The Register Home Page

back to article The post-quantum cryptography apocalypse will be televised in 10 years, says UK's NCSC

The UK's National Cyber Security Centre (NCSC) today started the post-quantum cryptography (PQC) countdown clock by claiming organizations have ten years to migrate to a safer future. The guidance defines three key milestones that NCSC claims organizations must be aware of as quantum computers - perceived to be the next major …

  1. Clausewitz4.1 Bronze badge

    Bollocks

    "organizations have ten years to migrate to a safer future."

    Likely who wrote this has stocks in post-quantum crypto companies. My RSA-4096 will still be safe.

    And IA will never beat real human intelligence.

    1. JimmyPage Silver badge
      Mushroom

      Re: Bollocks

      +1

      I have no idea what grifting outfit downvoted you.

      Quantum cryptography (if it ever comes to pass. Where's my fusion powered jetpack ?) just means that you apply a little logic to your encryption needs. 80% of encrypted data will generally have a very short shelf life and can be generally casually encrypted.

      And there is probably a lot of data that doesn't really need to be encrypted at all.

      1. rafff

        Re: Bollocks

        "And there is probably a lot of data that doesn't really need to be encrypted at all."

        The trouble with encrypting just the important stuff is that you are firing a signal rocket to tell any attacker just where to focus his energies.

        You cannot hide the needle if there is no haystack to hide it in.

        1. Scotech

          Re: Bollocks

          One of many reasons why the push for HTTPS by default in Web browsers was worth doing, why the move towards some form of encryption for DNS is also sensible (assuming that a sensible standard can ever be agreed on here - my preference is for either DoT or DoQ, just not DoH, please!) and a very good reason to push for a shift in all web encryption to use PQC techniques by default, before anyone comes up with a scalable quantum computing system. In fact, any responsibile business who reckons they're close to achieving this milestone should absolutely be pushing for these changes vocally and publicly, right now. The fact that MS isn't is a further piece of evidence that they're maybe not so close as they claim?

          1. Clausewitz4.1 Bronze badge

            Re: Bollocks

            "my preference is for either DoT or DoQ, just not DoH, please!)"

            I didn't saw a mention to a PKI into RFC 9250 (QUIC). Did I miss something ?

      2. Bebu sa Ware Silver badge
        Windows

        Re: Bollocks

        "And there is probably a lot of data that doesn't really need to be encrypted at all."

        But you encrypt it anyway to thwart traffic analysis and friends.

        You are right that if you don't require perfect forward secrecy of more than a few years and you are using current cryptography then quantum computing isn't really a threat.

    2. Anonymous Coward
      Anonymous Coward

      Re: Bollocks

      RSA keys useful lengths are 2048 (equivalent to 112 bit symmetric keys, eg 3DES), 3072 (AES128), 7680 (AES192) and 15360 (AES256), as described in NIST SP800-57 Part 1.

      That the use of 4096 is so commonplace is interesting, because it shows the love for neat powers of 2, disregarding whether they're actually useful (ie, people using them don't really understand how what they using works, but they want it to look good).

      Ed25519 ftw!

      1. Anonymous Coward
        Anonymous Coward

        Re: Bollocks

        "That the use of 4096 is so commonplace is interesting"

        That's the maximum number of bits a lot of open source software let's you generate a key. I would go for 15360 if it allowed me to.

      2. owlstead

        Re: Bollocks

        It's also the maximum umber of bits many hardware accelerators are able to handle. It's not some kind of conspiracy. It doesn't make much sense to have a 6k or so key if the certificates above that only have a 4k key pair.

    3. Jeffrey Tillinghast

      Re: Bollocks

      I suspect that even RSA-2048 might still be safe. In fact, even RSA-1024 seems to remain beyond the reach of anything but truly herculean and costly efforts, which would be justified only in a very few cases - certainly not for cracking mine or your RSA keys.

      1. Anonymous Coward
        Anonymous Coward

        Re: Bollocks

        You wrongly assume brute force is the only way to break RSA keys (of whatever length).

        I for one would willingly hand over mine if you put a gun to my head or deposit a few million in my bank account. The latter would be preferable. :-)

  2. SsiethAnabuki

    Seems not entirely unreasonable

    Whilst we still seem to be a way away from anyone having a realistic chance of leveraging quantum computing to crack encryption, it probably will continue to feel that way almost until the day that someone is in that position. At that point, it's pretty much too late to scrabble for a solution.

    Compounding the problem is that there's a great deal of incentive for state-level actors to conceal their capabilities - either playing them up or down for different effect.

    All in all - encouraging people to move, on a challenging timescale, doesn't feel so bad.

  3. PCScreenOnly Silver badge

    SMS

    Don't worry, you'll still be asked to validate from the SMS text they are about to send you.

    Nice and safe

    1. Tim 11

      Re: SMS

      And email will continue to be completely unreliable and insecure

      Oh and your credit card will still have the "secret" cvv code printed on the back

      1. ovation1357

        Re: SMS

        Except that a number of cards now print the "secret" CVV on the same face as the card number and expiry date.

        I don't get it: However tenuous/weak the CVV may be, it does still add a layer of protection e.g. one "attack" might be obtaining a photo of the card so having the code on the back slightly reduces the risk of this being useable.

        I'd love to know why some banks have decided it's okay to do this.

  4. thatguywithadog

    Wait... is this the same government that just issued a notice to a well known tech company demanding it secretly punch holes in existing encryption, cos they want to see what Mrs Miggins is talking about with her neighbour at number 32 down the road?

    That government?

    That is telling businesses to work on their encryption skills?

    I... um... yeah.

    1. DancesWithPoultry
      Alert

      Standard Operating Procedure

      That's been SOP for our spooks for quite some time.

      NCSC, part of GCHQ, looks after business interests and gives advice on securing OT/IT and using encryption, including a recommendation to use E2EE.

      MI5 and plod are on the hunt for "baddies" [1] and so want a back door into everything.

      This has been the confused government policy for years.

      [1] This included using the Regulation of Investigatory Powers Act 2000 to catch people not picking up their dogs shit, as reported by El Reg many moons ago

    2. FuzzyTheBear
      Pint

      You got it wrong ...

      What they're really after is the pics she's sending to Mr Brown.

  5. amanfromMars 1 Silver badge

    Keep It Simple, Stupid and let LOVE Flow with Compassionate Conservatism at ITs Very Best

    If governments are worried about the post-quantum cryptography world then they can define and provide the applications required for any desired mitigations designed to secure sensitive and secretive information and intelligence......... and charge a subscription fee for the service rather than causing untold expense upon others who may not have a clue about what to do.

    Methinks even now though, the full truth of the matter is that there is nothing to be done to prevent quantum computer base communication rendering any and all defensive measures against it’s remarkable abilities a complete and utter waste of time and money.

    1. Anonymous Coward
      Anonymous Coward

      Re: Keep It Simple, Stupid and let LOVE Flow with Compassionate Conservatism at ITs Very Best

      "all defensive measures against it’s remarkable abilities a complete and utter waste of time and money."

      KISS is nice. Money and power, better. And yes, the years that passed were a complete waste of time and money. Faults on all sides.

  6. Doctor Syntax Silver badge

    Yes, quantum computing is sticking to the schedule it's always had - 10 years away.

    1. Anonymous Coward
      Anonymous Coward

      Not quite, actually

      Someone above observed that encrypted things rarely need to be encrypted for long - very true.

      But in my industry corner we're mostly focused on digital signatures, and signed items can last for decades. We're definitely discussing post-quantum crypto (PQC) but there aren't even OIDs for half the algorithms, let alone implementations, so nothing past discussions yet. But it will change, and if I were going to take a guess of where it will change first I'd look to the time-stamp services - google RFC3161.

      We're all anticipating the "quantum apocalypse", the day RSA and EC are broken. If you can prove something was digitally signed before then, it's arguably valid even if its signed with RSA. If it's signed after that day, it's arguably not. It's the timestamp that needs a quantum-resistant algorithm, and I'm certain we'll start seeing them in a lot less than ten years.

      Will you be encrypting your zip files with PQC in ten years? No. But it's going to be a real thing by then, there's simply too much at stake for it not to be.

      1. owlstead

        Re: Not quite, actually

        Nice comment, but zip usually uses password based key derivation and symmetric encryption; it is already quantum safe (assuming that the password is sufficiently safe of course, but that's an issue that's plaguing password based encryption *right now*). So yeah, agree but for the last sentence; zip is not a good example.

        1. Androgynous Cupboard Silver badge
          Pint

          Re: Not quite, actually

          Exactly the kind of pedantry I would hope for around here, have a beer.

    2. Phil O'Sophical Silver badge

      > sticking to the schedule it's always had - 10 years away.

      So, about the same time as we get AGI and fusion power? Not holding my breath...

      1. Anonymous Coward
        Anonymous Coward

        Hope springs eternal ...

        You are missing the point !!!

        The 'fact' that AGI & Fusion power WILL be available at the same time is very fortuitous !!!

        They will be needed to 'help' prove the PQC actually works and, of course, provide the increased power needs to run ALL the 'Quantum Computers' !!!

        Looks like good planning for once !!!

        [Keep holding the straight face ... just a little bit longer ... ]

        :)

  7. Diogenes8080

    Advances in cryptography and in the computing power required to break those cyphers are collectively predictable. We just don't know exactly when the tortoise will overtake the hare or vice versa. What is certain is that the encrypted data you send with the best cryptography today will be trivially decypherable X years in the future. What was not happening maybe 15 years ago and is happening to an uncertain degree today is the quantity of intercepted encrypted data being stashed away in the hope that it will prove useful in X years time.

    Now let's see. Who is in a position to collect that data, bear the cost of its retention and derive the highest value from it when it is finally unlocked?

    1. Anonymous Coward
      Anonymous Coward

      "Now let's see. Who is in a position to collect that data, bear the cost of its retention and derive the highest value from it when it is finally unlocked?"

      Interesting philosophical question.

    2. Eclectic Man Silver badge

      PEDANT ALERT!!!

      Diogenes8080: What is certain is that the encrypted data you send with the best cryptography today will be trivially decypherable X years in the future.

      This depends on the encryption algorithms used. A one-time-pad encrypted message is theoretically secure for ever. What you mean is that current encryption algorithms based on classical number theory with numbers too large for current computers to have a reasonable chance of cracking in, say 4 billion years continuous run time, will be easy for the computers of 2035 to crack. These are not the same things. The real problem quantum computing poses to cryptography is in remote key distribution, where the communicating parties have to exchange key material over public, insecure communications links. The belief is that currently 'difficult' mathematical problems, such as the discrete logarithm problem in finite fields, and factorisation of large numbers will become easier with quantum computing.

      1. owlstead

        Yeah, but (EC)DSA, (EC)DH and RSA are also used for in place encryption (ECIES), signatures and whatnot. I don't think that this problem is just an issue of *remote* key distribution. That's underestimating the problem.

  8. Long John Silver Silver badge
    Pirate

    Please clarify

    Some issues for people savvy about the internal workings of encryption.

    1. Presumably a quantum computer (QC) presented with a stream of digits and no prior expectation of the nature of the encoding algorithm or hint about the content, must work through all known algorithms and possible variations in their parameters until a stop criterion surfaces. The criterion would be recognisable text, numerals, or images. That, assuming the QC itself, or via a link, has AI abilities. The attempt at recognition step must entail delay in the process. Even should the QC just churn out results - these for later analysis - until it runs out of options, it would be tied up on that task and not available for other uses.

    That suggests, an organisation archiving confidential/secret information using its own, perhaps a cascade, of encoding algorithms could achieve pretty much impenetrable obfuscation. The main source of weakness, as for other means of confidential data storage, would be human error/malfeasance.

    2. When the organisation's data is accessible onsite for live, rather than archival, purposes, multiple persons may have entry to the data. That must entail checking bona fides by gatekeepers to the facility, and/or issuing individuals with passcodes. This offers potential insecurity, but not directly related to the effectiveness of the data's encoding. In this and the previous example, a QC cannot be given sight of the encoded data without some form of 'break-in' to purloin it.

    3. Menace from QC inspection appears to be greatest for encoded live information shared among people. Unless one time pads are deployed, these being unsuitable in many circumstances, there must be a common set of encoding algorithms e.g. public key cryptography. In these instances a QC need not, as was necessary in the first item above, speculatively explore many possible algorithms. However, this acts as an incentive for organisations to devise independent semi-public key cryptography.

    4. On the basis of the foregoing, and when the true capabilities of QC for decryption are known, considerable effort may be put into understanding how to maximise the cost of decryption (QC time) for enabling security of varying degrees and durations. To be borne in mind is whether there is the potential for QC to become ubiquitous.

    1. owlstead

      Re: Please clarify

      It's some time since I've seen such misinformed technobabble, and that's while following security and specializing on this particular subject of PQC.

  9. Jeffrey Tillinghast

    Excuse my skepticism

    As of the first half of 2025 it still remains to be seen whether quantum computers can be engineered to scale up to tackle problems of a practical relevance that cannot be tackled by conventional digital computers far more conveniently, cheaply, and probably faster. Quantum computing looks more and more like controlled exothermic nuclear fusion: an issue the science of which is very well understood, but one in which the concomitant engineering problems are extraordinarily difficult. My guess - and I cheerfully hope that I am wrong - is that, by 2050 people will still be saying that practical quantum computers will be available for sale soon. Forget about D-Wave, which is extremely limited in the problems it can address, and it is not yet clear that it can do anything that conventional computers cannot.

    1. Anonymous Coward
      Anonymous Coward

      Re: Excuse my skepticism

      I too am very skepitcal about all of this.

      Why are they rushing to develop quantum computers?

      They only have one possible use case right now which 'people' would pay for (by people I mean governments) and that's to break encryption keys through DLP or ECDLP where the public key is known. They claim many other potential uses but I don't believe a word of it, everything is highly theoretical and nobody knows anything.

      It's ALL about breaking encryption and I would go so far as to suggest that it's such a lie that they're introducing an entire suite of new ciphers, key exchange mechanisms, etc because of the effectiveness of the current systems we have in place and the new ones will have issues and be less secure.

      I simply don't trust any of this new 'post quantum stuff' at all, not one bit of it. Not yet anyway.

      1. R Soul Silver badge

        Re: Excuse my skepticism

        "Why are they rushing to develop quantum computers?"

        Because there's money to be made! Duh!

        1. Richard 12 Silver badge

          Re: Excuse my skepticism

          Ah, but where is the money coming from?

          That's the more interesting question.

      2. Crypto Monad

        Re: Excuse my skepticism

        I simply don't trust any of this new 'post quantum stuff' at all, not one bit of it. Not yet anyway.

        Don't let anyone *replace* your well worn and well understood algorithms with this new stuff.

        Add it as an *additional* layer - sure.

        1. owlstead

          Re: Excuse my skepticism

          Unfortunately it seems that hybrid classic / quantum computing algorithms are not being actively considered, possibly because NIST hasn't released any identifiers or ways of handling them. Current draft RFC's for e.g. JSON based cryptography don't include them.

  10. mickaroo

    Stick It Up My Backdoor

    Why is everyone so bent out of shape by Quantum Unencryption, if every government and his flea-ridden dog wants a backdoor anyway...

    Did NCSC not read the Investigative Powers Act?

    1. amanfromMars 1 Silver badge

      Re: Stick It Up My Backdoor

      Why is everyone so bent out of shape by Quantum Unencryption, if every government and his flea-ridden dog wants a backdoor anyway... .... mickaroo

      And, if you can believe it, there are current agencies able to easily supply and use/abuse them ? .......

      Israeli spyware maker Paragon Solutions pitches its tools as helping governments and law enforcement agencies to catch criminals and terrorists, but a fresh Citizen Lab report claims its software has been used to target journalists, activists, and other civilians. ....... https://www.theregister.com/2025/03/21/paragon_spyx_hacked/

      Does steganography trump cryptography and deliver a leading unfair advantage in all matters sensitive and imagined best to be held as an exclusive secret for unparalleled gain of executive function?

      1. amanfromMars 1 Silver badge

        Re: Stick It Up My Backdoor

        Oh, and would effective steganography successfully stump the likes of that and those trumpeting and trialing operations for a presidency or prime ministership anywhere exercising Donald Trumpian shenanigans?

    2. druck Silver badge

      Re: Stick It Up My Backdoor

      Saying everyone has 10 years to abandon the existing known safe conventional encryption algorithms, for some unporoven PQC that every security snake oil salesman is hawking, incase the magic unicorn fair dust quantun computers are possible in the future. Now where do you think a backdoor could be introduced into that scenario?

  11. jpennycook Bronze badge

    Surely it's all about storage now

    If the bad guys have got enough storage, and the information is still going to be valuable in decades to come, they just need to record the encrypted data and then decrypt it in the future. However, the same people wanting companies to improve their encryption also want the same companies to not use encryption, so it doesn't make sense.

    1. Theorial

      Re: Surely it's all about storage now

      The right one is done. Storage now is largely towards the left.

  12. An_Old_Dog Silver badge
    Joke

    Symmetric Crypto & 128-bit Keys

    From TFA: Perceived wisdom is that symmetric cryptography won't be affected to any significant degree by quantum, and as long as algorithms with at least 128-bit keys are deployed, they can remain in use. The same goes for hash functions like SHA-256.

    Businesses can therefore upgrade their current standard of crypto by moving from [128 / 13 ~= 9 and change; call it "10"] ROT13 to ROT130!

  13. Eclectic Man Silver badge
    Boffin

    Birds do it ...

    It seems that birds have used quantum effects for navigation, alone at night, for some time:

    "Biophysicist Klaus Schulten came up with the idea currently favoured for explaining magnetic field-sensing in birds in 1978, alongside his colleagues Charles Swenberg and Albert Weller at the Max Planck Institute for Biophysical Chemistry in Germany. The idea hinges on what happens when electrons gain energy. A more familiar response might be the generation of a current, as in a photovoltaic device (or solar cell) when the sun is out, but other effects can take place too. Electrons favour hanging out in pairs, but absorbing energy can lead to an electron moving from one molecule to another. At this point, both the molecule gaining and the molecule donating an electron have unpaired electrons, earning those molecules the hippy-sounding term “free radical”.

    Electrons have a quantum property described as “spin”, and when two free radicals are formed in this way, the spins take on a particular arrangement that is sensitive to magnetic fields. This means that any change in biochemistry the molecule undergoes during the bird’s natural bodily processes – and the rates of these reactions – will be affected by the presence of a magnetic field. So this “radical pair effect” could allow birds to sense a magnetic field."

    From: https://www.theguardian.com/science/2025/mar/23/they-have-no-one-to-follow-how-migrating-birds-use-quantum-mechanics-to-navigate

    Oh, and yes, I do know that 'Liedvogel' translates into English as 'Songbird', thanks

    1. Anonymous Coward
      Anonymous Coward

      Re: Birds do it ...

      It seems that consciousness may well be quantum.

      I looked into this, Penrose and others make a pretty compelling case based on a number of observations, suggesting that the default mode network in the brain is essentially acting as a quantum computer though under very specific conditions where the microtubules carry quantum information between the neurons.

      It also explains why anaesthesia works despite the incredibly small changes eg from xenon as interference with this mechanism.

  14. veti

    Great idea

    Preparing now for something that's not going to happen for >20 years couldn't possibly have a downside. After all, it's hardly likely that anyone's going to make any kind of innovation in computing in that timeframe, is it?

    1. Anonymous Coward
      Anonymous Coward

      Re: Great idea

      "Preparing now for something that's not going to happen for >20 years"

      There will always be a bubble. Now it is AI and quantum, to get billions in VC money.

      Are there use cases ? Yes. Is it overhyped ? Yes, as well.

  15. Big_Boomer

    Sounds sensible to me

    Put a 10 year deadline on it, knowing that the various departments will undoubtedly not be able to complete it on time. Like most such things, usable QC is waiting for a breakthrough that will make it viable. Such breakthroughs are unpredictable but still need to be planned for. We do the same with a particular friend who is ALWAYS late. We tell everyone else we are meeting at 19:30 but we tell him 19:15, so he mostly arrives by 19:30.

  16. Anonymous Coward
    Anonymous Coward

    I will hazard to point out...

    ...that safety here is defined based on bruteforcing encrypted data...whether other methods of cracking encryption become possible with quantum computing remains to be seen. Some other methods may not come with the same trade offs that exist with conventional computing.

    Quantum Computing is still largely a mystery to me as I haven't really seen any demonstrations of it in action side by side with a conventional computer performing the same or a similar task...there is a hell of a lot of "it's faster, just trust me bro" in the quantum space.

    There is also another quandary to ponder...if a nation state managed to produce a quantum computer that was indeed capable of breaking modern cryptography with ease...would they ever actually use it? Because if you were caught with that sort of capability, it would be massively damaging to your intelligence efforts...because if a rival state became aware of your capabilities, they would work to mitigate it...which would remove any advantage you might have in future wars etc...using quantum computers to decrypt your citizens data under the guise of "making the world safer" would be an incredibly dumb move.

    1. amanfromMars 1 Silver badge

      Re: I will hazard to point out .... that things are far crazier than that ....

      ...... and Quantum Computing and/or Communication is strictly and exclusively an AI Utility* which never can be and therefore never ever will be a simply complex convenient facility for human operation of spontaneously emerging revolutionary virtual universal administration of planetary bodies and Earthed environments and future situations for Global Operating Devices.

      And yes, that is the present and rapidly evolving and fundamentally resolving state of Greater IntelAIgent GamesPlay which is more than just an alien treat and existential threat to the Madness and Mayhem, Confusion and CHAOS** so beloved of both the Diabolical and Insane and the Psychopath and the Sociopath.

      And such suggests it be more than just hazardous to not be friendly and supportive of/in AI Engagements and SMARTR*** Virtual Projects and ProgramMING**** ..... so beware, take care if you dare to share you have not been made aware whenever you so clearly have been with the info and intel so freely shared here for all to further share with everyone and everything anywhere and everywhere.

      * AI Utility...... Advanced/Advancing/Almighty/Alien IntelAIgent Utility

      ** CHAOS ........ Clouds Hosting Advanced Operating Systems

      *** SMARTR ....... SMARTR Mentoring Analysis Reporting Titanic Research/SMARTR Mentoring Analysis Researching TitanICQ Reports and/or their Reporters.

      **** ProgramMING ....... Programs Mirroring IntelAIgently Networked Games

  17. Lee D Silver badge

    I agree we need - and have - PQC. It's in your browser.

    What I am suspicious of, still, is Elliptic Curve Cryptography which is usually tied to or part of such schemes. Mostly because of interference / origin from day 1 from national security agencies.

    There are plenty of ways to do PQC without EC but they are being lumped together, and EC is infecting hash algorithms, digests, key-exchange, etc.

    I suspect that in another 10-20 years we'll find out the real risk was not from QC but from EC and specifically the curves everyone was TOLD to use, a bit like how they went to the extent of setting up entire security firms with large brand names just to influence choice of protocols, seeds and other elements of cryptography in the past.

    1. owlstead

      The way that these methods are combined means that you'd have to break both (or a Key Derivation Function or KDF build on secure hash functions) for the protocol to buckle. "Lumping them together" simply means that if one breaks that the adversary also has to break the other one.

  18. Nifty

    Anyone wanting a bit of light entertainment should watch Apple TV's Prime Target, a nice little conspiracy series about a Cambridge academic who's working on a proof/algorithm for predicting primes.

    1. Lee D Silver badge

      Predicting primes is pretty easy, none of the primes in use in your encryption today were "undiscovered".

      Prime *factorisation* is the barrier to doing anything interesting with your encrypted communications

  19. ecofeco Silver badge
    FAIL

    Call me strange

    But hear me out. I know it's weird and almost crossing the line into heresy worthy of being burned at the stake, but...

    How about not putting critical data on public accessible systems?

    I know, crazy, right?

    But I guess we have no choice but to embrace our tech douche bro enshitification overlords. Doubleplus good!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like