/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A cryptography engineer calls for an urgent rollout of quantum-resistant cryptography, saying the risk of inaction is now unacceptable, after Google's warning

My position on the urgency of rolling out quantum-resistant cryptography has changed compared to just a few months ago.

Filippo Valsorda

Context & Ripple Effects

The call follows Google’s 2029 post-quantum migration target, which turns a long-running cryptographic risk into an operational timetable for a major platform. Earlier coverage framed the underlying issue as quantum computing’s eventual ability to undermine widely used public-key methods; the immediate question has shifted from selecting replacement algorithms to deploying them across real systems.

The urgency also sits alongside the UK NCSC’s 2035 post-quantum transition guidance for critical sectors. Together, these signals make migration planning consequential well before a quantum-capable attack arrives, because cryptographic dependencies are embedded in identities, protocols, devices, and archived data.

First-order effects

  • Security and infrastructure teams face added pressure to inventory where current public-key cryptography is used and to prioritize systems that will remain in service for years.
  • Google’s stated timetable becomes a practical planning reference for organizations and vendors that interoperate with its services, rather than a distant research milestone.

Second-order effects

  • Cryptography, cloud, and device suppliers will be pushed to demonstrate migration paths and compatibility for quantum-resistant schemes; customers will increasingly weigh deployability alongside algorithm choice.
  • Critical-infrastructure operators may bring post-quantum work forward as the gap between Google’s target and the UK’s sector-wide guidance highlights the risk of treating migration as a last-minute compliance project.

Third-order effects

  • If large platforms and public-sector guidance continue to converge, cryptographic agility—being able to replace algorithms without rebuilding services—could become a standard procurement and architecture requirement.
  • The transition is likely to reward implementation capacity as much as cryptographic research: the hard constraint will be upgrading long-lived, interconnected systems without disrupting trust or interoperability.

The trend: Post-quantum cryptography is moving from a standards-and-research problem toward a multi-year infrastructure migration in which deployment readiness becomes the central competitive and security issue.

Discussion

  • @matthewdgreen Matthew Green on bluesky
    I think this is a good precautionary analysis but I'd bet huge amounts of money against a relevant quantum computer by 2029 or even 2035.  [embedded post]
  • @marypcbuk Mary Branscombe on bluesky
    Hopefully the PQC algorithms we have are strong even though they aren't battle tested and commercial vendors have been adding them to products for a few years; what we need in organisations is for folks to turn them on and do the relevant cert management.  Not sure open source is…
  • r/crypto r on reddit
    A Cryptography Engineer's Perspective on Quantum Computing Timelines
  • @johnspurlock.com John Spurlock on bluesky
    'In my course, I'm going to mention RSA, ECDSA, and ECDH only as legacy algorithms, because that's how those students will encounter them in their careers.  I know, it feels weird.  But it is what it is.'  —  words.filippo.io/crqc-timeline/
  • @pfrazee.com Paul Frazee on bluesky
    Probably since he's the one leading the awareness campaign on QC.  See words.filippo.io/crqc-timeline/