Post-quantum, explained

Everyone keeps saying quantum computers will break encryption. Here is what that actually means, with the jargon removed.

01 / the handshake

Two strangers agree on a secret while everyone listens

Every time you load a site with a lock icon, your browser and that server have to agree on a secret number. Neither has ever met. They do this exchange over a "wire" that anyone in the middle can read.

That sounds like it should be impossible, but it works because of math that runs easily in one direction and very badly in reverse.

YOUR BROWSER THE SERVER private private OPEN WIRE mixtures, safe to send = SAME SECRET, NEVER SENT

Anyone reading the wire sees the mixtures and none of the private values.

Picture mixing paint. Combining two colors takes a second. Looking at the finished color and precisely naming the exact Pantone number of the two that went in is brutally hard. Your browser keeps one color, the server keeps another, they swap mixtures in the open, and both end up holding the same final shade. Anyone watching the wire sees mixtures and gets nowhere.

That is the whole trick behind the lock icon. Everything after it gets scrambled with the shared secret.

02 / the machine

A quantum computer can unmix the paint

A quantum computer is a different kind of machine, not merely a faster laptop. At almost everything it is useless. At a small handful of specific math problems it is absurdly fast.

ORDINARY COMPUTER secret mixture seconds longer than the universe has existed QUANTUM COMPUTER, LARGE ENOUGH secret mixture an afternoon

The arrow that matters is the one pointing backwards.

One of those problems is the exact one holding up that handshake. A machine big enough could watch the mixtures go by and work out the secret anyway.

Nobody has built one that big. Public estimates for when range from about a decade to never. Your bank is not getting emptied this afternoon.

03 / why now

Record today, open it in 2040

Here is why, despite the fact that no known quantum computer powerful enough exists right now, this a today problem.

Scrambled traffic is trivial to copy. Someone with access to the "wire" can save the scrambled bytes now, understand none of it, and put it on a disk. Storage is cheap (well, it used to be much cheaper) and patience is free. When a capable machine finally arrives, they go back and open the old recordings.

  • TodayYou load a site. The traffic is scrambled and unreadable.
  • Same momentSomeone with access to the wire copies the scrambled bytes.
  • The next 15 yearsThe copy sits on a disk. Still unreadable. Still there.
  • Some yearA quantum machine large enough to do the job exists.
  • That afternoonToday's recording gets opened and read.

The attack starts long before the machine does.

So the real question is not when the machine shows up. It is how long your data has to stay secret. Chat messages, a week. Medical records, source code, legal files, intelligence, signing keys: decades. Anything in that second group needs stronger protection on the wire right now.

04 / the wire

Who is this person with access to the wire

Your traffic does not teleport to the server. It gets handed from one network to the next, like a package moving through sorting depots, and every depot along the way physically holds it for a moment.

you wifi ISP or work carriers server copy kept ANY HOP CAN DO THIS. NONE OF IT IS A BREAK-IN.

None of them can read your scrambled traffic today. All of them can keep a copy of it. Your provider can, and in some countries is required to. A school or employer running the network can. Whoever operates the coffee shop wifi can. So can the carrier networks in the middle, which is where governments have historically gone when they wanted a tap.

That is ordinary plumbing, and mostly nothing sinister happens. The point is that copying is easy and needs no permission.

05 / routing

And your traffic can be dragged somewhere it was never meant to go

The internet has no master map. Networks announce to their neighbors which addresses they will accept traffic for, the neighbors pass that along, and the whole thing runs on everyone believing everyone else. The protocol is called BGP. It was built in an era when the operators all knew each other.

If a network announces addresses it does not own, traffic starts flowing to it. A more specific claim beats a general one, so a small false announcement can beat the real owner's larger, correct one. This is a BGP hijack. Sometimes it is a typo by a tired engineer. Sometimes it is not.

your traffic a network on the way real owner big block attacker smaller block MORE SPECIFIC WINS. NO PROOF REQUIRED.

A real one, three weeks ago

Late August 2026, a network announced a block of addresses belonging to the hosting provider Hetzner. Those addresses ran update and billing services for a company called Softaculous, whose products include Virtualizor, software used to run virtual machines.

For roughly 33 hours across two waves, traffic for those addresses went to a machine the attacker controlled. Public routing measurements show the false route reached every one of 368 global observation points at some stage, and around 72 percent of them at peak. This was not a local glitch.

The attacker then collected a genuine certificate for those domains from Let's Encrypt. Certificate authorities prove you own a domain by connecting to it, and that check ran through the hijack as well, so the attacker passed a test they should have failed. Connections landing on the impostor showed no warning at all. Machines checking for software updates during the diversion downloaded a poisoned package.

  • 28 Aug, 20:57 UTCAn unrelated network starts announcing address space it does not own.
  • Within minutesThe false route wins, because it is more specific than the real one.
  • Hours laterA valid certificate is issued to the attacker. No browser warning anywhere.
  • Across the windowSome machines download a malicious update instead of the real one.
  • 30 Aug, 06:10 UTCThe false announcement is withdrawn. Routing returns to normal.

Softaculous and Virtualizor, August 2026, reconstructed from public routing data.

Why nothing stopped it

There is a fix for this. Address owners can sign a statement saying which network is allowed to announce their addresses, and other networks can check those signatures and drop announcements that fail. Both halves have been available for years.

Adoption has been slow on both counts. As of mid 2026 roughly two thirds of routes carry a signed statement, leaving a third with nothing to check against. Measurement studies put the share of networks that actually enforce the check at something closer to a quarter.

The deeper gap is what the signature covers. It says which network may announce the addresses. It says nothing about the route the traffic takes to get there.

THE ROUTE A NETWORK CLAIMS carrier transit attacker real owner never checked checked A HIJACK KEEPS THE REAL OWNER ON THE END

The August hijack kept the real owner's name on the end of the route and inserted itself in the middle, which is precisely the case the check was never designed to catch. The extension that would cover the rest of the route exists and sits at about two percent deployment.

This particular attacker impersonated rather than eavesdropped. The same position on the network is all you need to quietly copy traffic instead, which is the thing that matters for the previous section.

06 / the fix

New math, bolted alongside the old math

Cryptographers spent years building replacement math that quantum machines have no known shortcut against. The winner is called ML-KEM. It is a finished public standard, not a research paper.

Browsers and servers deploy it in hybrid mode. They run the old handshake and the new one, then blend both results into the secret. An attacker has to break both. If the new math turns out to have a flaw nobody spotted, the old protection is still there holding the door.

old math quantum breaks this new math ML-KEM one shared secret BREAK BOTH, OR NOTHING

If you ever see X25519MLKEM768 in a log somewhere, that is this, in one word.

This does not fix hijacking, and hijack defenses do not fix the recording problem. They are separate repairs to separate parts of the same journey.

07 / where it stands

Your side is done. The other side is the work.

Browsers already ship the new math. You do not install anything or turn anything on. If the server you are talking to supports it, the two quietly agree to use it and you never see a thing.

Servers are the slow half. A server has to be running the current version of the protocol before the new math is even reachable, and plenty of them still run older versions. Those cannot do post-quantum at all until they upgrade, no matter what anyone's roadmap says.

Email is further behind than the web, which is awkward, because email is the traffic most likely to sit in an archive for twenty years.

08 / short version

Your traffic passes through networks that can copy it, and can be pulled toward networks that should never have seen it at all. A copy taken today can be opened in twenty years. New math fixes that last part, your browser already runs it, and the servers on the other end are what is still catching up.

Nothing here needs you to do anything. It needs them to.