🔐 Technology

Harvest today, decrypt tomorrow

"Harvest Now, Decrypt Later": the quantum computer does not break encryption yet, but we are already storing our secrets to read them one day. And the same trove of data opens two opposing futures.

Break RSA-2048
< 1 week
with fewer than a million qubits, 2025 estimate, against 20 million and 8 hours in 2019
Mosca's theorem
X + Y > Z
if the confidentiality lifespan plus the migration time exceeds the delay before the machine, the secret is already lost
Quantum threat Encryption Data Surveillance Privacy

A secret stolen today does not need to be readable today. It is enough to store it and wait for the machine, or the artificial intelligence, that will decrypt it. This time asymmetry has a name in English: "Harvest Now, Decrypt Later". It holds for encryption as for the political meaning of a piece of data. And the same trove that we accumulate without sorting opens two futures: absolute comfort, or a surveillance where even thinking becomes risky.

1 The phrase that says it all

Four words that sum up the whole threat.

Harvest Now, Decrypt Later
Harvest now, decrypt later
The phrase, established in the cybersecurity world, describes a patient strategy: capture encrypted data today, unreadable today, store it, and bet on the machine that will make it readable tomorrow. It is also found in the form "store now, decrypt later". The dreaded day when a quantum computer breaks today's encryption even has its nickname: "Q-Day". The idea overturns an intuition: a secret can be lost years before it is read. It need only have been harvested.
This is no novelist's fantasy
The term appears in black and white in an official joint factsheet from the US cybersecurity agency (CISA), the national security agency (NSA) and the standards body (NIST), published in 2023: actors could target encrypted data right now in a "catch now, break later" logic, capture now, break later. The threat is not a hypothesis: it is a category of risk that states officially address.
2 What the machine will break

Not everything falls. But what falls is essential.

Shor's algorithm
Public-key encryption, the Achilles' heel
In 1994, the mathematician Peter Shor showed that a quantum computer would be able to factor very large numbers at great speed. Yet that is exactly the difficulty that protects today's public-key encryption: RSA and elliptic-curve cryptography, which secure the key exchange behind nearly the whole web. Breaking this lock means opening the envelope of almost every encrypted communication. And the usual countermeasure, enlarging the key, does not suffice: the lock itself must be changed.
Encrypted web browsing
≈ 93%
of traffic over HTTPS, against half a decade earlier (Google).
Symmetric holds
AES-256
deemed safe: Grover's algorithm only doubles the cost of attack.
The dividing line, drawn by the NSA
The NSA itself distinguishes two worlds: public-key encryption "requires fundamental changes", while symmetric encryption (AES-256) and strong hash functions "are considered safe" against the quantum. The danger, then, is not that everything collapses, but that what collapses is precisely the part that protects the transport of secrets: the key exchange.
3 The countdown

The machine does not exist yet. But it is drawing closer, fast.

Q-Day
The horizon that recedes toward us
How many qubits does it take to break RSA-2048? The answer has kept falling. In 2019, two Google researchers estimated the cost at 20 million qubits and 8 hours of computation. In 2025, one of them, Craig Gidney, revised his estimate: fewer than a million qubits, in under a week. The target has not changed; it is our capacity to reach it that has come closer by a factor of twenty. Expert surveys now give a majority probability of seeing this machine appear within fifteen years.
Qubits for RSA-2048
20M → < 1M
estimate divided by twenty between 2019 and 2025 (Gidney).
Q-Day within 15 years
51 to 70%
deemed likely by the experts surveyed (Global Risk Institute, 2025).
Patience plays against us
The hardware is progressing: in late 2024 Google unveiled a chip, "Willow", crossing a long-hoped-for error-correction threshold; IBM is aiming for a fault-tolerant machine around 2029. None of this breaks RSA yet. But the data harvested today does not erase itself: it waits. The countdown is not that of the machine, it is that of our secrets.
4 The new measure of a secret

The right question is no longer "does my encryption hold?" but "how long must it hold?".

Mosca's theorem
Three durations that decide everything
The cryptographer Michele Mosca formulated an inequality of fearsome simplicity. Call X the length of time a piece of data must stay secret, Y the time it will take to migrate to quantum-resistant encryption, and Z the delay before the machine exists. If X + Y > Z, it is already too late: the data encrypted today will be readable before the end of its useful life. In other words, the security of a secret is no longer measured by the strength of the lock, but by the length of time it must remain shut.
State secret
25 to 75 years
of required confidentiality: well beyond the expected Q-Day.
Genetic data
for life
it identifies you, and your descendants, forever.
Already lost, without knowing it
As early as 2015, Mosca estimated "a one in seven chance of breaking RSA-2048 by 2026, and a 1/2 chance by 2031". A medical record, an industrial secret, diplomatic communications: anything that must stay confidential over ten or twenty years and is harvested today is, by this reckoning, already exposed. This is the heart of the threat, and it is what our notion on the confidentiality lifespan and deferred risk sheds light on.
5 Who is already harvesting

And this is no figment of the imagination.

Documented, or acknowledged
States that do not wait for the machine to collect
The harvest is already here. The Snowden documents revealed in 2014 that the NSA was funding, to the tune of nearly $80 million, a program aimed at building "a cryptologically useful quantum computer". Defense analysts judge it likely that state actors, including China, are already stealing encrypted data of long-term value, biometrics, identities, weapons blueprints, to read them later. And the agencies no longer hide it: a US executive order of June 2026 states in black and white that adversaries "may already be collecting" encrypted federal data.
NSA program revealed
≈ $80 million
for a "cryptologically useful" quantum computer (Snowden, 2014).
Migration mandated
2030-2035
post-quantum switchover deadlines (NSA, European Union).
When the defender warns
The most telling sign comes from the protectors themselves. The NSA, in mandating the abandonment of RSA, writes that "the data these systems protect will require protection for decades beyond its end of life: the NSA must act now". In France, ANSSI explicitly names the "store now, decrypt later" attack and mandates hybrid protection from today. When the one who defends starts to run, it means the threat is not for tomorrow: it is for today's data.
6 From now on, everything is concerned

The subject has left intelligence alone. It touches almost everything.

Accumulation without sorting
Storing costs less than choosing
Why keep everything? Because storage costs almost nothing anymore: its price has fallen by nearly 99.99% since 1980. Sorting, classifying, deleting takes time and judgment; keeping is free. The result: the world produces dizzying volumes of data, and two-thirds of corporate data lies dormant, unexploited, awaiting a use. Hackers, platforms and states accumulate the same troves. Even finance is exposed: the US Federal Reserve published a 2025 study devoted to "Harvest Now, Decrypt Later", concluding that the confidentiality of records already written is "irremediably" vulnerable.
Data worldwide, 2025
175 ZB
zettabytes, against 33 in 2018 (IDC projection).
Bitcoins exposed
≈ 25%
including those attributed to Satoshi, vulnerable ECDSA keys (Deloitte).
The bill, already encrypted
The cost of migrating US civilian agencies alone to post-quantum encryption is estimated at $7.1 billion over ten years. And the raw material of the threat is not lacking: a single compilation of leaks, nicknamed "Mother of All Breaches", aggregated some 26 billion records in early 2024. Harvesting, today, takes almost no effort.
7 Two futures in the same trove

The same decryptable data opens two opposing futures.

One raw material, two destinations
Absolute comfort, or total surveillance
One and the same trove of data, exploited by artificial intelligence, can lead to two worlds. On one side, comfort: earlier cancer screening, accelerated science, services that anticipate our needs. On the other, dictatorship: mass surveillance that knows where you are, whom you keep company with and, soon, what you think. The data is the same; it is the use, and the regime that decides on it, that separates the two futures.
The comfort side
+29%
more breast cancers detected by AI, with no more false alarms (Sweden, 2023).
The surveillance side
≈ 540 million
cameras in China, roughly half the world's stock.
Both sides, in figures
On the bright side: the AI AlphaFold predicted the shape of 200 million proteins, where sixty years of laboratory work had resolved 170,000; personalization is said to represent more than $1 trillion in value. On the dark side: in Xinjiang, the DNA collection of an entire population aged 12 to 65 and nearly a million detentions; a social credit system that has already barred 28 million plane tickets; a Western company, Clearview AI, that has scraped 30 billion faces. The same technology, two possible civilizations.
8 When thinking becomes risky

For surveillance does not merely observe: it alters.

The chilling effect
Knowing you are watched is enough to censor yourself
Psychologists call it the "chilling effect": the mere awareness of being watched pushes toward self-censorship. This is not an intuition, it is measured. After the Snowden revelations of 2013, a survey showed that 16% of American writers had avoided addressing certain subjects; an academic study found a 25 to 30% drop in views of "sensitive" Wikipedia articles. More troubling: the effect is strongest among those who claim to "have nothing to hide". Surveillance does not wait to punish before it acts: it need only exist for people to fall silent.
"Sensitive" articles viewed
−25 to −30%
on Wikipedia after the 2013 revelations (Penney study, 2016).
Writers self-censoring
16%
avoided a subject for fear of surveillance (PEN America, 2013).
The retroactivity of meaning
"Harvest now, decrypt later" also holds for the meaning of a piece of data. Information harmless today can become compromising tomorrow, if the law, the regime or the employer changes. In the United States, mundane private messages were used to prosecute a mother and her daughter after a legal reversal on abortion. Further back in history, the Dutch population register, a peaceable administrative tool, became in 1941 an instrument of deportation. The data outlives the intention that created it; its meaning, however, depends on who will read it.
9 Will we have a choice?

The countermeasure exists. It remains to want to use it.

The antidote, and its limit
The poison has a remedy, but it must be taken in time
Let us be fair: the threat is manageable. In August 2024 the NIST published the first post-quantum encryption standards, and deployments have begun, from Apple to Signal to Cloudflare, which already secures nearly half its connections this way. Against accumulation, the law exists too: the GDPR mandates data minimisation and the right to be forgotten. The real difficulty is not technical, it is political and temporal: migration must happen before Q-Day, and the window is closing at the speed of the shelf-life of our secrets. As Mosca puts it, "There's no free lunch: every unit of crypto-procrastination translates either into a unit of catastrophic risk or a unit of rushed migration risk".
The compass
The time asymmetry. A secret harvested today can be read tomorrow: this holds for encryption as for the political meaning of a piece of data.
Act now. The post-quantum countermeasure exists, but X + Y > Z: to migrate later is to have already lost the long shelf-life data.
The only safe data. The data not harvested: minimising what we collect and keep remains the most radical protection, alongside encryption.
The choice, by default or by decision
The future will not be decided by the machine, but by us. The battles are already under way: in the spring of 2026, the European Parliament rejected by a single vote (307 to 306) a plan for generalised message scanning; in the United Kingdom, a state tried to obtain a backdoor into Apple's encryption. Between comfort and surveillance, the same trove of data can tip one way or the other. Which future will we choose? The answer depends on what we decide before the machine arrives, because afterward it will be too late for today's secrets.
Key concepts · Finance Academy
Confidentiality lifespan and deferred risk →
Why the security of a secret is now measured by its shelf-life, and how Mosca's theorem (X + Y > Z) decides whether data encrypted today is already lost.

Read alongside: When your data sets your price, the other face of the exploitation of personal data; and When doubting costs nothing and proving costs dear, the other long-term face of digital trust. Reference: abbreviations & acronyms used (RSA, NIST, NSA, GDPR).