intermediate · Interactive lab
Harvest Now, Decrypt Later
Traffic captured today can be opened whenever the capability arrives, so the clock started when the data was sent. Three numbers decide each asset — and two of the seven here are not exposed at all.
By the end: Do Mosca's arithmetic on an asset: how long it must stay safe, how long its migration takes, and what that sum means against a range.
Your challenge
Start here. This lab opens with every asset marked as having time, which is the wrong starting point and the position most estates are actually in. Two of these are already late, two are not exposed at all, and two land inside the range and need a conditional answer. Read the arithmetic on each row and say what the plan should record.
See it happen
Three numbers per asset

- The asset → Exposure
- Exposure → The range
- The range → What the plan says
The clock started already
The asset arrives with two durations, and Exposure decides whether either of them matters. Watch the bars: protection, migration, their sum, and what is left of the range.
Learn more
Why this pattern exists
An attacker does not need a quantum computer today to benefit from one later. Capture the traffic now, store it, and open it when the capability arrives: harvest now, decrypt later. That single sentence moves the deadline from whenever a machine is built to whenever the data was first sent, and it is why this is the one quantum topic with a date attached. The arithmetic is Mosca's: add how long the data must stay confidential to how long the migration would take, and compare that sum to the headroom anybody credibly claims. If the sum is larger, the decision has already been made — badly. The second half of the lesson is the opposite error. Symmetric encryption at a long key length is not meaningfully threatened, and data with no confidentiality requirement is not threatened at all. A migration budget spent on those is a budget the exposed systems do not get.
Seven assets from an ordinary enterprise estate. For each one the bench adds the years it must stay safe to the years its migration would take, and puts that sum against an estimated 8–15 years of headroom. No date is claimed anywhere: an asset that lands inside the range has a conditional answer, and saying so is part of the answer.
- Do Mosca's arithmetic on an asset: how long it must stay safe, how long its migration takes, and what that sum means against a range.
- Tell exposure apart: public-key key exchange, long-lived signatures, symmetric encryption and no confidentiality requirement.
- Report a conditional answer as conditional, instead of turning a range of estimates into a date.
The rule this lesson applies: Three numbers decide an asset, and only two of them are yours. How long the secret has to hold and how long your migration takes are facts about your estate; when the capability arrives is an estimate, and it is a range. Mosca's inequality says that if the first two added together exceed the third, the exposure is already in force — and for harvestable traffic it is in force retroactively, because the archive is being filled now. That is why long-lived confidential data over a public-key key exchange is the first thing to move, and why a signature that must stay unforgeable for the fifteen-year life of a device in the field is on the same list for a different reason: nothing is harvested, but a forgery accepted later is just as bad, and the device cannot be updated. Two things are not on the list. Symmetric encryption at 256 bits loses half its effective length to Grover and remains far out of reach, and data with no confidentiality requirement has nothing to lose. The practical answer to all of it is crypto-agility: knowing where every algorithm lives, and being able to change one without a two-year project — which is the capability most estates are actually missing, and it is worth building before any particular algorithm is chosen. This lesson names no vendor, no product and no year; it reasons with a range of published estimates and the arithmetic they feed.

