The assumption that you care about this is baked into ANSSI certifications, otherwise you would usually not bother certifying your product. They warned in 2022 that they would do this (See Phase 2: https://messervices.cyber.gouv.fr/guides/en-anssi-views-post...) and will allow PQC-only algorithm no earlier than 2030.
YAGNI - https://en.wikipedia.org/wiki/You_aren%27t_gonna_need_it
Even regions with few quakes may have a history of large quakes. The New Madrid region (southern Illinois, southeastern Missouri, southwestern Kentucky, northwestern Tennessee, northeastern Arkansas) doesn't experience especially frequent temblors, but when they do occur, they're doozies:
<https://en.wikipedia.org/wiki/1811%E2%80%931812_New_Madrid_e...>
The potential risks of PQC are large enough that preemptive countermeasures seem prudent.
1. https://blog.cloudflare.com/post-quantum-roadmap/ 2. https://blog.google/innovation-and-ai/technology/safety-secu...
The security industry loves to use belt and belt and braces and braces and braces. If they add an extra belt or two, I doubt anyone will remark on it at all.
In your opinion, what chance of QC would warrant PQC migration? Would you be ok with a 20% chance of everyone being caught unprepared? 30%? 50%?
Keep in mind the impact is "hackers can take control of almost all online infrastructure and forge almost any document".
The increase in complexity is a huge problem. It is arguably justifiable but simultaneously concerning. It's already quite hard to make a correct TLS implementation as it is.
(Personally though, I still like post quantum encryption. It's a nice hedge in case ECC and/or RSA do fall any time soon, whether by quantum computer or simply math.)
The problem with PQC is not that nobody knows when a CRQC (cryptographically relevant quantum computer) will appear, but that by the time it appears, you are already ~10 years too late for migrating (5 years of migration time and 5 years of your adversary silently storing all your classical crypto messages to decrypt them at a later time, the "harvest now decrypt later" attack).
Of course the HNDL attack is only relevant for the most critical pieces of infrastructures, 99% of companies are not a real target for that, especially given the storage cost of such an attack.
There is also the "trust now, forge later" attack, in which a CRQC could break a chain of trust (i.e. digital signatures), and that attack does not need any storage besides the logs of past messages. If you want to guarantee authenticity and unforgeability of your logs for, say, 20 years, you better hope that no CRQC appears by 2050 at least. Once again, it only concerns maybe 1% of companies.
But hey, these 1% companies are exactly the ones that are needing specialised crypto equipment so the move from ANSSI tracks.
I personally do not believe a CRQC will appear before 2050 either. I am willing to bet some money on it, despite researchers in quantum computers being quite confident it will appear in the next 15 years, but I am not willing to bet the entirety of Internet security on it.
From yesterday's posts: <https://news.ycombinator.com/item?id=48983610> (my comment on the Romanian land registry hacking thread).
I hate to be that guy, but I'm 52 now and I've been hearing about how Quantum Computing is going to revolutionise everything in the next two years, since I was in primary school and ZX81s were state-of-the-art.
At least a couple of manufacturers offered a practical and afforable(-ish) transputer-based system in the 80s that you could have actually gone out and bought.
But it's also very possible that hypothetical report was genuinely concerning. We just haven't seen it or anything like it.
However I'm pretty firmly in the "quantum computing won't be doing anything useful any time soon, if ever" camp, so that definitely colors my opinions. I don't have any particular recent expertise to support that, but I did used to share an office with some serious QC people and go to their talks so... make of my words what you will.
Because right now my attitudes are trained by things like this https://algassert.com/post/2500 that explain just why 15 was factored in that famous run of Shor's algorithm and not, say, 21; and why 21 hasn't been factored yet and isn't likely to be any time soon....
Not because we expect a workable quantum computer by 2030 (current estimates are around 2035-2040), but because stuff survives for decades in large enterprises (especially if it touches hardware in any way. Think OT, think controllers for all kinds of machines).
Now that PQC is standardized, there's no gain not to demand it (it's basically a demand to use a current openSSL/libreSSL/$library), but not demanding it now will cause a major headache once/if quantum computers work.
TLS connection speed matter only for a very tiny niche of applications; those will choose according to their needs. For the general case, it just doesn't matter.
If your threat model includes store-now-decrypt-later, you should have been demanding PQC for years.
For instance, breaking RSA or ECDSA is requiring much fewer logical qubits than previously thought, and thus fewer physical qubits as well. Progress in error codes, quantum processing etc. made it that in 2019, it was estimated we needed ~20 million noisy qubits to factor RSA 2048. In 2025, we know we need fewer than 1 million. [0]. Some other papers even claim the need of 1000 physical qubits but they rely on a very exotic architecture so I would not consider them feasible.
Progress on the hardware is also continuing, see [1]. Researchers managed to have functional-ish error correction for the first time last year, and experts in the topic are confident that a cryptographically relevant computer will appear in around 15 years.
I personally am less optimistic than the experts (admittedly I am not an expert either), but there is enough activity to get worried for critical infrastructure.
Regarding the factoring issue, as you point out factoring 15 and factoring 21 are two very different tasks. The first one can be used to show that your quantum computer is indeed doing quantum computation; the second will prove that you have a functional error correcting code. If you can factor 21, it is probably only a matter of months/maybe a few years until you factor RSA 2048. As Scott Aaronson said [3], "Once you understand quantum fault-tolerance, asking “so when are you going to factor 35 with Shor’s algorithm?” becomes sort of like asking the Manhattan Project physicists in 1943, “so when are you going to produce at least a small nuclear explosion?”"
[0] https://arxiv.org/abs/2505.15917
[1] https://sam-jaques.appspot.com/quantum_landscape
[2] https://globalriskinstitute.org/publication/quantum-threat-t...
The concern is systems which won't be resistant against quantum cryptographic attacks.
The US's NIST has an explainer page, "Post-Quantum Cryptography PQC":
I work at AWS, where we have been deploying Post-Quantum Cryptography for quite some time and have experts. We're making easier than ever, but the sudden changes in deadlines do make me wonder how many companies are going to have to spend more time than they'd planned on migrations and settings. The "context switch" of working on PQ can be quite expensive. Most tech people have no idea what ML-KEM, ML-DSA, or HQC are, or how to not worry about SHA, HMAC, or AES. It's going to be a ride!
You mean the opposite. PQC-free will be blocked, so by 2030 all products will be PQC qualified.