Illustration of a quantum computer connected to encrypted messages, computer networks, and clocks.
|

The Messages That Waited

Quantum computers powerful enough to break modern encryption may still be years away. Yet the race to defend against them began decades ago, because this is not the first time messages have survived longer than the security meant to protect them.

In February 1943, inside a commandeered girls’ school in Arlington, Virginia, a former home economics teacher from Kentucky named Gene Grabeel began organizing and analysing  stacks of intercepted Soviet telegrams. She could not read them. No one could.

The messages had been encrypted using one time pads, a system that is mathematically unbreakable when used correctly. To the cryptanalysts studying them, the telegrams offered no patterns, weaknesses, or clues. They were little more than noise. The Army kept them anyway.

Over the next three years, cryptanalysts at Arlington Hall discovered that some Soviet one time pads had been accidentally duplicated during wartime production. It was precisely the kind of mistake the system was designed to make impossible.

In late 1946, a quiet linguist named Meredith Gardner turned that mistake into a breakthrough. By painstakingly reconstructing parts of the Soviet codebook, he began drawing meaning from what had appeared to be random static.

The fragments revealed more over time. In the decades that followed, American codebreakers identified spies including Klaus Fuchs, the physicist who passed atomic secrets to Moscow, Julius Rosenberg, and Donald Maclean of the Cambridge spy ring. The project, eventually codenamed Venona, continued until 1980. Some of the people it exposed were identified through telegrams sent while Franklin Roosevelt was still president. The messages had simply waited for mathematics and cryptanalysis to catch up.

Venona is usually told as a spy story. It is more useful as a warning. It reveals something about encryption that is easy to overlook. Interception and decryption are separate events, and decades may pass between them.

A message does not have to be readable when it is stolen. It only has to be kept. That is happening again now, on a scale the filing clerks at Arlington Hall could not have imagined.

The Algorithm That Arrived Thirty Years Early

In 1994, a Bell Labs mathematician named Peter Shor demonstrated that a quantum computer could efficiently factor enormous numbers. At the time, quantum computers were little more than a theoretical possibility, with researchers only beginning to coax a few qubits into existence. The result sounded obscure. In reality, it placed a delayed explosive beneath the foundations of the internet.

Modern public key encryption depends on mathematical problems that ordinary computers find extraordinarily difficult. RSA relies on factoring large numbers. Other widely used systems rely on a related problem known as the discrete logarithm.

These problems allow two strangers, such as your laptop and your bank, to establish a secret over a connection that anyone could be listening to. That initial exchange creates the key used to protect everything that follows.

Break the exchange, and you have not opened a single lock. You have recovered the key to the entire conversation.

Shor’s algorithm showed how a quantum computer could do exactly that. There was only one obstacle. No machine powerful enough to run it existed. It still does not. Today’s quantum computers contain hundreds or, in some cases, thousands of noisy and error prone qubits. Breaking modern encryption would require far more capable machines, potentially using millions of physical qubits together with error correction systems that researchers are only beginning to demonstrate at meaningful scales. Estimates for when such a machine might arrive range from the 2030s to perhaps never.

That raises an obvious question. Why prepare urgently for a weapon that may not exist for years?

Gene Grabeel’s filing cabinets provide the answer.

Harvest Now, Decrypt Later

Storage is cheap. Encrypted internet traffic still passes through cables and exchange points that intelligence agencies can tap. Any adversary who believes a powerful quantum computer may one day exist has an obvious move. Record the traffic now, store it, and wait. The strategy is known as “harvest now, decrypt later.” Western security agencies have said plainly that they assume it is already happening. Of course they do. It is what they would do. In the 1940s, it is what they did.

This reverses the timeline most people instinctively imagine. The natural question is when quantum computers will arrive. But that is the wrong place to begin. The real calculation starts with how long the information must remain secret. A credit card number may matter for only a few years. Medical records can matter for a lifetime. The identities of intelligence sources, weapons designs, and diplomatic communications may need protection for half a century.

Then comes another question. How long will it take to replace today’s encryption with systems that a quantum computer cannot break? As we will see, the honest answer may be a decade or more.

Now compare those two periods with the possible arrival of a cryptographically powerful machine. If the lifetime of the secret, combined with the time required to protect it, extends beyond the years we may have left, then the danger does not begin when the quantum computer arrives. It begins when the encrypted data is intercepted.

For information that must remain confidential into the 2040s, and that is travelling across networks today under encryption a future quantum computer could break, the breach may already have happened. It simply has not been read yet.

The Venona cables remained secure for three years before Gardner made his first breakthrough, and for decades before investigators uncovered everything they could. Security that expires retroactively is not security.

It is a countdown you cannot see.

Breaking Things in Public

Cryptographers read Shor’s paper too. For the past thirty years, they have been building replacements based on mathematical problems that quantum computers are not known to solve. Many of them rely on high dimensional geometric structures called lattices. The challenge was never finding possible replacements. It was deciding which ones deserved to be trusted.

In 2016, the United States National Institute of Standards and Technology launched a global competition to answer that question. The process it chose reveals how confidence in cryptography is actually built. Dozens of teams submitted algorithms. Then cryptographers around the world spent years trying to break them. The work happened publicly and on the record, with every successful attack offering a chance to expose a weakness before the algorithm became part of the world’s infrastructure.

The attacks came. In early 2022, a cryptographer named Ward Beullens broke Rainbow, one of the finalists for digital signatures. He did it over a weekend using a laptop.

A few months later, an even stronger candidate collapsed. SIKE was an elegant system that had survived five years of scrutiny and advanced deep into the competition. Two Belgian researchers, Wouter Castryck and Thomas Decru, defeated it using mathematics published in the 1990s that the field had overlooked.

Their attack recovered a secret key in about an hour using a single ordinary processor core. No quantum computer was needed. No supercomputer was needed. Just a laptop and a theorem almost everyone had forgotten.

It is tempting to see these collapses as failures of the competition. They were the opposite. They were the reason the competition existed. Every algorithm that failed in public was one that would not fail a decade later, after governments, banks, hospitals, and billions of devices had begun depending on it.

By 2024, the surviving algorithms had endured years of concentrated attack, and NIST finalized its first post quantum cryptography standards. The new systems did not require exotic machines. They could run on the ordinary hardware already inside phones, laptops, and servers. The transition had already begun. Chrome and Signal started protecting connections with hybrid encryption, combining new algorithms with older ones so that an attacker would need to defeat both. Apple rebuilt the security of iMessage around the same principle.

None of this required a powerful quantum computer to exist. The possibility of one was enough. Given that encrypted information can be collected today and decrypted years later, possibility is exactly the right trigger.

Where the Encryption Lives

The replacement mathematics exists. It has been standardized, it is freely available, and it runs on ordinary computers. This is where a reasonable person might conclude that the problem is mostly solved. It is where the problem actually begins.

Cryptography is not a product that an organization can simply upgrade. It is sediment. Over decades, it settles into every layer of a system, often so deeply that nobody remembers it is there.

Ask a large bank where its encryption lives and the question quickly becomes difficult to answer. There is the visible layer, including the padlock icons and certificates protecting public websites. Beneath it are virtual private networks, remote access keys, and the hardware security modules that guard payment systems. Go deeper and the list keeps growing. There are keys that authenticate software updates, tokens that preserve user sessions, encrypted databases, backup tapes, smart cards, ATM networks, and message formats negotiated with other banks decades ago. Some of this technology runs on mainframes executing code written by people who have long since retired.

No single person knows where all of it is. Until now, nobody needed to. That is why the first step in any migration is not replacing the encryption. It is discovering where the encryption exists. Building a complete inventory can take a large organization years, and that is considered the easy part.

Some systems are even harder to reach. Satellites in orbit carry the cryptography they had when they left Earth. Cars sold today may remain on the road for fifteen years, possibly long enough to encounter machines their security was never designed to withstand. Medical implants, smart meters, and industrial controllers inside power plants are built to operate for decades, often with their encryption embedded directly into the hardware.

Some of these devices can receive remote updates. But the update channels are themselves protected by digital signatures. A sufficiently powerful quantum computer might therefore do more than read the information passing through a device. It could impersonate the manufacturer and send a malicious update that the device would accept as authentic.

The mechanism meant to repair the system depends on the same cryptography that needs to be replaced.

The scale of the migration reflects this complexity. The United States government has directed federal agencies to remove vulnerable cryptography by 2035. Estimates for civilian agencies alone reach into the billions of dollars.

Even that timeline may be ambitious. The previous major transition involved retiring SHA 1, a single weakened hash function. That process took well over a decade, and some systems continued using it long after the danger was understood.

The obvious comparison is Y2K, but the difference matters more than the similarity. Y2K had a date printed on the calendar. That made the threat easy to explain, easier to fund, and impossible to postpone forever. The transition to quantum resistant encryption has no deadline anyone can name with confidence. That uncertainty makes delay feel reasonable, even when it is not. For information that must remain secret for decades, the effective deadline may already have passed.

Y2K was a sprint toward a known date. This is a marathon away from an unknown one. Every year of delay adds another year of encrypted traffic to someone else’s warehouse.

 The Bet

The skeptic deserves a direct answer. The machine may never arrive. Quantum computing has a long history of promises that remain just beyond reach, and the engineering obstacles are real. Error correction remains the largest of them. Recent milestones have shown that adding more qubits can sometimes reduce errors rather than compound them, but these experiments are still vastly smaller than the machines needed to break modern encryption. Perhaps useful quantum computers will remain fifteen years away for the next fifty years, as fusion power often has.

But consider the shape of the bet. Migrating early costs time, money, and engineering effort. Those costs are substantial, but they are visible and limited. Migrating late could expose decades of recorded communications all at once. By then, no emergency patch could recover them. The copies would have left their owners years earlier and might already be sitting in someone else’s archive.

One side of the wager is costly but bounded. The other is irreversible. You do not need to believe the most optimistic predictions about quantum hardware. You only need to accept that the future is uncertain. No serious person can claim otherwise.

There is also a version of this argument that requires no quantum computer at all.
The Venona cables were not broken by a revolutionary machine. They were broken because one time pads had been duplicated and a patient linguist found a way through the mistake. SIKE was not defeated by quantum hardware. It was defeated using mathematics that had existed for thirty years, waiting for someone to recognize its relevance.

The deeper lesson is that encryption is not a permanent quality that a message possesses. It is a prediction. It is a claim about what every person who may ever obtain a copy will be capable of doing, for as long as the contents remain valuable.

Quantum computing is unusual only because it announced the threat decades in advance. The attacks that give no warning are the ones security officers should fear most.

The Archive Is Patient

There is one final scene from Arlington Hall worth remembering. In 1946, Meredith Gardner was working through the reconstructed Soviet codebook. Among the messages he examined was a cable identifying scientists inside the atomic bomb project. A colleague would sometimes stop at his desk, watch him work, and take a friendly interest in his progress.

His name was William Weisband, and he was a Soviet agent.

Weisband’s warnings reached Moscow. In 1948, the Soviets abruptly replaced their communications systems, and the new traffic went dark. American codebreakers called the moment Black Friday. But the change came too late. The new systems protected messages that had not yet been sent. They could do nothing about the thousands of older cables already sitting inside American archives. Those messages continued revealing secrets for another three decades. Fuchs, the Rosenbergs, and Maclean were all exposed through traffic intercepted before the Soviets repaired the weakness.

Migration protects the future. It cannot recover the past.

Gardner appears to have understood the weight of this better than most. By the accounts of people who knew him, he was a gentle and scholarly man. He read the private words of people who believed they were speaking into silence, and reportedly took little satisfaction in the consequences that followed. The people who wrote those telegrams had made a reasonable assumption. What could not be read, they believed, would never be read.

They were not speaking into silence. They were speaking into a filing cabinet.

Somewhere today, data centres are playing the same role as Arlington Hall. Racks of drives hold encrypted traffic that nobody can yet read. The institutions collecting it have long memories, large budgets, and every reason to wait for mathematics to catch up. The machine they are waiting for may arrive in fifteen years. It may arrive in thirty. It may never arrive at all. The archive does not care. Archives are patient.

That is why the race does not begin on the day a powerful quantum computer switches on. It is already underway. Two slow processes are moving at once. The world is replacing the encryption that quantum computers may eventually break. At the same time, unknown institutions may be accumulating everything that the old encryption still protects.

Black Friday reveals where the finish line really lies. It is not the day the machine arrives. It is the day the last long lived secret stops travelling under mathematics that the machine could undo. Everything intercepted before that day remains inside the archive.

For any secret that must outlive the uncertainty, the deadline is not somewhere in the 2030s.

It was the moment the message was sent.

Leave a Reply

Your email address will not be published. Required fields are marked *