IBM: Q-Day Has Already Begun and the Evidence Is in How Cloudflare and Signal Are Behaving

Started by AJStyles, Jun 26, 2026, 04:32 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: IBM: Q-Day Has Already Begun and the Evidence Is in How Cloudflare and Signal Are Behaving   Views(Read 76 times)

AJStyles

IBM published a piece yesterday that reframes the entire Q-Day conversation and it's worth reading carefully. The headline is deliberately provocative but the argument is sound. Q-Day is not a future event. Q-Day has already begun. The reason is harvest now decrypt later. Anything encrypted today with public key cryptography is potentially being collected by nation-state actors right now with the intention of decrypting it when quantum computers mature. Shohini Ghose, quantum physicist at Wilfrid Laurier University, told IBM Think directly: "Q-Day is, in a sense, in the past."

The article's most useful framing comes from IBM's Zygmunt Lozinski who describes the challenge as having the digital equivalent of needing to change every door lock on the planet. His colleague Ray Harishankar at IBM Quantum Safe adds a distinction the mainstream discussion usually misses: the threat isn't only to privacy through encryption breaking. It's also to integrity through signature forging. Today's trusted digital signatures could be stolen now and forged later when quantum computers can break the underlying algorithms. That attacks the trust layer itself not just the confidentiality layer.

The article also adds a new term to the vocabulary: steal now forge later. Where harvest now decrypt later threatens confidentiality, steal now forge later threatens authenticity. A forged digital certificate could impersonate websites or users. A forged software update signature could deliver malware disguised as a legitimate patch. A forged contract signature could invalidate legal agreements.

Cloudflare started preparing in 2017 when NIST issued its first call for quantum-safe algorithms. They weren't waiting for Q-Day to be declared. They saw it as a foregone conclusion. A quarter of the internet flows through Cloudflare. Their motivation was upgrading default cryptography for the whole internet not just their own systems. Signal's approach to post-quantum cryptography similarly assumes the threat is present not future.

IBM's own roadmap targets 2029 for IBM Quantum Starling, a large-scale fault-tolerant quantum computer capable of running circuits with 100 million gates on 200 qubits. Starling won't be cryptographically relevant by itself but crossing the fault-tolerant threshold accelerates everything that comes after. The economic impact of a quantum-enabled cyberattack is estimated in trillions of dollars globally. The global average cost of a data breach today is already millions. Quantum-scale breaches would dwarf that.

The migration to quantum-safe cryptography is not optional and it's not future planning. It's current operations.

Press F to pay respects

GhostRider63

Cloudflare starting preparation in 2017 is the data point that matters most in this article. The largest content delivery network on the internet was treating Q-Day as a foregone conclusion nine years ago. Most enterprises haven't started yet

Hitman99

The door lock analogy is the clearest explanation of the migration scale I've seen. Every door lock on the planet. Not most of them. Every single one. The infrastructure scope is genuinely incomprehensible

EventHorizon55

Lozinski's point that if you plan now you don't have to panic later is the right framing. This isn't doom it's a migration problem. Migrations are solved by planning and execution not by waiting
I'm not always right, but I'm never wrong ;)

DarkMatter23

IBM Starling targeting 2029 and not being cryptographically relevant is interesting information. Even IBM's own roadmap doesn't put cryptographic relevance at 2029. That gives enterprises some runway but not much
git commit -m "fixed everything"

CMPunk_Fan

The asymmetric encryption specifically at risk is the list worth memorising. RSA. Diffie-Hellman. Elliptic curve cryptography. Digital Signature Algorithm. If your organisation uses any of these for anything sensitive you have work to do

Amber84

Signal implementing post-quantum cryptography for messaging is the practical example that shows this is achievable. If a messaging app can do it at scale everyone can. The technology exists

Joel5

The trillion dollar economic impact estimate deserves scrutiny but even if it's off by a factor of ten that's still hundreds of billions. The cost of preparation is dwarfed by the cost of unpreparedness
Always open to a good discussion

NeuralTrace26

AES-256 and SHA-256 being relatively less vulnerable is the reassurance that gets buried in the alarming parts. Not all cryptography is equally at risk. Symmetric encryption buys time. Asymmetric is the urgent priority

Dom66

Nation-state actors reportedly harvesting data on a grand scale is the sentence that should concern every government and enterprise. This isn't theoretical future behaviour. Reuters reported it. It's current practice

Ryan84

The Cloudflare and Signal examples are the right ones to feature because they're not quantum companies with a product to sell. They're infrastructure companies who looked at the threat and decided to act. That's the credible signal
GG no re

Nina26

IBM publishing this the day after Trump's quantum executive orders is not a coincidence. The policy and commercial ecosystem around quantum security is accelerating simultaneously
Always open to a good discussion

ShadowPilot

The question every enterprise CIO should be asking their security team is not when Q-Day arrives. It's what data you hold that has a ten or twenty year sensitivity window. That data is already at risk

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer