q-day quantum-computing post-quantum encryption harvest-now-decrypt-later

Why Quantum Is Suddenly Everywhere (And What Q-Day Means for Your Data)

Filip Balik · · 4 min read

Quantum is everywhere now. It's in the headlines, in government budgets, in every major tech company's roadmap. A few years ago it was a physics topic. Today it's an industry. And when something moves that fast, it's fair to wonder how much of what you're hearing actually affects you.

Here's the part that does.

The math isn't the debate. The date is.

Almost everything encrypted on the internet, your banking sessions, your messages, your email, relies on math problems normal computers can't crack in any useful amount of time. A large enough quantum computer running Shor's algorithm cracks them. That's been understood since 1994. There's no debate about whether it works. The only open question is when the hardware gets there.

The people building that hardware have answered. The Global Risk Institute surveys the leading quantum researchers every year, and their 2024 Quantum Threat Timeline puts the chance of a machine that breaks RSA-2048 at 17 to 34 percent by 2034, climbing to 79 percent by 2044. Nearly a third of the experts surveyed put the odds at 50 percent or better within the next decade. And this worry isn't new. Michele Mosca, co-founder of the Institute for Quantum Computing, estimated back in 2015 that there was a 1-in-2 chance of it happening by 2031.

Governments read the same numbers and started moving. NIST deprecates RSA-2048 in 2030 and disallows it after 2035. The White House gave federal agencies until 2035 to migrate. The EU wants critical infrastructure moved by 2030. Governments don't set compliance deadlines for theoretical problems. That, more than any headline, is why quantum is suddenly everywhere.

Harvest now, decrypt later

Here's what makes Q-Day different from every other security threat, and why "I'll deal with it when it happens" is the one answer that guarantees you lose.

Encrypted traffic can be recorded today and stored for almost nothing. Whoever is collecting doesn't need to break your encryption right now. They just need to keep a copy. When the hardware arrives, whenever that is, everything in the archive gets opened at once. Years of it. The tactic is called harvest now, decrypt later, and it means the clock isn't counting down to when your data becomes vulnerable. It's counting down to when data captured years earlier becomes readable.

Sit with that for a second. The email you send this week could be sitting in someone's archive on Q-Day. It doesn't matter that the encryption holds today. It only matters whether it still holds the day the archive gets opened.

Reacting is not an option here

With most security problems, reacting works. A vulnerability gets disclosed, you patch, life goes on. That model completely breaks against harvest now, decrypt later. There's no patch for traffic that was recorded three years ago. Once Q-Day is a headline, everything captured before it is already lost, and no amount of scrambling gets it back.

That's why every serious response to this has been proactive. It's why the government deadlines sit years ahead of the expected hardware. Migrating the world's cryptography takes a decade or more, and the people setting those dates know you can't start when the problem becomes visible. You have to start years before it does.

The replacement algorithms already exist. NIST finalized the post-quantum standards in August 2024, and the migration is underway. Over the past couple of years, some of the biggest messaging and email services have started adding post-quantum protection. That's genuinely good news. But look at the shape of it: post-quantum is arriving as a feature. An option here, an upgrade there, one product at a time.

We built Secria the other way around. Post-quantum isn't a setting, it's the foundation everything sits on. Every email is wrapped in ML-KEM, the NIST standard, layered on top of classical encryption. The VPN tunnels the same way. There's nothing to switch on, because it was never off. Not because we think Q-Day is next year. Because mail sent through us today has to stay unreadable no matter what year it comes.

If you want to judge the timeline for yourself, that's why we built the Q-Day Clock, a live countdown built only from published forecasts and government deadlines, with every source public and linked. When the research moves, the clock moves.

Quantum being everywhere is not the story. What it opens is. Move before it matters.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.