Interview with NIST's Dustin Moody on the agency's recently selected encryption algorithms and why they're designed to withstand future quantum hacking threats
The NIST's “quantum-resistant” encryption standards, picked via contest, were designed to keep everybody one step ahead of hacking by quantum computers.
Context & Ripple Effects
The interview lands days after NIST selected four quantum-resistant algorithms to underpin its future cryptography standards by 2024 — the endpoint of a public contest that has been running since at least 2020, when the WSJ profiled the race to replace RSA-era public-key cryptography.
Moody is the mathematician explaining why the picks matter now: as MIT Technology Review reported in 2021, US agencies worry about attackers harvesting encrypted data today for decryption once quantum machines mature, so the standards are designed to be adopted before such computers exist.
First-order effects
- Vendors and federal agencies building to NIST standards get their target algorithms named, starting migration planning away from RSA-class public-key methods toward the four selections.
- Dustin Moody and NIST's cryptography team shift from judging the contest to shepherding the winners through standardization, with final standards slated by 2024.
Second-order effects
- Security product makers and cloud providers face pressure to ship quantum-resistant options early, since 'harvest-now, decrypt-later' exposure makes long-lived data the first customer demand driver.
- Any algorithm that stumbles during scrutiny would force re-selection among the contest's remaining candidates, so the runner-up designs retain commercial value.
Third-order effects
- If the pattern holds, NIST's contest model — open, multi-year, international submission — becomes the template for how foundational security standards get set, and the 2024 publication of three finalized algorithms would mark the start of a decade-long global crypto migration.
- Quantum computing timelines become a procurement variable: organizations holding data for decades must weigh migration costs against uncertainty about when cryptographically relevant machines arrive.
The trend: Cryptography is moving from quantum-vulnerable public-key standards to NIST-crowned post-quantum algorithms through open multi-year contests, with adoption racing against both quantum progress and data-harvesting adversaries.