1. The Quantum Threat: Shor's Algorithm
Classical computers solve mathematical problems by checking states sequentially. Quantum computers, leveraging superposition and entanglement, explore massive solution spaces concurrently.
In 1994, Peter Shor published a quantum algorithm capable of computing discrete logarithms and factoring large integers in polynomial time ( O((log n)^3) ). When a fault-tolerant quantum computer of sufficient size is built, RSA, Diffie-Hellman, and standard Elliptic Curve cryptography will be compromised instantly.
2. The 'Harvest Now, Decrypt Later' Danger
Why should we worry about a threat that is years away? Because of HNDL (Harvest Now, Decrypt Later) attacks. Adversaries and intelligence agencies are intercepting and storing petabytes of encrypted HTTPS traffic today. When quantum computers arrive, they will retroactively decrypt and inspect this archived traffic.
3. How Many Qubits Are Needed to Break RSA-2048?
Breaking a 2048-bit RSA key requires approximately 4,000 logical, error-corrected qubits (or several million physical noisy qubits). As of 2026, leading quantum hardware laboratories have demonstrated noisy systems with roughly 1,000 physical qubits, meaning fault-tolerant cracking remains several years away.
4. NIST's New Post-Quantum Champions (ML-KEM / Kyber)
To defend global communications, NIST completed a rigorous 8-year international competition and standardized lattice-based post-quantum algorithms:
- ML-KEM (Module-Lattice Key Encapsulation Mechanism, formerly CRYSTALS-Kyber): The official replacement for RSA and ECDH key exchange.
- ML-DSA (Module-Lattice Digital Signature Algorithm, formerly Dilithium): The primary standard for digital certificates and signatures.
5. What Should Developers Do Today?
- Adopt Hybrid Key Exchange: Modern TLS 1.3 implementations (e.g. in Cloudflare, Chrome, and OpenSSH) now support hybrid
X25519 + ML-KEM-768key agreements. - Maintain Minimum RSA-2048/3072: Ensure all legacy RSA keys use at least 2048 bits with secure OAEP/PSS padding.
- Follow Crypto Agility Best Practices: Build modular key management so algorithms can be swapped with configuration flags rather than code rewrites.
Written by Marcella Thorne
Marcella advises fintech startups and cloud providers on PKI infrastructure, TLS certificate rotation, and post-quantum migration.