Almost every secure connection on the internet, from a bank’s login page to a messaging app, relies on math problems that an ordinary computer would need centuries to solve by brute force. A sufficiently powerful quantum computer would not need centuries. It is not there yet, and estimates of when it might arrive vary widely, but the U.S. government has already spent the past several years finalizing a replacement set of encryption standards, on the theory that waiting until the threat is confirmed would be too late to matter.
RSA And Elliptic-Curve Encryption, Explained Simply
The encryption protecting most of today’s online banking, shopping, and messaging relies on a small number of math problems that are easy to compute in one direction and extraordinarily hard to reverse. RSA encryption, one of the oldest and still most widely used schemes, depends on the difficulty of factoring the product of two very large prime numbers; elliptic-curve cryptography, used in most modern browsers and messaging apps, depends on a related but different hard problem involving points on a curve. A classical computer, no matter how large, would need an amount of time measured in centuries or longer to reverse either calculation for a sufficiently large key. That assumption, that reversing the math is computationally impractical, is the entire foundation the modern internet’s security rests on.
Shor’s Algorithm And Why Size Matters
The math changes if the computer doing the reversing is a quantum computer running a specific algorithm published by mathematician Peter Shor in 1994. Shor’s algorithm can, in principle, factor large numbers and solve the elliptic-curve problem exponentially faster than any known classical method, turning a calculation that would take longer than the age of the universe into one that could finish in hours or days. The catch, so far, has been scale: running Shor’s algorithm against a real-world encryption key requires a quantum computer with many thousands of stable, error-corrected qubits, far beyond the machines that exist today, which top out in the hundreds of physical qubits and struggle with error rates that corrupt long calculations. That gap is why no quantum computer has broken real-world encryption yet, and why estimates of when one might range from within a decade to considerably longer.
NIST’s New Post-Quantum Standards
Rather than wait for a definitive timeline, the National Institute of Standards and Technology spent eight years running a public competition among cryptographers to design replacement algorithms that even a large quantum computer could not efficiently break. In August 2024, NIST finalized the first three of those replacements as official federal standards: a key-exchange method built on lattice math known as ML-KEM, and two digital-signature schemes, ML-DSA and SLH-DSA, each based on a different hard mathematical problem so a weakness in one would not compromise all three at once. The agency’s announcement described the release as the culmination of the standardization effort, with the underlying approved standards now available for any government agency, browser maker, or bank to begin adopting.
The “Harvest Now, Decrypt Later” Problem
The most immediate risk is not a working quantum computer today but a simple storage strategy: an adversary can copy and save encrypted traffic now, keep it in cold storage for years, and decrypt it later once a capable quantum computer exists. Intelligence and cybersecurity agencies refer to this as a harvest-now, decrypt-later attack, and it matters most for data with a long shelf life, such as medical records, trade secrets, or classified communications, where information intercepted today could still be damaging if exposed a decade from now. A joint quantum-readiness fact sheet issued by federal cybersecurity agencies urges organizations to inventory which of their systems rely on vulnerable encryption now, rather than waiting for a quantum computer capable of breaking it to actually appear.
Who Is Already Migrating, And Why It’s Slow
Large technology companies have started building the new standards into everyday products; both major browser makers and cloud providers have begun rolling out hybrid connections that pair a traditional algorithm with a post-quantum one, so a connection stays secure even if only one of the two methods holds up. Migration across the wider economy is expected to take years, not months, because the new algorithms typically require larger keys and more computing overhead, and because replacing cryptography embedded inside older hardware, payment terminals, industrial control systems, and government systems built decades ago is a slower and more expensive undertaking than updating a single app. That slow pace is precisely what worries the agencies pushing the standards: the safest window to migrate is before a capable quantum computer exists, not after one is announced.
Quantum computing itself remains, for now, a fast-moving research field rather than a working tool for breaking bank-grade encryption, which is exactly why the standards-setting work is happening years ahead of the threat it is designed to counter. Financial regulators and central banks have begun studying the same risk from the other direction, examining how encrypted ledgers and payment systems built today might need to be re-secured before any transition is complete.
This article was produced with the assistance of AI and reviewed by Morning Overview editors.
More from Morning Overview