Post-Quantum Cryptography
Shor will eventually break today’s public-key encryption — so we’re swapping in quantum-resistant locks now, before the code-breaking machine even exists.
Right now, somewhere, adversaries may be quietly recording encrypted internet traffic they can’t read — banking, medical records, state secrets — and simply storing it. Why bother with data they can’t open? Because they’re betting that in a decade or two a quantum computer running Shor’s algorithm will crack the encryption and reveal all of it retroactively. This “harvest now, decrypt later” threat makes the quantum crypto problem urgent today, before a single code-breaking quantum computer exists. Hold the question: what exactly breaks, and how do you defend against a computer that doesn’t exist yet?
What Shor breaks (and what it doesn’t)
Public-key cryptography — RSA, Diffie-Hellman, elliptic-curve — secures key exchange and digital signatures across the internet, and it rests on factoring or a close cousin (the discrete logarithm). Shor demolishes both, so this whole family is the real casualty. But symmetric encryption (like AES) and hashing are not broken: the best quantum attack there is Grover’s, which only square-roots the brute-force effort, so simply doubling the key length restores safety. The threat is specific, not total.
Post-quantum cryptography: new locks on ordinary computers
Post-quantum cryptography (PQC) is a set of new encryption algorithms built on math problems believed hard even for quantum computers (for example, certain lattice problems). The key point that surprises people: PQC runs on ordinary classical computers — you don’t need a quantum computer to use it, only to break the old stuff. Standards bodies have already been selecting and standardizing PQC algorithms, and software is steadily migrating to them.
Why migrate now: harvest now, decrypt later
Here’s the urgency. Encrypted data can be copied and stored cheaply today, then decrypted years later once a quantum computer matures. So anything that must stay secret for a long time — health records, government secrets, long-lived keys — is already at risk and needs to move to PQC before the machines arrive. It’s a huge but planned engineering migration: not a reason to panic, but genuinely not optional for long-term secrets.
Changing the locks before the master key is finished. Imagine you learn that a master key is being manufactured that will open your brand of lock — it won’t be ready for years, but a thief is already photographing your locks (recording your encrypted data) to use the moment the key exists. The smart move isn’t to wait until the key is done; it’s to swap in a new kind of lock the master key won’t fit (post-quantum cryptography) now — especially on the doors guarding things that must stay shut for a long time.
The timeline of the “harvest now, decrypt later” threat: 1. Today: you send bank data encrypted with RSA. It’s safe against every classical computer. 2. An adversary records the encrypted blob and stores it — cheap and easy. 3. Years later: a large fault-tolerant quantum computer runs Shor, factors the RSA key, and decrypts the stored blob → your data from years ago is exposed. 4. The defense: had that data been encrypted with PQC instead, Shor wouldn’t help — the stored blob stays unreadable. 5. So the real deadline isn’t “when quantum computers arrive”; it’s “now,” for anything that must remain secret past that arrival date. That’s exactly why governments and companies are migrating today.
This is the reading. The interactive version — active-recall quiz, a hands-on experiment you run in your own AI, and an earned mastery check — is free in the app.
Start this lesson free →