When qubits gossip (security nightmares)¶
Security in quantum computing is what happens when you take the already nightmarish landscape of classical cybersecurity and add the fundamental weirdness of quantum mechanics. Every principle that made security comprehensible gets replaced with something from theoretical physics, and every solution arrives with footnotes beginning “assuming perfect implementation” or “in the absence of side channels”.
Two threads run through it. Quantum systems promise unbreakable encryption through quantum key distribution, marvellous if it worked reliably outside laboratories and did not cost the GDP of a medium-sized nation. They also threaten to break all existing public-key cryptography once quantum computers grow powerful enough, which has sparked a frantic scramble to replace the world’s cryptography before that particular disaster arrives. The second thread is the pressing one, because its bill is already being run up.
Unbreakable, theoretically¶
Quantum key distribution answers the question, what if security depended on the laws of physics rather than the difficulty of mathematics? Two parties share quantum states, and any eavesdropper measuring them inevitably disturbs them, revealing the intrusion. It is elegant, theoretically sound, and demonstrated many times in the laboratory. The practical reality is less inspiring: it needs specialised optical channels that hold coherence over their whole length, works over a few hundred kilometres in good conditions, uses expensive and temperamental equipment, and remains vulnerable to side-channel attacks on the implementation rather than the physics. It also only distributes keys; everything else still relies on classical encryption and classical endpoints, so a compromised laptop undoes all of it. Impressive, then, but not the reason to lie awake.
The two clocks¶
The reason to lie awake is Shor’s algorithm. Most modern encryption rests on problems classical computers find intractable: factoring large numbers for RSA, discrete logarithms for elliptic curves. A sufficiently large, error-corrected quantum computer would solve them efficiently, and everything secured by public-key cryptography, bank transactions, signatures, encrypted traffic, would become readable. This has not happened, because breaking 2048-bit RSA would need millions of stable, error-corrected qubits and today’s machines have dozens of noisy ones. The honest timeline runs from “twenty years” through “sooner than we would like” to “never”.
Two clocks are therefore ticking against each other. One counts down to a cryptographically relevant quantum computer, on a schedule nobody can read. The other counts the years a global cryptography migration takes, which is many. The migration has to finish before the first clock runs out, which is why the work is happening now while the threat is still theoretical. And there is a third, quieter mechanism that turns a future threat into a present debt: harvest now, decrypt later. An adversary can record encrypted traffic today and store it against the day a quantum computer can open it, so anything with long-term value is already exposed, retroactively, the moment it crosses the wire. That is technical security debt in its purest form: incurred today, on a due date nobody can name, at compound interest.
The oddities with no classical analogue¶
Beyond the crypto threat, quantum systems raise security questions classical ones never had to. Observing a quantum state collapses it, so a computation cannot be audited in progress without destroying it, and the audit trails that can be extracted read like measurements of observables rather than “user X accessed resource Y”. Entanglement creates correlations with no classical equivalent, so a shared quantum processor may leak information between tenants through crosstalk that ordinary isolation was never designed to catch. And data protection law assumes data sits in a definite state that can be found, shown, and deleted, which superposition and entanglement quietly complicate. Most of this is deferred, because current systems process classical data through brief quantum intermediate states and the compliance boundaries sit at the classical edges. It is a set of problems being filed for later, which is, once again, the section’s recurring theme.
The clerk’s brief¶
From the clerks, for the Patrician’s eyes
Compiled July 2026. Newest first; settled items are folded into the harvest ledger at the end. The clerks note that this is the one file in the section whose threat is already present, in the sense that traffic recorded today is a liability that has not yet been billed.
March 2026: The clock creeps forward¶
The Quantum Threat Timeline Report 2025, published March 2026 by evolutionQ for the Global Risk Institute from a survey of 26 experts, put the probability of a cryptographically relevant quantum computer within ten years at 28 to 49 per cent, the highest ten-year estimate in the report’s seven-year history, and noted the sharpest upward shift yet. The machine is still not here; the experts are simply less willing to bet it stays away. The clerks observe that a threat which moves earlier each year while remaining perpetually a decade off is precisely the sort that gets deferred until it does not.
June 2025: Europe sets the migration timetable¶
On 23 June 2025 the Commission and member states published a coordinated implementation roadmap for post-quantum cryptography, drawn up by a workstream of the NIS Cooperation Group, asking member states to begin transition by end 2026, secure critical use cases by 2030, and the rest by 2035. Ten years is allotted to a job the roadmap admits is urgent. The clerks note the pattern is familiar from the regulatory file: a deadline long enough to encourage delay, and a threat that may not wait for it.
March 2025: A second lock for the door¶
On 11 March 2025 NIST selected HQC as a backup key-encapsulation mechanism, a code-based scheme chosen deliberately to rest on different mathematics from the lattice-based standard, so that a future break of one does not open everything. The clerks approve of a spare key cut from a different blank, and note it is the sort of prudence that looks excessive right up until the afternoon it does not.
August 2024: The standards land¶
On 13 August 2024 NIST finalised its first post-quantum cryptography standards, FIPS 203, 204 and 205, concluding an eight-year process and giving the world’s cryptographers something concrete to migrate to. Standards are the starting gun, not the finish line; the migration they enable is the multi-year part. The clerks file this as the moment the deferral stopped having an excuse.
The harvest ledger¶
The ledger has one entry that keeps growing and cannot be paid down retroactively: every message encrypted with today’s public-key cryptography and recorded by a patient adversary is a liability whose due date is whenever the first cryptographically relevant quantum computer arrives. Standards exist, since August 2024, with a backup since March 2025; Europe has a timetable, since June 2025, running to 2035; and the expert estimate of the due date, as of March 2026, is creeping earlier. The clerks’ standing assessment is that this is the section’s only genuinely present threat, that it behaves exactly like debt, silent, compounding, discovered late, and that the harvest already gathered will be billed regardless of how the migration goes.