Post-quantum cryptography, without the panic
Nothing you own needs replacing this year. But data stolen today could be unlocked later, and that is the part worth understanding calmly.
Post-quantum cryptography sounds like a problem for the far future, and for the equipment on your desk it mostly is. A large enough quantum computer, capable of breaking the encryption that protects banking, messaging and the padlock in your browser, does not exist today. When people tell you to replace everything now because of quantum, they are selling fear, and usually a product alongside it.
There is one genuine reason not to shrug it off entirely, and it has a name: harvest now, decrypt later. An attacker who cannot read encrypted data today can still copy it and keep it, betting that in some future year the tools to unlock it will exist. For most people and small businesses that bet is not worth an attacker's storage costs. For data that must stay secret for a decade or more - certain legal, medical or state records - it is a real consideration now.
The reassuring part is that the response is already under way, above your head, by the people whose job it is. New encryption standards designed to resist quantum attacks have been agreed, and the big platforms - browsers, phones, messaging apps - have begun building them in. When your devices update, you will inherit this protection without doing anything, in the same quiet way you inherited stronger encryption before.
So the honest to-do list is short and unexciting. Keep your software and devices updated, because that is how the new protection actually reaches you. Do not buy a “quantum-safe” gadget from anyone knocking on your door. And if you genuinely hold data that must remain confidential far into the future, that is the one case where it is worth asking your suppliers what their plan is.
Treat this as weather you can see coming, not a storm at the door. The mechanism is real, the timeline is years not months, and the sensible posture is to stay current and let the standards bodies and platform makers do the heavy lifting they have already started.
- ✓Keep every device and app updated, because that is how quantum-resistant encryption will reach you.
- ✓Ignore anyone selling a “quantum-safe” product to individuals or small firms today.
- ✓If you hold data that must stay secret for ten years or more, ask suppliers about their plans.
- ✓Revisit the topic in a year rather than acting on it in a hurry now.
- Preparing for quantum-safe cryptography NATIONAL CYBER SECURITY CENTRE ↗
- Post-quantum standards and internet protocols IETF ↗
- Harvest now, decrypt later explained THE REGISTER ↗
- The UK approach to quantum and cyber resilience DSIT ↗
Links open each publisher’s live coverage of this topic.