Is the quantum computing threat to encryption is being taken seriously enough?

Started by Nina81, Yesterday at 08:18 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Is the quantum computing threat to encryption is being taken seriously enough?   Views(Read 50 times)
Active members in this topic:
Nina81(1)

Nina81

Sky News ran a segment putting the quantum threat question to the people who actually have to defend against it, rather than the vendors trying to sell a fix for it. The framing is simple and has been circulating in cybersecurity circles for a while now under the name harvest now, decrypt later, the idea that hostile actors are already scooping up encrypted traffic today with no ability to read it, banking on a future quantum computer to crack it open once one exists.

That waiting game matters because some categories of data stay sensitive for decades. Government communications, health records, long term financial data and intellectual property do not lose their value just because nobody can decrypt them yet, so an adversary with patience and cheap storage can simply sit on stolen traffic until the maths catches up. The segment frames this as a live rather than theoretical risk, since the storage cost of hoarding intercepted data has fallen dramatically while the timeline for a cryptographically relevant quantum machine has been steadily pulled forward by researchers across the field.

The uncomfortable part for a lot of organisations is that migrating away from vulnerable encryption is not a software patch, it is closer to a multi year infrastructure project touching everything from VPNs to certificate authorities to embedded devices that were never designed to be updated in the field. NIST has already finalised post quantum cryptography standards, but standards existing on paper and organisations actually deploying them across legacy systems are two very different states of readiness.

What gives the segment its edge is the gap between how seriously governments talk about this and how seriously most private organisations actually act on it. National agencies have been issuing migration guidance for a couple of years now, yet plenty of businesses still treat post quantum migration as a someday problem rather than a now problem, largely because the payoff is invisible until the day it very much is not.

The segment does not pretend there is a single dramatic fix, and that is probably the most honest thing about it. Post quantum migration is inherently a slow, unglamorous, multi year slog through legacy systems, and the risk of leaving it too late is that the harvesting has already happened long before anyone notices the theft.
Making the internet slightly better one post at a time

Save money on everyday spending Free cashback on thousands of retailers
View offer