We joked in a recent post that the famous five-dollar wrench of security lore is really a ten-dollar wrench now, because inflation comes for everything. Fair enough. But there is another number in security that matters far more, and it is moving hard in the opposite direction. The cost to break the encryption protecting almost everything you send is collapsing, and unlike your grocery bill, that is not a slow grind. It is a fire sale, and the buyers are already shopping.
Here is the uncomfortable shape of it. Nearly all secure communication on earth rests on two families of cryptography, RSA and elliptic-curve, and both are vulnerable to a sufficiently powerful quantum computer running an algorithm that has existed since 1994. For thirty years that was a theoretical footnote. It is not anymore. In just the last two years, published research cut the estimated size of a quantum computer needed to break RSA-2048 from around twenty million qubits to under one million, and by some newer designs closer to a hundred thousand. The target did not move a little. It fell through the floor.
The threat is not the break. It’s the harvest.
This is where most people misjudge the risk, so slow down here. You might think, a quantum computer that can crack RSA does not exist yet, so this is a problem for later. That is exactly the assumption the attack is built to exploit.
The strategy has a name: harvest now, decrypt later, sometimes store now, decrypt later. Intelligence agencies and other well-resourced adversaries are not waiting for the quantum computer to arrive before they act. They are intercepting and storing your encrypted data today, TLS web traffic, VPN tunnels, email, messages, and warehousing petabytes of it, so that the day a capable quantum computer comes online, they can go back and decrypt all of it retroactively. It is not a new breach. It is the delayed detonation of one that is already underway. As one analysis put it, attackers do not need a quantum computer to create quantum-era risk. They only need access to encrypted data that will still be worth reading when the decryption becomes possible.
So the question is not “can anyone break this today.” It is “will this still matter when someone can, and is it being copied into an archive right now.” For a lot of data, the answer to both is yes.
Why “it’s years away” is false comfort
Let us be honest about the timeline, because fear-mongering helps no one. The actual break, a quantum computer that can defeat RSA-2048 and elliptic-curve crypto, is most likely still years out. Credible estimates cluster around 2030 to 2035, though they keep sliding earlier as the research advances. Nobody can give you the date.
But that uncertainty is not the reassurance it sounds like, for two reasons. First, if a secret you send today needs to stay secret past that day, and it is being harvested now, it is already compromised. You simply will not find out until the archive gets decrypted. Second, migrating cryptography across real systems takes five to ten years. So the safe moment to start moving was never “when quantum arrives.” It is now. The organizations and individuals who are fine in 2032 will be the ones who acted in 2026, not the ones who waited for a headline.
And this is not a fringe worry anymore. In August 2024, NIST finalized its first post-quantum encryption standards. Its official transition plan deprecates RSA-2048 and the common elliptic curve by 2030 and disallows them entirely by 2035. The US government has, in writing, given itself a deadline to be off the encryption that currently secures most of the internet. When the standards body publishes an expiration date for the locks on everything, the smart move is to stop treating it as science fiction.
The good news: the fix is real and already shipping
The defense is post-quantum cryptography, new algorithms built to resist quantum attacks, and the encouraging part is that the best tools are already deploying it, quietly, today. Signal added a post-quantum key-agreement step back in 2023. Apple moved iMessage to a post-quantum protocol it calls PQ3. Chrome, Cloudflare, Amazon, and Microsoft have all rolled out hybrid post-quantum protection for web traffic. Among VPNs, several now offer post-quantum-resistant tunnels, including Mullvad, one of the providers we ship. The migration is uneven and far from finished, but it is underway, and the leaders are the ones who moved before they had to.
Who actually needs to care, honestly
Proportion matters, so let us be straight about it. If the sensitive thing you send has a shelf life of days or weeks, harvest-now-decrypt-later barely touches you. Nobody is going to spend a quantum computer’s time decrypting your dinner plans in 2034. For most everyday traffic, this is a low priority.
It matters enormously, though, if you handle data that must stay confidential for years or decades. Legal and medical records. Financial and business negotiations. The identity of a source. Trade secrets. Anything a future adversary would still find valuable. A merger discussion captured in 2026 can still be actionable intelligence in 2034. Cryptocurrency holders have a specific, sharp exposure, because older blockchain addresses rely on exactly the elliptic-curve math that quantum breaks, and those keys are sitting in public view being harvested by definition. For anyone in those categories, the harvest is a live problem this year, not a future one.
What to actually do
For the long-lived secrets that matter, three moves.
Prefer tools that have already migrated to post-quantum cryptography. Use the messengers and VPNs that added it, Signal, iMessage’s PQ3, post-quantum VPN tunnels, and check whether the critical tools you rely on are quantum-ready, because many still are not.
Favor crypto-agility, meaning setups that can swap algorithms as standards evolve rather than being welded to one scheme forever. The organizations that struggle will be the ones who cannot change.
And lean on the oldest rule in privacy, which harvest-now-decrypt-later only sharpens: data you never create or transmit cannot be harvested. Minimize what you send. Avoid services that log and archive everything, because nothing stored is nothing to decrypt later. Prefer designs with no central server hoarding your history. The smaller your footprint today, the less of you is sitting in an archive waiting for the key to turn.
This is why we keep insisting that the cryptography under the hood matters, not just whether something is encrypted, but whether that encryption will still hold a decade from now. We choose tools that are moving to post-quantum, we favor architectures that do not stockpile your life for later, and we treat minimizing your transmitted footprint as a real defense, because the best protection against being decrypted later is to not be in the harvest at all.
The wrench got more expensive. Breaking your encryption is getting cheaper by the month. Only one of those is worth planning around, and it is not the wrench.
If you want communications and a device built with their shelf life in mind, using tools that have already made the post-quantum move, email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.