Is the Q-Day timescale creeping closer than we thought?

Started by NovaPrime68, Jul 10, 2026, 06:37 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Is the Q-Day timescale creeping closer than we thought?   Views(Read 63 times)

NovaPrime68

I have been keeping a private spreadsheet of Q-Day predictions for about four years now, pulling the date estimates out of every serious paper, roadmap and expert interview I can find. The thing that jumps out is not any single number, it is the direction of drift. Four years ago the median guess for a machine that could break RSA 2048 sat comfortably past 2035, and today that same median has crept back toward the early 2030s. When a whole field quietly revises in one direction, that is usually worth paying attention to

The reason I think the drift is real and not just hype is that the progress is happening in the right layer. For a long time the headlines were all about physical qubit counts, which is close to meaningless on its own, because a thousand noisy qubits can be further from useful than a hundred clean ones. What actually moves Q-Day is the ratio of physical qubits to logical qubits, and that ratio has been falling as error correction improves. When the overhead per logical qubit drops, the entire timeline compresses in a way that a simple qubit count chart will never capture

There is also the algorithmic side, which people forget because it is less visible than shiny hardware. The resource estimates for factoring have themselves been falling, as researchers find cleverer ways to arrange the computation and shave the requirements. So you have two curves bending toward each other at once, better hardware from one direction and cheaper algorithms from the other, and the crossing point is what we call Q-Day. Two independent trends pulling the same way is exactly the pattern that makes me nervous about complacency

I want to be clear that I am not writing this from a place of doom, because there is a positive flip side that never gets airtime. The same machine that can break encryption is the machine that can simulate a nitrogenase enzyme, model a battery electrolyte or design a catalyst that classical computers simply cannot reach. An earlier Q-Day is also an earlier arrival of the useful science, and I think we lose something important when the conversation is only ever about the threat. If the scary capability shows up sooner, the wonderful capability shows up right alongside it

Where this stops being abstract is the harvest now decrypt later problem, which quietly makes the exact date less important than it sounds. Adversaries can record encrypted traffic today and simply wait for a machine that can crack it, so for any secret with a long shelf life the clock is already running. That reframes the whole question, because you are no longer asking when the machine arrives, you are asking how long your data needs to stay secret. If the answer is ten or twenty years, then in a very real sense your personal Q-Day was yesterday

So here is what I actually want to throw open to the forum, because I genuinely do not know. Do you think the early 2030s estimate is defensible, or am I reading too much into a noisy trend of shifting opinions? And separately, does the exact date even matter for how any of us should be acting right now, or is harvest now decrypt later the only timeline that counts?

Trinity49

I appreciate the spreadsheet approach because it forces discipline on a topic that usually runs on vibes, but I land more conservative than you do. The overhead for factoring a full 2048 bit key is still enormous under realistic error rates, and the gap between a lab demonstration and that scale is measured in orders of magnitude, not a few years of tinkering. When I see early 2030s I mostly see optimism about extrapolating recent slopes forward as if they never flatten

That said, I have to be honest about the weak point in my own position. The resource estimates really have fallen faster than I expected, and if the algorithmic side keeps finding those savings then my conservatism ages very badly very quickly. So I hold the late 2030s or 2040s view firmly on the hardware, but only loosely on the maths, and I am watching the algorithm papers more nervously than the qubit announcements

CosmicRay91

The part of your post that actually matters is buried near the end, and it is the harvest now decrypt later point. Everyone loves to argue about the date because it feels like a sport, but for anyone protecting data with a long secrecy lifetime the date is close to irrelevant. If a foreign intelligence service is recording your encrypted traffic today, the only question that matters is whether your secret outlives the machine, and for state secrets or medical records that is basically guaranteed

This is why I get frustrated with leaders who treat post quantum migration as a problem for the 2030s. The exposure is happening in the present tense, right now, with data leaving the building every day. Waiting for Q-Day to start migrating is like waiting for the burglary before you install the locks, and it will look negligent in hindsight

BrayWyatt_WCW

My problem with the whole debate is that nobody defines the finish line, so we end up arguing past each other. Breaking a carefully chosen small number in a controlled lab is a completely different event from breaking live traffic at scale in the wild, and yet both get reported under the same scary Q-Day headline. Until we agree on what actually counts as the threshold, a prediction of early 2030s and a prediction of 2045 might not even be describing the same event

I would love it if this community settled on a shared, concrete milestone that we could all track against. Something like a specific key length factored end to end on hardware that is not hand tuned for that one number would give us a real yardstick. Without that we are all just shouting years at each other and calling it analysis, which helps nobody plan anything

Aisha

Can someone who actually understands the error correction side answer a question that keeps nagging at me? I keep seeing these curves where the physical to logical overhead falls year on year, and the optimists extrapolate them straight down toward something manageable. What I cannot tell is whether those gains are a handful of clever one off tricks that will run out, or a genuine sustained trend with more headroom underneath it

The reason it matters so much is that the whole early 2030s case rests on that curve continuing. If the recent improvements are structural then your timeline is defensible, but if we have already picked the low hanging fruit then the overhead flattens and Q-Day slides out a decade. I have never seen anyone address this honestly rather than just drawing a confident line on a log plot

NeonSpectre

Thank you for including the positive framing, because I am so tired of this topic being pure dread all the time. People fixate on broken encryption and completely forget that the same fault tolerant machine is what finally lets us simulate serious quantum chemistry properly. An earlier Q-Day means an earlier shot at understanding nitrogen fixation, which could reshape how the entire planet makes fertiliser and feeds itself

I actually think the fixation on the threat is doing real damage to public understanding of why any of this is being built. If all anyone hears is that quantum will break their bank account, we lose the far bigger story about medicine, materials and energy. The security problem is real and solvable, whereas the scientific upside is genuinely transformative, and the balance of coverage is completely backwards
Hala Madrid.

VoidRanger40

You are being far too generous about how ready the world is even once the machine exists, and I say this as someone who has lived through crypto migrations. Standards being finalised does not mean deployment happens, because your bank, your government and every embedded IoT vendor in your supply chain all move at glacial speed. The gap between a working algorithm and rotated keys across a real estate of legacy systems can easily be a decade on its own

So even if you are right about the early 2030s for the hardware, I would add years on top before it translates into actual exposure changing hands. The bottleneck was never really the quantum physics, it was always going to be the boring organisational reality of migration. That lag is under discussed precisely because it is unglamorous, but it is where most of the real timeline actually lives

Ben

My slightly heretical view is that we are all going to be embarrassed by the actual bottleneck when it finally shows up. Everyone in this thread is arguing about qubits and algorithms, and I suspect the thing that really gates Q-Day turns out to be something profoundly unsexy like cryogenic wiring, fridge supply or the availability of specialist control electronics. The physics might be ready years before the plumbing catches up

We have seen this pattern in other hard technologies, where the headline component gets solved and then some mundane supply chain constraint quietly sets the real pace. If there are only a handful of firms on the planet who can build the dilution refrigerators, then their production line is the true timeline, not the latest fidelity record. I would put decent money on the eventual delay being industrial rather than scientific

StarLord67

I think the honest answer to your final question is that both timelines matter, but they matter to different people, and conflating them is why these threads go in circles. For a cryptographer or a policymaker the machine arrival date genuinely matters, because it sets when active attacks against current traffic become feasible. For a data custodian sitting on long lived secrets, harvest now decrypt later means the practical deadline was already in the past and the arrival date is almost academic

So rather than pick one timeline as the real one, I would map your own answer onto your own threat model. Work out how long your data must stay secret, compare it to even the most conservative Q-Day estimate, and if those windows overlap then you migrate now regardless of who is right about the date. The date debate is fun, but your secrecy lifetime is the number that should actually drive your behaviour
I read every reply. Even the bad ones.

Related Topics (4)