Q-Day: Worse Than Y2K Because the Unknowns Are Unknown
Y2K had a known date, known impact, and a $300 billion price tag. Q-day has none of those. We do not know when quantum computers will break encryption. We do not know how many of the 60 billion applications using asymmetric encryption actually protect PII. We cannot estimate the cost to fix everything. That makes Q-day worse.
Superposition and Entanglement: The Two Concepts You Need
Quantum computers use cubits that can be in two states at once, called superposition. Electrons can spin up and down simultaneously. Entanglement links two particles so that one’s state instantly determines the other’s, even at a distance. Coherence time is how long cubits stay in superposition. Noise and EMI limit coherence time. That is why we lack enough noise-free cubits to break encryption.
The Real Threat: Collect Now, Decrypt Later
Attackers can store encrypted data today and decrypt it when quantum computers mature. Long-shelf-life data like SSNs, dates of birth, and mother’s maiden names are at risk. A blog by Mike Maglin claimed China is actively collecting data for later decryption. An FBI report said China’s target was 2040 but AI focus delayed it to 2049. The threat is real even if cubits are years away.
Why Cryptography Upgrades Take Decades
MD5 was first attacked in 2004 but remained in use until 2015. SHA-1 was cracked in 2005 and is still not gone. Backward compatibility forces companies to keep old algorithms. Hardcoded keys and lack of regular upgrades slow migration. Windows had 50 different MD5 implementations from Windows 3 to Windows 10. Once cryptography is embedded, it stays forever.
Crypto Agility: The Only Way to Survive Q-Day
The solution is cryptographic agility. Start with an inventory: create a cryptography bill of materials (C bomb). Label data by risk: PII, high-risk, low-risk. Create a roadmap. Implement and test. Repeat the cycle. Benefits include no vendor lock-in, easy algorithm swapping, and compliance with PCI DSS, HIPAA, DORA. NIST recommends upgrading all systems by 2030 and reaching full PQC by 2035.
PQC Algorithms and Hybrid Encryption: How to Implement Now
Two approaches: quantum cryptography (expensive, limited range) and math-based PQC. Math-based PQC uses lattice, code, hash, or multivariate problems. Lattice-based is NIST’s leading candidate. Hybrid encryption combines PQC with traditional RSA or ECC. Methods include XOR, concatenation, KDF, and wrapper. Hybrid doubles key size and slows applications but improves security. NIST released final four algorithms in August 2024.
Notable Quotes
The problem that we have right now, right, we don’t know any of these three factors because we don’t know uh when it will happen for sure Sandip Dholakia · ▶ 5:15
collect the data now decrypt it later Sandip Dholakia · ▶ 19:14
if you don’t understand all this right you are not alone Sandip Dholakia · ▶ 11:07
NIST actually says that you should start upgrading everything by no later than 2030 and you should be on 100% PQC by 2035 Sandip Dholakia · ▶ 43:01
Key Takeaways
- Q-day is worse than Y2K because the date, impact, and cost are unknown.
- Attackers can collect encrypted data now and decrypt it later with quantum computers.
- Crypto agility and NIST’s 2030/2035 timeline are essential for survival.