It is the attack that makes quantum computing a problem today. An attacker records encrypted traffic or steals encrypted data now, stores it, and decrypts it years later once a quantum computer can break the RSA or elliptic-curve cryptography that protected it. The data does not need to be broken today to be lost today.
Who would do this?
Collecting and storing encrypted traffic is cheap, and storage keeps getting cheaper. Government agencies in several countries have warned that well-resourced adversaries are already doing it, targeting data with long-term value: government and military communications, health records, financial data, intellectual property and trade secrets.
Is my data at risk?
Ask how long it has to stay secret. A useful rule of thumb, often called Mosca's inequality: if the time your data must stay secret plus the time it will take you to migrate is longer than the time until a cryptographically relevant quantum computer exists, you are already late.
Some examples:
- Session data that is worthless tomorrow is at low risk.
- Medical records, legal documents and long-lived credentials that must stay private for ten years or more are at high risk now.
- Anything protected only by RSA or elliptic-curve key exchange in transit — TLS, VPNs, SSH — can be recorded today.
Does this affect digital signatures?
Less directly. A signature only has to hold until it is checked, so an attacker cannot go back in time and forge yesterday's login. Long-lived signatures are the exception: firmware signing keys, root certificates and signed documents that must stay trustworthy for years all need to move to post-quantum signatures (ML-DSA or SLH-DSA) in good time.
What protects against it?
Moving key exchange to a post-quantum algorithm — ML-KEM, usually in a hybrid with X25519 at first — so that traffic recorded from now on cannot be decrypted later. Symmetric encryption with 256-bit keys (AES-256) already holds up. See What is ML-KEM?
Where do I start?
Find where your data is protected by quantum-vulnerable key exchange, and start with what is exposed to the internet and holds the longest-lived secrets. Qopanza inventories the RSA and elliptic-curve cryptography across your code, dependencies, TLS endpoints and cloud accounts, and ranks it by exposure, so the first things you migrate are the ones an attacker could be recording today. Read how to migrate or start at qopanza.com.