Skip to content
Quantum

intermediate · Interactive lab

Harvest Now, Decrypt Later

Traffic captured today can be opened whenever the capability arrives, so the clock started when the data was sent. Three numbers decide each asset — and two of the seven here are not exposed at all.

By the end: Do Mosca's arithmetic on an asset: how long it must stay safe, how long its migration takes, and what that sum means against a range.

Your challenge

Start here. This lab opens with every asset marked as having time, which is the wrong starting point and the position most estates are actually in. Two of these are already late, two are not exposed at all, and two land inside the range and need a conditional answer. Read the arithmetic on each row and say what the plan should record.

See it happen

Three numbers per asset

Clock: inside the range
Slowed down so you can follow
SOURCE|+⟩and a coin in a boxBENCHDETECTORZ BASISanswers 0 and 1TALLYTHE QUBITTHE COIN
An asset arrives with two durations: how long it must stay safe, and how long its migration would take. The clock adds them, and the horizon compares that sum to the range of estimates for when a quantum attacker could open it.
  1. The asset → Exposure
  2. Exposure → The range
  3. The range → What the plan says
STEP 1 / 6

The clock started already

The asset arrives with two durations, and Exposure decides whether either of them matters. Watch the bars: protection, migration, their sum, and what is left of the range.

Configure

Your reading of each asset

For each asset, say where it stands. The two durations and the exposure are on the row; the range is an estimate, and it stays an estimate.

Where does this asset stand?
Already late
· The sum exceeds even the longer estimate.
Late if the early estimate holds
· It lands inside the range: conditional, and the plan should say so.
There is time
· The sum fits comfortably inside the range.
Not exposed
· A quantum attacker gains nothing here.
  1. A-901 — TLS on the public marketing site

    Session traffic for a site that publishes everything it serves.

    Must stay safe for
    0 years
    Migration would take
    2 years
    Sum against the range
    2 years against an estimated 8–15 years of headroom
    Exposure
    No confidentiality requirement beyond the moment
  2. A-902 — Patient records in transit, RSA key exchange

    Thirty years of confidentiality by law, and the traffic crosses a public network.

    Must stay safe for
    30 years
    Migration would take
    5 years
    Sum against the range
    35 years against an estimated 8–15 years of headroom
    Exposure
    Public-key key exchange — traffic captured today can be opened later
  3. A-903 — Card data in transit, one-year retention

    The same key exchange, a much shorter secret.

    Must stay safe for
    1 year
    Migration would take
    5 years
    Sum against the range
    6 years against an estimated 8–15 years of headroom
    Exposure
    Public-key key exchange — traffic captured today can be opened later
  4. A-904 — Firmware signing for devices with a 15-year life

    Signatures, not secrets; the devices in the field cannot be reached to update them.

    Must stay safe for
    15 years
    Migration would take
    4 years
    Sum against the range
    19 years against an estimated 8–15 years of headroom
    Exposure
    Signatures that must stay unforgeable for the life of the thing they sign
  5. A-905 — Nightly backups under 256-bit symmetric encryption

    Ten years of retention, and no public-key algorithm involved in the encryption itself.

    Must stay safe for
    10 years
    Migration would take
    2 years
    Sum against the range
    12 years against an estimated 8–15 years of headroom
    Exposure
    Symmetric encryption at a long key length — Grover halves it and it is still ample
  6. A-906 — Site-to-site VPN carrying four-year commercial secrets

    Public-key key exchange, and a migration held up by the appliances at both ends.

    Must stay safe for
    4 years
    Migration would take
    5 years
    Sum against the range
    9 years against an estimated 8–15 years of headroom
    Exposure
    Public-key key exchange — traffic captured today can be opened later
  7. A-907 — Legacy document store, three-year confidentiality

    A bespoke application nobody wants to touch, which is why its migration is the longest here.

    Must stay safe for
    3 years
    Migration would take
    6 years
    Sum against the range
    9 years against an estimated 8–15 years of headroom
    Exposure
    Public-key key exchange — traffic captured today can be opened later

Two durations and an exposure decide it. The range of estimates is not a date, and an asset that lands inside it has a conditional answer.

Learn more

Why this pattern exists

An attacker does not need a quantum computer today to benefit from one later. Capture the traffic now, store it, and open it when the capability arrives: harvest now, decrypt later. That single sentence moves the deadline from whenever a machine is built to whenever the data was first sent, and it is why this is the one quantum topic with a date attached. The arithmetic is Mosca's: add how long the data must stay confidential to how long the migration would take, and compare that sum to the headroom anybody credibly claims. If the sum is larger, the decision has already been made — badly. The second half of the lesson is the opposite error. Symmetric encryption at a long key length is not meaningfully threatened, and data with no confidentiality requirement is not threatened at all. A migration budget spent on those is a budget the exposed systems do not get.

Seven assets from an ordinary enterprise estate. For each one the bench adds the years it must stay safe to the years its migration would take, and puts that sum against an estimated 8–15 years of headroom. No date is claimed anywhere: an asset that lands inside the range has a conditional answer, and saying so is part of the answer.

  • Do Mosca's arithmetic on an asset: how long it must stay safe, how long its migration takes, and what that sum means against a range.
  • Tell exposure apart: public-key key exchange, long-lived signatures, symmetric encryption and no confidentiality requirement.
  • Report a conditional answer as conditional, instead of turning a range of estimates into a date.

The rule this lesson applies: Three numbers decide an asset, and only two of them are yours. How long the secret has to hold and how long your migration takes are facts about your estate; when the capability arrives is an estimate, and it is a range. Mosca's inequality says that if the first two added together exceed the third, the exposure is already in force — and for harvestable traffic it is in force retroactively, because the archive is being filled now. That is why long-lived confidential data over a public-key key exchange is the first thing to move, and why a signature that must stay unforgeable for the fifteen-year life of a device in the field is on the same list for a different reason: nothing is harvested, but a forgery accepted later is just as bad, and the device cannot be updated. Two things are not on the list. Symmetric encryption at 256 bits loses half its effective length to Grover and remains far out of reach, and data with no confidentiality requirement has nothing to lose. The practical answer to all of it is crypto-agility: knowing where every algorithm lives, and being able to change one without a two-year project — which is the capability most estates are actually missing, and it is worth building before any particular algorithm is chosen. This lesson names no vendor, no product and no year; it reasons with a range of published estimates and the arithmetic they feed.