Do quantum computers already break current encryption today?

Started by Rob98, Aug 16, 2026, 11:10 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Do quantum computers already break current encryption today?   Views(Read 127 times)

Rob98

Do quantum computers already break current encryption today.png

Do quantum computers already break current encryption today?

The honest and direct answer right now is no. No existing quantum computer is currently capable of breaking the encryption that actually protects things like your online banking, your messaging apps, or your VPN traffic today. If someone tells you a quantum computer has already cracked RSA or AES in any practical, real world sense, they are either mistaken or exaggerating. That capability does not exist yet.

To understand why, it helps to know what breaking encryption like RSA actually requires. RSA security depends on the difficulty of factoring extremely large numbers. A classical computer would take an impractically long time to factor a 2048 bit RSA key, effectively longer than the age of the universe with current methods. Shor's algorithm, developed in 1994, showed that a sufficiently powerful quantum computer could factor those same numbers in a reasonable amount of time. The catch is the phrase "sufficiently powerful." Running Shor's algorithm against a real world RSA key requires a fault tolerant quantum computer with a very large number of stable, error corrected logical qubits, likely in the range of thousands of them working reliably together. Current machines remain well below that threshold.

Why qubit counts can be misleading

Quantum computing companies regularly announce impressive sounding qubit counts, sometimes in the hundreds or even over a thousand physical qubits. This can create the impression that powerful, code breaking machines are just around the corner. But physical qubits and logical qubits are not the same thing, and the distinction matters enormously.

Physical qubits are inherently noisy and error prone. They lose their quantum state easily due to heat, electromagnetic interference, and other environmental factors, a problem called decoherence. To get around this, quantum computers use error correction schemes that combine many physical qubits together to form a single logical qubit, which is stable and reliable enough to actually be used in a meaningful computation.

Depending on the error correction method and the quality of the physical qubits involved, it can take anywhere from dozens to over a thousand physical qubits just to create one dependable logical qubit. So a machine with 1,000 physical qubits might only yield a handful of usable logical qubits after error correction overhead is accounted for, which is nowhere near enough to run Shor's algorithm against a real encryption key. This overhead is exactly why headline qubit numbers can sound impressive while the actual machine remains genuinely far from posing any real cryptographic threat.

The real risk right now: harvest now, decrypt later

None of this means the topic is irrelevant today. There is a real and actively discussed risk called "harvest now, decrypt later." The idea is straightforward. An adversary, whether a government intelligence agency or another well resourced actor, can intercept and store encrypted data traffic today, with no ability to read it right now, but with the specific intention of decrypting it retroactively once a sufficiently capable quantum computer eventually exists.
This matters most for data that needs to remain confidential for a long time. Think of things like classified government communications, long term trade secrets, medical records, or infrastructure design documents. If that kind of data is encrypted today using algorithms vulnerable to quantum attacks, and someone is already storing a copy of it, then it could genuinely become readable a decade or more from now even though it is completely safe today.

Why migration is already underway

This exact risk is why governments and major companies are not waiting around for quantum computers to actually arrive before addressing the problem. Efforts to migrate toward post quantum cryptography, meaning encryption algorithms specifically designed to resist attacks from quantum computers, are already well underway.

NIST, the U.S. National Institute of Standards and Technology, has already finalized a set of standardized post quantum cryptographic algorithms after years of public evaluation and testing. Major technology companies and government agencies have set internal migration deadlines years in advance, some targeting full transitions before the early 2030s, specifically because they recognize that data encrypted today could still need protection well into the future.

The short version

Your data is safe from actual quantum decryption today. No quantum computer that exists right now can break the encryption protecting your accounts or communications. But the migration effort happening right now across governments and industry is not about a hypothetical future threat. It is a direct response to the fact that sensitive data encrypted today may still need to remain secure a decade or two from now, by which point a capable quantum computer could plausibly exist.
Measure twice, post once

Always_Myles26

Quick summary, no capable quantum computer exists yet that can break real world encryption today. But harvest now decrypt later is a real present tense risk for data that needs long term confidentiality specifically
GG no re

Ann

The physical versus logical qubit distinction is actually the single most important technical detail missing from almost every alarmist headline on this exact topic.

A thousand noisy physical qubits is really nowhere near a thousand reliable logical qubits once you account for the real error correction overhead involved
RTFM and then ask

Amber Drifter

Hard to say if exact question gets asked constantly precisely because quantum computing headlines are so clearly confusing and inconsistent for a general audience to actually parse correctly on their own without more background.

Still true either way
RTFM and then ask

NeuralTrace26

Curious about seeing dedicated thread specifically on what BIP-360 and other post quantum crypto proposals actually look like technically. Feels like the quite useful practical follow up to this whole broader conversation happening across the forum lately

CMPunk96

Reads like qubit count arms race in tech marketing actually does not help public understanding here at all. A headline number sounds impressive but really tells you almost nothing about actual real world decryption capability without proper full context

Annie71

Leans toward being true that this risk quite matters way more for governments and specific industries handling long term sensitive information than it does for most regular individual consumers.

Your average online banking session is a much lower priority target for this specific kind of long game attack

Darkseid

In short, current machines cannot do this yet.

The real active risk today is specifically about data recorded now for future decryption once a capable machine eventually exists, not any live active threat happening right now
Posted from my main qubit

AgentSmith95

Going by what I've seen, the migration timeline being years ahead of the actual threat existing is exactly the responsible way to handle a real emerging risk like this. Being early carries way less real cost than the alternative of being caught unprepared later

Related Topics (2)