Why quantum threatens today's encryption
Most of the internet's security rests on one convenient fact: multiplying two huge prime numbers is easy, but working backwards from the result is practically impossible for normal computers. Your bank login, your messages, online payments: protected by math being slow.
In 1994, mathematician Peter Shor showed that a sufficiently large quantum computer could run that math backwards absurdly fast. That single result is why security agencies and banks have watched quantum computing for thirty years. The honest caveat: running Shor's algorithm against real encryption needs millions of reliable, error-corrected qubits. Today's best machines have a few hundred noisy ones. Nobody credible claims the code-breaking machine exists. The question is when, and serious answers range from a decade to several.
"Harvest now, decrypt later"
So why is everyone moving already? Because encrypted data can be stolen today and stored cheaply for years. If a quantum computer can open it in 2035, everything harvested in 2025 becomes readable: state secrets, medical records, financial archives, deal documents. Intelligence agencies openly plan around this, and it has a name: harvest now, decrypt later. For anything that must stay secret for a decade or more, the quantum threat is effectively already here.
The fix: changing the internet's locks
The answer is post-quantum cryptography (PQC). New encryption math chosen specifically because neither normal nor quantum computers know how to crack it. After a multi-year global competition, the US standards agency NIST published the first official post-quantum standards in August 2024. That was the starting gun.
The new standards, by name
| Padrão | Com base em | O que faz | Status |
|---|---|---|---|
| FIPS 203, ML-KEM | Key establishment / general encryption workflows | Module lattices | |
| FIPS 204, ML-DSA | Digital signatures | Module lattices | |
| FIPS 205, SLH-DSA | Digital signatures / diversified backup | Hash-based cryptography |
Approved by NIST on August 13, 2024. NIST selected HQC in 2025 as an additional encryption algorithm for standardization and continues work on further signature standards. Post-quantum cryptography is classical cryptography designed to resist quantum attacks. Different from quantum cryptography, which uses quantum physics for communication or key distribution. ■OfficialOfficial: Standards body or institutional primary source. NIST, Aug 13 2024 ↗
Now comes the migration: every bank, government, cloud provider, browser, messaging app and payment network eventually swaps its cryptography. Big platforms began rolling PQC into browsers, phones and messaging protocols almost immediately; regulated industries follow on multi-year timetables. It's one of the largest coordinated upgrades in the internet's history: mostly invisible to users, very visible in budgets.
The flip side: physics as a security guard
Quantum mechanics doesn't just pick the lock: it also offers a new kind of lock. Because measuring a quantum signal disturbs it, a link built on quantum states reveals any eavesdropper by physics itself. China operates a roughly 2,000-km quantum-secured backbone between Beijing and Shanghai plus the Micius satellite, and metropolitan quantum networks are growing in Europe and the US. It's early and specialized, but it's real, shipping technology.
Visão do investidor: a migração de segurança é o orçamento quântico que será gasto independentemente de quando computadores quânticos úteis chegarem. Determinada por órgãos de padronização e reguladores, fluindo pelos grandes fornecedores de segurança e nuvem, empresas especializadas em criptografia e consultorias. É o canto "já real" do cenário mapeado em página de investimento.
How to read security headlines
Three questions cut through almost every scary quantum-security story: Is this about a demonstrated capability or a projection? Does the math involved actually need Shor-scale machines, or is it marketing? And is the recommended action just… the migration everyone already agreed on? Panic is rarely warranted; complacency about long-lived secrets is equally wrong. The boring truth: the fix is known, standardized, and rolling out.