Why public-key cryptography is exposed
Shor’s algorithm can factor large integers and solve discrete-logarithm problems efficiently on a fault-tolerant quantum computer. Those mathematical problems underpin RSA and widely used elliptic-curve cryptography.
Why symmetric encryption is different
Quantum search gives a smaller speedup against symmetric keys. Larger key sizes can compensate more directly, so AES-style encryption is not threatened in the same way as RSA or ECC.
NIST has already standardised replacements
NIST finalised its first post-quantum cryptography standards in 2024, giving organisations algorithms designed to resist known quantum attacks while still running on ordinary computers.
Why migrate before the machine arrives
Encrypted data can be captured now and decrypted later if a powerful quantum computer becomes available. Long-lived secrets, certificates and infrastructure therefore need transition time before the threat is operational.
Research record
NIST — first post-quantum cryptography standards approvedNIST · open sourceNIST Post-Quantum Cryptography projectNIST · open sourceNIST FIPS 203Standard · open sourceWill Quantum Computers Break Today’s Encryption?
Direct answer: A cryptographically relevant fault-tolerant quantum computer could break much of today’s public-key cryptography. Such a machine does not yet exist, but waiting for it before migrating would be poor risk management.
Future threat, present migration. Post-quantum standards are now an engineering requirement, not science fiction.