Stickybit.PortuguêsPost-quantum · cryptography · 2026
Post-quantum

Today's padlock has an opening date.

Almost every secure connection depends on a kind of lock that a large quantum computer can open. It does not exist yet. But whoever records your encrypted traffic today can open it later, so the question is not only "when does it arrive" but "how long does your secret need to last".

Specimen · your secret against the clock

0years of exposure
0last data under the old lock must last until
0days to Jan 2029

Third-party estimates, not our measurement: 2029 is the deadline Filippo Valsorda began defending in 2026, citing Google executives; 2035 was his earlier position. The math is Mosca's rule: if the time the secret must last plus the time to migrate goes past Q-Day, data encrypted today is already exposed. 20 years is the minimum retention for electronic medical records in Brazil.

In everyday life

Photocopying sealed letters and waiting.

Picture someone who photocopies, every day, the sealed letters going through the post. Today they can't read any of them: the seal holds. But they keep everything in a drawer, because they know that one day a tool will appear that opens that kind of seal. When it does, letters from years ago open too.

That is exactly what is called "store now, open later". The seal is public-key cryptography, the kind that agrees on the password for each secure connection (the browser padlock, payment systems, open banking, the VPN). The tool is a large enough quantum computer, which does not exist yet.

So the deadline that matters to your company is not the day the machine switches on (Q-Day). It is that day minus how long your data must stay secret, minus how long you take to change the locks. A medical record that must stay secret for 20 years, encrypted today, is already on the wrong side of any estimate.

today Q-Day recorded under today's lock the drawer opened migration recorded under the new lock stays closed ✓
What is recorded today under the old lock can be opened on Q-Day. Data encrypted under the new lock cannot.
What breaks

Not all cryptography is in the crosshairs.

There are two kinds of lock. The public-key kind has a part everyone sees, like an open padlock hanging for anyone to lock, and a secret part that opens it. It agrees on passwords and signs documents: RSA, ECDH, ECDSA and the secp256k1 behind Bitcoin wallets. A large quantum computer can work out the secret part from the public one (Shor's algorithm). These break.

The shared-secret kind (AES-256 to encrypt, SHA-256 for fingerprints) has no public part to attack. The best known quantum shortcut only halves its strength, and AES-256 keeps plenty of margin. These hold.

In practice, migrating means replacing public-key locks with the new ones NIST standardized in 2024: ML-KEM to agree on passwords and ML-DSA to sign, ideally alongside the old ones during the transition.

BreaksHoldswith a quantum computereven with oneRSApasswords, signaturesECDHthe HTTPS padlockECDSAdigital signaturesecp256k1crypto walletsAES-256encrypting contentSHA-256fingerprintsHMACpassword sealML-KEM · ML-DSAthe new locksReplace →Keep ✓
The migration only touches the left column. The right one already resists, including the new locks.
When

Nobody knows the date. The estimates got shorter.

There is no measurement of Q-Day, only estimates, and they come from people with different positions. What changed in 2026 was the direction: two studies (one from Google, with superconducting qubits, and one from Oratomic, with neutral atoms) indicated that 256-bit elliptic curves, the ones behind HTTPS and Bitcoin, fall with far less machine than previously calculated.

The section

Changing the locks, where to start.

From estimate to code: the deadline and the assessment, the regulation that should arrive, the inventory of what must change, the identity of devices that stay decades in the field, and what we measured encrypting telemetry with the new locks.

The other front

Computing without opening: the same kind of math.

The new locks rest on a mathematical problem, lattices, that also enables something that sounds impossible: computing on data that stays encrypted the whole time (FHE). A hospital adds up results without seeing patients; a bank computes risk without receiving the customer's data. We measured on our bench what is usable today and where it is still expensive.

24-hour assessment · free

Where are your old locks?

You tell us which algorithms you use and where. We reply within 24 business hours with a short report: what is critical, the next 90 days' roadmap and an effort estimate. No sales pitch.

  • Secure connections and APIs (open banking, payments, partners)
  • Certificates whose validity reaches into the risk window
  • Long-retention data (health, contracts, legal)
  • Server access keys and login tokens
  • Blockchain wallets and identities
Three words from this page
Q-Day

The day the first quantum computer able to break today's cryptography switches on. Only estimates exist.

Store now, open later

Recording encrypted traffic now to read it on Q-Day. That is why the problem has already begun.

Swap the lock, keep the door

Systems built to change algorithm through configuration. Useful to migrate now and again, if needed.

Limits

Where this could be wrong.

The dates are estimates

No Q-Day number on this page is our measurement. The sources disagree and move; we show whose each one is.

The new locks are young

Every so often a claimed break of lattices appears; the 2024 one fell apart in about eight days. In July 2026, an AI model found the attack that removed HAWK, a candidate signature, from the NIST process; the ML-KEM and ML-DSA standards were not affected. That is why we recommend migrating with both locks together.

Signatures are harder than key exchange

The new signatures are much larger. In certificates, smart cards and small channels (satellite, sensors) they do not always fit, and identity migration lags behind.

BACEN in 2028 is our reading

No resolution has been published. We explain the reasoning on its own page, so you can agree or disagree on the merits.

See also

← stickybit.com.br · Glossary · 24-hour assessment

Sources