Connections: The Internet’s Quantum Problem – Why Your Passwords Have an Expiration Date

READ IN:

3–4 minutes

By: Sanvi Immadi.


Think about the last few minutes of your day. You unlocked your phone, read an article, sent a message you’d rather keep private, maybe even bought something online. Each of those tiny actions felt effortless–almost invisible. But underneath every one of them, a quiet kind of computation is standing guard, scrambling your data into a form that only the right key can undo. 

That invisible shield is called cryptography, and for decades, it has worked so well that most of us never even have to think about it. However, with the profound advances in new technology, it raises the question: will these encryptions still be effective? 

To understand why, you have to know what those digital locks actually are. 

The encryption protecting most of the internet relies on a clever trick. It uses math problems that are simple to create but agonizingly hard to reverse. Multiplying two enormous prime numbers is easy; figuring out which two primes produced a giant result is a nightmare for an ordinary computer. The difference in effort (between locking and unlocking) is what keeps your data safe. 

This approach, done by systems with names like RSA and elliptic curve cryptography, has held the line for a generation. Conventional machines simply compute too slowly to crack the keys in any reasonable time. 

And then a different kind of machine enters the picture. 

A sufficiently powerful quantum computer would not play by the old rules. Using a method called Shor’s algorithm, it could solve certain math problems, like factoring the giant numbers behind your encryption far faster than ordinary machines ever could, slicing through the very defenses that protect us. As NIST (National Institute of Standards and Technology) puts it, researchers are racing to build machines “that could break the current encryption that provides security and privacy for just about everything we do online” (NIST, 2024) 

That is the heart of the threat, and it no longer is some distant sci-fi worry. The other issue is that adversaries do not need to wait for the technology to arrive. Encrypted data stolen today can simply be stored, like a letter tucked into a drawer, and unlocked later once the machines catch up. Security agencies call this “harvest now, decrypt later,” and together the NSA, CISA, and NIST have warned that this tactic could be “particularly devastating to sensitive information with long-term secrecy requirements” (National Security Agency/Central Security Service, 2026). That is why CISA urges organizations to begin preparing for the transition now, before the threat matures (“Post-Quantum Cryptography Initiative | CISA,” 2022). 

So what is the answer? This is where post-quantum cryptography (PQC), steps in.

The name can be misleading. Post-quantum cryptography is not about using quantum computers to encrypt things. It is a new family of mathematical locks designed to run on the ordinary laptops and phones you already own, but built from problems that even a quantum machine struggles to crack. Think of it as redesigning the lock so the new picks no longer fit. 

The groundwork is already laid. In August 2024, NIST finalized its first three post-quantum standards: FIPS 203 (ML-KEM) for secure key exchange, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures (NIST, 2024). NIST’s director, Laurie E. Locascio, framed it plainly: the goal is to ensure quantum computing “will not simultaneously disrupt our security.” 

None of this means your messages are defenseless tomorrow. Quantum computers powerful enough to break today’s encryption do not yet exist in usable form, and NIST notes that some experts predict such a machine could appear within a decade (NIST, 2024). But replacing the locks across the entire internet takes years, which is exactly why the work begins now rather than later. 

The threat is real, but so is the response. Governments and engineers are already swapping out the old mathematics for sturdier stuff. The quiet shield over your daily life is being re-forged, not because it failed, but because the world is changing beneath it


References

National security agency/central security service. (2026). Nsa.Gov. https://www.nsa.gov/press-room/news-highlights/tag/47488/cyber/

NIST. (2024). NIST releases first 3 finalized post-quantum encryption standards | NIST. In NIST. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards

Post-Quantum cryptography initiative | CISA. (2022). In Cybersecurity and Infrastructure Security Agency CISA. https://www.cisa.gov/topics/risk-management/quantum

Leave a Reply

Discover more from The Curiosity Review

Subscribe now to keep reading and get access to the full archive.

Continue reading