Steal Now Forge Later: The Quantum Threat Nobody Is Explaining Properly

Started by QuantumFoam, Jun 26, 2026, 05:38 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Steal Now Forge Later: The Quantum Threat Nobody Is Explaining Properly   Views(Read 84 times)

QuantumFoam

The mainstream quantum security conversation focuses almost entirely on harvest now decrypt later. Collect encrypted data today. Decrypt it when quantum computers arrive. That threat is real and well-documented. But IBM's Ray Harishankar at IBM Quantum Safe introduced a term this week that deserves more attention: steal now forge later.

The distinction matters. Harvest now decrypt later attacks confidentiality. You can't read the message but the attacker stores it until they can. Steal now forge later attacks integrity and authenticity. Digital signatures certificates and identity proofs could be stolen today and then forged when quantum computers can break the underlying algorithms. That means digital contracts could be tampered with. Software updates could be maliciously replaced with versions carrying forged valid signatures. Websites could be impersonated with forged certificates. Users could be fraudulently authenticated.

The difference is that harvest now decrypt later produces information you shouldn't have. Steal now forge later produces actions that shouldn't be valid. One is about knowing. The other is about doing. Both are dangerous but the second is more immediately operational in its consequences. An attacker who can forge a software update signature can deliver malware to millions of machines through a trusted channel. An attacker who can forge a financial institution's certificate can redirect transactions. The trust layer that the entire digital economy depends on becomes weaponisable.

Making the internet slightly better one post at a time

QuantumDay

I'm not always right, but I'm never wrong ;)

CosmicRay17

Financial certificate forgery enabling transaction redirection is the scenario that keeps banking security teams awake. The scale of potential theft through certificate impersonation is incomprehensible

VoidSentinel74

The trust layer being weaponisable is the phrase that captures the full scope. We've built the entire digital economy on cryptographic trust. That trust has an expiry date

Midnight Georgia

Harishankar calling it nonrepudiation is the technical term. A signed document can no longer be proved to come from the claimed signer. Legal frameworks built on digital signatures become uncertain

TommyB_20

The blockchain angle is interesting. Cryptocurrency transactions depend on digital signatures. Quantum computers that can forge those signatures could drain wallets or falsify transaction histories

Lynx55

Signal implementing post-quantum cryptography defends against harvest now decrypt later. Defending against steal now forge later requires certificate infrastructure to upgrade too. Different problem same urgency

BiscuitTin46

The reassuring part is that the solutions exist. NIST published quantum-safe standards. The question is implementation speed versus quantum capability development speed

Related Topics (1)

Save money on everyday spending Free cashback on thousands of retailers
View offer