously the human level is is without a doubt the hardest to to protect. People people use their private keys wrong, people get scammed, they click on links, they sign the wrong thing, and some attacks are very sophisticated. They there might even be physical attacks as well. Like we’ve seen things like kidnappings and and ransoms and someone’s as well. ⁓ so the the personal one is as I said, very challenging to prevent against because there are an unbounded number of avenues. In in the cryptographic primitives, You just got a a few equations. Like it’s it’s maths. It’s very simple. and and some of these encryption algorithms are are seriously simple. the discrete logarithm problem is is literally ⁓ a number to the exponent. and then you modulus a prime and that’s all there is. There’s like three components to it.

speaker-1: Yeah, that sounds really mathematical. ⁓ the human in the loop. We actually on a on a couple of episodes we’ve talked about the human in the loop, which sounds like the weakness in the loop. ⁓ and so the consequence, I guess, or the emphasis should be on the humans who are operating or on these platforms. Can you give us an example of some of the ⁓

speaker-0: ⁓

speaker-1: Consequences to the weaknesses?

speaker-0: I think the the biggest consequence is the the biggest theft ever in the history of humankind, ⁓ via Bybit. That was at the human level, kind of. Yeah. So basically what they did is they changed what displayed on your computer to what you’re actually signing on your device. And so it looked everything looked correct on the computer, ⁓ and then on the hardware wallet.

speaker-1: Can you take us through how it happened?

speaker-0: ⁓ was something completely different. So when they ⁓ sent the funds that they were trying to transfer, it went to the wrong place and two billion dollars was taken by hackers.

speaker-1: So how do you pretend ⁓ just going back to the HTTPS and seeing a website in front of you that you trust because it has that, ⁓ and then being scammed through that interface? How does that happen?

speaker-0: Yeah. ⁓ so so what actually happened is they hacked the website’s code, ⁓ which was safe, and they so they they didn’t just hack Bybit, they actually hacked ⁓ the website as well that generates ⁓ the code that Biobit then used. It was very sophisticated and there’s a few more levels to it as well, but I’m I’m trying to keep this as abstract as I can. ⁓ the ⁓ yeah, it w it was insanely sophisticated. ⁓ If it wasn’t so bad, I would be very impressed.

speaker-1: Yeah. Well, I I think we we all watched on and I’ve seen a couple of chain analysis walkthroughs as well as to to how that unfolded. When you look at it a a post mortem view of the whole thing, you realise just how vulnerable we are. It could happen to anyone. You did talk a little bit about the other risks as as well, and not to downplay them, but you know, there’s abductions, there’s other scams that happen, there’s romance scams, there’s exits into you know, ⁓ send us this amount of cryptocurrency ⁓ and in exchange for this or I’ll send everyone photos or something that I found. You know, there’s all sorts of scams and and risks out there. Do you have any solutions? Or is there anything that’s actually working ⁓ to help the humans in the loop?

speaker-0: Yeah. is is it working? Well, the number one hacks right now are the human in the loop hacks. in it was about last year I think it it swapped. Is before that, most of the hacks were in the implementation, in the code themselves. but as an industry where we’ve matured, our security’s gotten a lot better. We have ⁓ a lot better development practices, and now the number of actual like implementation hacks are going down have been well surpassed by the human in the loop. how do we stop it? Well, it it’s not like a one solution, right? Because there’s such a a huge number of attacks, right? You got your personal security, you got your laptop security, ⁓ making sure no one’s plugging things in or putting anything on your laptop, and then you have the protocol. ⁓ is probably being run on servers somewhere. So you got their infrastructure, the cloud infrastructure. What happens if someone gets physical access to your servers? So you’re using AWS cloud. What happens if there’s a malicious employee in there who just goes and plugs something into yours? there’s just too many different attack vectors to have a a clean solution. But we yes, we we do what we can. There’s a nice book that was made by the folks at SEAL. seal being the security lines. ⁓ they made a book, ⁓ OPSEC for traveling, which tried to cover as much of this as you could in in one small little booklet that was about the size of your hand and and you could travel with. ⁓ it’s very interesting read. If you can get your hands on that, I would strongly recommend. ⁓ but it’s it’s really a solution to each of the different attack vectors. And when there’s an unbounded number of attack vectors, you need an unbounded number of solutions. ⁓ but a lot of these solutions are to just not trust the data you’re being given. Whatever it is. If if someone is ⁓ if you got a transaction on your screen, make sure you can double check it on your hardware device as well. So you’re checking in two places, that just makes the attack harder. Now the attacker has to hit both your screen and the hardware device. ⁓ so the the best thing you can really do is apply your common sense and check as much as you can, verify everything.

speaker-1: So there’s scammers and hackers, they always seem one step ahead. They’re very innovative. And I feel like historically, that’s how good tech is built. First the scammers build a way to scam and then we come out and we provide a solution and and learn from it. post operatively it’s it’s actually it could be done better. We’re quite reactive as as a species. Is there anyone that’s doing it? well, providing solutions, well, because ⁓ ten years ago ⁓ we were getting letters in the mail from African princes or you know, na now it’s quite sophisticated. We’ve moved on. Is there anyone who is providing solutions or are there technical solutions that are being built right now to safeguard us mere mortals?

speaker-0: Yeah, there’s there’s lots of solutions, but again, each each of this solution is specific to a problem. But I’ll ⁓ run through one of my favorite solution right now, which is the ⁓ the talking grandma. So when you get a phone call and it’s it’s from a scammer, ⁓ they’ve deliberately set up some numbers that just have an old grandma who is talking to them. It’s an AI, ⁓ and just wasting as much as the scam’s time. As they possibly can. So the the longer they spend on the call with the grandma, the less time that they’re spending talking to a real person and trying to scan.

speaker-1: And you know, I I remember seeing that and wondering if because I’ve seen two AIs talk to each other. And I’m in a lot of the scam calls are AI as well. And so essentially it’ll just be s AIs talking to AIs, trying to scam each other. ⁓ my goodness.

speaker-0: Then that then degenerates what a lot of security degenerates into is a cost of attack versus ⁓ the benefit of the attack. So this is a ratio that is often used, ⁓ and you can do it financially in terms of dollars. ⁓ we can often ⁓ estimate that an attack’s going to cost you about one million dollars ⁓ worth of of compute time and all your other resources. And then we can say if the attacker succeeds and spends the million dollars to do the attack, ⁓ how much would they gain? And as long as you can make that cost higher than the amount, then the attacker’s not gonna do it, right? Because if it costs them a million dollars and they only get ten grand they’re losing money.

speaker-1: So you make it more expensive to scam. Correct. That’s very interesting. So ⁓ so the friction points. ⁓ the innovation could be in the potholes, the frictions and their time, I guess. There’s a few ⁓ countries that I’m not quite sure which ones they are, but they have slave scammers and hubs of scammers and do you I don’t know if you know much about that and can speak about that, but they seem to be growing in number. ⁓ and that is impact the the humans being able to pick up that they’re talking to an AI, ⁓ or the AI grandma. ⁓ they seem to be using humans to combat the AI in some circumstances. Do you know much about these slave a ⁓ the slave

speaker-0: Yes. unfortunately. Yeah. So essentially what’s happened is kidnapping has taken place and then these people get transported to these compounds where they’re first forced to work day in, day out as scammers. ⁓ and if if they don’t work as scammers, they either get abused physically or they don’t get fed. ⁓ and so there is some empathy towards these people, of course. They’re they’re in a horrible situation ⁓ and they’re they’re forced to scam. ⁓ yeah. And so these sort of I’m not sure what the correct word is for conglomerates, as as you will, ⁓ these compounds will be run ⁓ in such a way that is very cost effective for them, ⁓ right? Because slavery is essentially free labour. ⁓ so they have a lot of labor on their side that is ⁓ very cheap and which can make combating that quite challenging because we probably need to spend more on the security side. ⁓ we have to have a lot more AI, so we maybe even have to have actual people working on these phone calls to talk to scammers and waste their time in instead of ⁓ doing that. So it’s yeah, it it’s a dynamic that has made the cost of the attack cheaper, which makes securing it ⁓ more expensive for us and harder to do.

speaker-1: And so, ⁓ let’s go back into you all essentially looking and working through code and making sure that there’s no vulnerabilities in there and there’s do I say attack vectors? Yeah. And no attack vectors. ⁓ to use some of the language I’ve heard. Is that constantly evolving as well? So that when you’re looking through code, you’re looking at vulnerabilities that you didn’t realise were there a couple of months ago because now they’re there.

speaker-0: Yeah. Absolutely. And and I think that’s a bit of what I was talking about as the industry ⁓ becomes more secure. So what one of the first bigger, big hacks that happened on Ethereum was a bug called reentrancy. ⁓ it was the Dow hack and ⁓ they stole a lot of millions of dollars. back at the time, no one knew what re-entrancy was. There was this class of bugs that so many contracts were vulnerable to, but no one had thought about it. ⁓ and when that first attacker found this bug and exploited it, all of the security engineers learned from it and we started looking for this. And that process has continued to happen again and again. New classes of bugs are found, we adapt them to our repertoire and then we look for those classes of bugs. So because the industry is 10 plus years now, ⁓ In the blockchain space specifically, we’ve got all of the regular programming bugs as well in our repertoire, but blockchain specific bugs. Every time we’re finding new classes of bugs, we’re adding them to our repertoire. And so the number of sort of unfound classes of bugs are smaller and they’re harder to find. So if you’re a an excellent security engineer and you found a new class of bug, ⁓ it would actually be worth a lot of money. ⁓ but it would also be ⁓ very important for you to share that with as many security researchers as you can. And we’re quite lucky that what AI is good for is pattern recognition. So all of these classes of bugs, ⁓ we have data on them. We’ve we’ve found the bug before and we can give that to AI and go like look for this specifically. So from that point of view, what we what we’re kind of doing and using AI now is to find the already found classes of bugs, so we spend more of our time looking for these new niche types of bugs.

speaker-1: Do you have bounty hunters sort of thing that go in there? Is there a rew reward for that?

speaker-0: Yeah, absolutely. ⁓ so if you do find ⁓ a new class of bug and it’s ⁓ there are protocols out there that are vulnerable to it, you can report it via their bug bounty. ⁓ some of these bug bounties pay you five hundred thousand dollars to a million dollars for critical vulnerabilities. ⁓ and if this class of bug was and if this this bug was on a lot of different protocols, you can claim one from each. So yes.

speaker-1: Like I might be in the wrong profession. Do you do that sometimes for for fun?

speaker-0: Yeah, I I’ve spent a lot of my free time doing bounty service. Okay. It’s quite interesting. Yeah, yeah. There’ve been rewards as well. Well done. No criticals, none of these five hundred thousand dollar ones unfortunately.

speaker-1: And you’ve got rewards. But that’ll come in in due course. Okay, so let’s look into the future. you we live in a world that is ⁓ almost free of bugs. We’ve got great. Do you want that or will you be without a job?

speaker-0: I I can’t say almost free of bugs, but less what does bugs are getting harder to find.

speaker-1: What do we need to get to that point? To be free of bugs. No pressure.

speaker-0: How do I stop bugs from existing? ⁓

speaker-1: So make how how is what is a secure digital economy? What does that look like? How do you achieve that? What are there any recommendations that you can make?

speaker-0: Yeah, absolutely. Absolutely. So, what we like to do is have redundancies and backups. So, for example, a multi sig’s a perfect example of the human in the loop, right? If you’ve got five people, ⁓ the multisig requires three out of the five people to sign something for it to actually go ahead. Therefore, you need to break three humans, right? Like you need to attack three humans to solve this problem. ⁓ so that sort of technique can be used in the software itself. ⁓ like Ethereum has a lot of different implementations being written in different code and a bug only really works if it’s in all of the implementations at the same time. Right? ⁓ if there’s a bug in one implementation, the other three will disagree and your own little chain ⁓ would go go on fork. When that’s that’s how we have ⁓ yeah. just one client going off in a different direction and then their team will be alerted and they’ll find the bug and fix it. Yeah. So basically when you design your principles, you really need redundancies and backups to ⁓ make it decentralized. Yeah.

speaker-1: We do love decentralization in our industry. So is there w when we talk chain, ⁓ distributed technology, we love it. It’s it’s the future. Do you think that it is and this is a left field question, but w in my view I’m a bit biased and I think that it will make the world more secure if we would just implement it across a lot of our traditional infrastructure? Do you think that that is possible when we talk about a revamp of the way in which security is implemented across our whole internet, for example? If we’re gonna redo a system, do you think it’s possible that they’ll roll out blockchain? As part of that infrastructure?

speaker-0: Good question. ⁓ hopefully. ⁓ yeah, I I really think that we can make things more secure in the blockchain setting because it is by its nature, ⁓ we can make it redundant and we can put in back backups and all of this. So I think from your first point, yes, it will make the internet of money. ⁓ all of the money transfers over the internet more secure and better for everyone. So yes, I think security wise, this is a good thing. ⁓ Will they do it during the rollout? Probably not. It’s it’s it’s a good time, and it would be a good time to do it.

speaker-1: Because otherwise you’re just going and doing it twice.

speaker-0: Correct. Correct. But they’re also they’re building a lot of these everyone who’s working in the banking world who’s getting into blockchain. They’re they’re building up their solutions now. ⁓ a lot of those solutions, ⁓ like Tempo, for example, are are only just starting to come to the mainnet. So so Tempo is having a mental blank on on who they

speaker-1: When you say they

speaker-0: Who they work with arts. Do you remember? ⁓ it’s one of the main payment channels. and yeah, so it’s it’s essentially getting to the point where it can be used now. Are they building up with post quantum ⁓ in mind? Not at this stage, and I imagine a lot of the others aren’t at this stage because they’re using a lot of the technology ⁓ that already exists. So, for example, Tempo uses a lot of the EVM Ethereum’s technology. ⁓ and they’re changing up the ⁓ consensus algorithms and they’re using their own consensus algorithms, and so right now they’re still using the Free quantum cryptography. Yeah. I I think in the future that when post quantum cryptography becomes cheaper and easier to do, everyone will be motivated to use it. But right now, ⁓ as I said, in in post quantum the size of your digital signature are larger. And on top of that, it’s more work for your computer to do. Yeah. So right now the cost is is there if we want to move to post quantum, we have to pay and we’re paying in terms of how much how many transactions per second our our blockchains can actually process. So it’s a it’s a weird balance between motivated right now to make it as fast as we can or security in the future.

speaker-1: Yeah. It’s a bit of a shame that securing the future ⁓ comes at a cost. And if I was to if we were to go into the future and ⁓ and look back and just say the reason why they were restricted in twenty twenty six was because of money or energy consumption or you know, some of the things that really could be avoided. I don’t know, it just sounds like the next generation is gonna look at us and go, What were they thinking? Why didn’t they just do it and spend the money? We’d be so much better off.

speaker-0: Absolutely. I really hope that we do not bite ourselves like this, but if quantum computers come quicker than we anticipate, we will be in exactly that situation. Yeah. The good news is that if quantum computers do get there right now, there’s only a sort of handful of research labs ⁓ and people who would have the ability to run these algorithms. So it’s it’s not like this is an attack that’s going to be available to everyone.

speaker-1: No, but ⁓ and this conversation got a bit sidetracked, but there’s a quantum race, a global quantum race, and there’s some secret squirrels, there’s some stealth builders happening globally because if you lead like if you lead in AI or if you lead in quantum, then you essentially have power.

speaker-0: But

speaker-1: ⁓ to do some of the things that no one else can do. And so that race is what I’m worried about because ⁓ you don’t really want to tell everyone what you’re doing. Do you have to? And and so do we really know how far along we are.

speaker-0: Yes. ⁓ no, we don’t know how far along we are. so there’s there’s a lot of dark horses in there. But we could probably interpolate from the best of the known. like if they need to improve another hundred thousand X on what they are right now to be able to break elliptic curves, but like even if someone’s developing in the dark, are they gonna have that sort of like a hundred thousand levels above our current best? Probably not. ⁓ but are they maybe one or two levels? So if we’re only a couple of levels short, then then yeah, we we should probably be a bit nervous if they’re we’re getting close to the range. Yeah.

speaker-1: And I sometimes because to see how fast AI when you just look at Chat GPT, is that Chat GPT three, three point five and then three you know, and four, it seems like it’s exponential when they really get when they get a hang of it and when they crack this one code and then ⁓ the horse has has bolted. So I do worry about that. Anyway, we’ve we’ve got we’ve got some tra I’m so sorry. No

speaker-0: It’s interesting conversation.

speaker-1: So I I guess if you to c to close off, if we do look to the future, what do you yourself in the future, what would you say to our time right now, what we actually got right?

speaker-0: I think that we are starting the post quantum rollout now. ⁓ and the people are generally looking into it and spending a lot of resources. So I think they are making the correct moves for for right now and spending a lot of money and resources and human thought and power. ⁓ onto trying to solve this problem in the best way we can solve this problem. So when we’re not just hoping, ten years. Well we’ll deal with it in ten years when they actually exist. No, we are starting to plan now. people are spending their times developing post quantum cryptography, ⁓ which is fascinating. Really good. and and so yeah, I I think that’s what I’d be most happy about. Like I’m glad that we’re getting the ball rolling right now as we’re doing.

speaker-1: Yeah, I’m quite excited about that too. Just knowing that someone’s thinking about it and it’s on the Australian agenda. Well it’s good to have you, Kirk. Thanks for joining us on The Houses Digital.

speaker-0: My pleasure. Thanks, Dan.

speaker-1: Digital, where policy meets innovation. Stay curious, stay inspired, and be part of the movement Building Australia’s next economy. The future is happening now. See you in the next episode.