How US agencies are preparing for “post-quantum cryptography” against attackers who harvest sensitive data now for decryption in the future
The US government is starting a generation-long battle against the threat next-generation computers pose to encryption. Tweets: @techreview , @techreview , @aarongrunwald , @statecreative74 , @royvanrijn , @sborsch , @jbdunne , @selenalarson , @techreview , @piratecto , @deephaven , @ianpatterson99 , @gaidar , @markgamache , @treyrutledge3 , and @dinodaizovi Tweets: @techreview : Faced with this “harvest now and decrypt later” strategy, officials are trying to develop and deploy new encryption algorithms to protect secrets against an emerging class of powerful machines. Read more from @HowellONeill here: https://www.technologyreview.com/ ... @techreview : The US government is starting a generation-long battle against the threat next-generation computers pose to encryption. https://www.technologyreview.com/ ... Aaron Grunwald / @aarongrunwald : Future “threat of a nation-state adversary getting a large quantum computer and being able to access your information is real,” says @NIST researcher #cryptography https://www.technologyreview.com/ ... State Creative / @statecreative74 : We need to transition towards a post-quantum #cryptography era since #quantum computers may be able to break today's #encryption. https://www.technologyreview.com/ ... Roy van Rijn / @royvanrijn : I've been saying this for years: If you want your secrets to be secret in 10-20 years, use different encryption methods. Once RSA is broken, every password you've “secretly” send over HTTPS will become plain text. Collect now. Profit later. https://www.technologyreview.com/ ... Steve Borsch / @sborsch : Of course, this is why the U.S. government's NSA has a *huge* facility in Utah, storing petabytes of data (all phone calls, texts, emails, etc. as well as encrypted data to crack someday). https://www.technologyreview.com/ ... Jbd / @jbdunne : hackers' time horizons just shifted https://www.technologyreview.com/ ... Selena / @selenalarson : I like to think of this as a warehouse full of unopened packages the government is sucking up and storing away until they can find the right box cutter to open them all https://www.technologyreview.com/ ... @techreview : Besides having to deal with the hackers of today, US government officials are preparing for another threat: attackers who are collecting sensitive, encrypted data now in the hope they'll be able to unlock it with the quantum computers of tomorrow. Thread. https://www.technologyreview.com/ ... Sergio Gago / @piratecto : Hackers are stealing data today so quantum computers can crack it in a decade - The threat comes from quantum computers, which work very differently from the classical computers we use today. Instead of the traditional bits made of 1s and 0s, they use qu... https://www.technologyreview.com/ ... @deephaven : Current computer security relies upon assumptions about what is easy vs. hard for a computer to do. Data protected by current encryption is potentially vulnerable to quantum computers of the not too distant future. https://www.technologyreview.com/ ... Ian Patterson / @ianpatterson99 : Around the world, various organisation - nefarious or otherwise - are surely storing encrypted data they get hold of for later exploitation, maybe decades later, when technology permits. This shouldn't be a surprise: Bletchley did it in WW2. https://www.technologyreview.com/ ... Gaidar Magdanurov / @gaidar : “The threat of a nation-state adversary getting a large quantum computer and being able to access your information is real” - https://www.technologyreview.com/ ... Mark Gamache / @markgamache : Encryption is not forever. https://www.technologyreview.com/ ... @treyrutledge3 : “The threat of a nation-state adversary getting a large quantum computer and being able to access your information is real,” says Dustin Moody, a mathematician at NIST. #QuantumEncryptedCyber #NIST #DRGN 🇺🇸#USA https://www.technologyreview.com/ ... Dino A. Dai Zovi / @dinodaizovi : It's been a good idea for years to assume that TLS and other encrypted traffic/data is being recorded to be decrypted in the future when quantum computers bring it within reach: https://www.technologyreview.com/ ...
Context & Ripple Effects
The threat model here has been building for years: analysts flagged as early as 2015 that modern encryption must adapt to resist quantum attacks, and a global competition to design replacement standards followed in 2020. What changed by this piece is the framing of urgency — attackers are not waiting for quantum computers to exist, but archiving encrypted traffic now against the day they do.
That makes migration a present-tense problem rather than a future one. NIST's selection of new quantum-resistant algorithms, covered separately in interviews with mathematician Dustin Moody, gives US agencies the concrete tools for what the government itself describes as a generation-long deployment effort.
First-order effects
- Agencies and any organization relying on public-key cryptography like RSA must begin replacing it with NIST's newly selected algorithms — a migration measured in decades because embedded systems and long-lived secrets cannot be swapped quickly.
- Data being collected today under 'harvest now, decrypt later' strategies — including, per the reporting, the petabytes of communications the NSA stores in its Utah facility — is exposed retroactively once capable quantum machines arrive.
Second-order effects
- Vendors of HTTPS and other encrypted products face a dual mandate: adopt quantum-resistant cryptography while governments including the Five Eyes, India, and Japan simultaneously push for backdoors into end-to-end encryption — two policy pressures pulling the same protocol stack in opposite directions.
- Standards bodies and security vendors gain a selling cycle: 'quantum-safe' becomes a procurement requirement, shifting competitive advantage toward firms that can demonstrate NIST-aligned migrations first.
Third-order effects
- If the harvest-now dynamic holds, confidentiality stops being guaranteed by key length alone and becomes a function of how fast an organization can rotate algorithms — making cryptographic agility a permanent architectural requirement rather than a one-time upgrade.
- The episode cements NIST's role as the arbiter of global encryption trust, while the gap between state stockpiling capability and civilian defense timelines widens into a structural asymmetry that regulators will eventually be forced to address.
The trend: Governments are treating quantum computing less as a research milestone than as a countdown clock on existing encryption, driving a multi-decade global migration of cryptographic infrastructure ahead of any working machine.