Cryptographically relevant quantum computers (CRQCs) don''t exist yet. However, the risk of this changing in the near future is significant enough that organizations are recommended to migrate away from classical algorithms like RSA and ECDSA by 2031.
With quantum computing on the horizon, "harvest now, decrypt later" (HNDL) attacks have become a real threat. Long-lived data encrypted today with classical algorithms may be exposed when quantum computers become able to break these algorithms.
How HNDL Attacks Work
HNDL attacks depend on the fact that, for data encryption, an attacker doesn''t need to be able to immediately decrypt the data to be a threat. Encrypted data collected today can be stored until CRQCs become available, allowing sensitive data to be exposed years in the future.
For some types of data, the delay between collection and decryption is long enough that the information is no longer sensitive. However, data with long shelf lives may still be sensitive years in the future when cyber threat actors can access CRQCs.
What''s Actually Exposed?
The risk of HNDL attacks depends on how long-lived data is. If the shelf life of data puts its expiry date beyond the advent of CRQCs, then it''s at risk.
Uncertainty about when these CRQCs will exist makes it difficult to estimate what data is at risk, especially since estimates are continuously shrinking. However, certain types of data will certainly be impacted by HNDL attacks, including:
- Health records
- Trade secrets
- Government and legal data
- Critical infrastructure and industrial control systems
- Contracts with multi-year confidentiality agreements
What''s Not At Risk
In contrast, any data whose sensitivity expires before CRQCs exist is not at risk. If short-lived, ephemeral, or already-expired data is decrypted, it poses no real risk to the business.
For example, credit card numbers are an example of highly sensitive data with a negligible HNDL risk. Card issuers regularly expire cards and send out new ones to address the risk of lost/stolen cards.
If they do so before CRQCs become available, all previous card numbers become non-sensitive. However, network traffic containing these card numbers (like traffic to payment pages on eCommerce sites) may contain other, longer-lived sensitive and protected data, such as customers names, addresses, and phone numbers.
Addressing HNDL Risk Today
HNDL attacks add urgency to organizations'' quantum migrations because data encrypted today can be exposed in the future. While organizations can wait until 2030/2031 to complete their migrations and maintain compliance, making the shift earlier helps to reduce their risk exposure.
The first step in any quantum migration is identifying where the organization is using vulnerable, classical algorithms in its codebase, a question that the company can answer by creating a cryptographic bill of materials (CBOM). From there, HNDL risk exposure and migration priorities can be assessed by evaluating what data is encrypted where and how its shelf life compares to quantum computing timelines.
New notes, roughly monthly per shift
No paywall, no membership tier — just an email when something new is published. Pick which shifts you care about.