Q-Day

Q-Day

Q-Day refers to the day on which a quantum computer will first be able to break today's standard encryption methods. Nobody knows exactly when this day will come — yet banks, government agencies, and software companies are already preparing for it.

Almost everything you send online is encrypted. Your messages and payment data are turned into unreadable gibberish before being sent. The trick behind this is a computational problem that is practically unsolvable for normal computers: breaking down a huge number into its factors. A quantum computer, however, operates according to different physical rules than a normal computer. For this one specific task, it would be extremely fast. Q-Day is the name for the point in time when such a computer becomes powerful enough to actually break real encryption.

Why the countdown is already running today

You might think this problem only concerns the future. That’s not true. Attackers can intercept encrypted data today and simply store it. It gets decrypted later, once the technology is ready. Experts call this “harvest now, decrypt later” — harvest now, decrypt later.

This is especially dangerous for data with a long shelf life. A chat log from today might not matter in fifteen years. Medical records, patents, military documents, or government files do matter. Anyone protecting such information must assume it is already sitting in foreign archives right now.

On top of that comes the length of the transition. Encryption is built into ATMs, cars, ID cards, and millions of servers. Replacing such systems has historically taken ten years or more. That’s why authorities are setting deadlines: US agencies, for example, are supposed to have switched to new methods by 2035.

What quantum computers do differently

A normal computer calculates with bits, which are either 0 or 1. A quantum computer uses qubits, which can superimpose both states simultaneously. This allows it to tackle certain tasks not just faster, but in a fundamentally different way. For most computational tasks, this brings no benefit at all. For a select few, it brings a great deal.

The most famous case is Shor’s algorithm, which the mathematician Peter Shor already described back in 1994. It factors large numbers and thereby breaks the RSA and elliptic curve cryptography methods. Both secure almost every encrypted connection on the internet today.

The catch for attackers: qubits are extremely prone to interference. You need a very large number of error-corrected qubits — according to current estimates, millions of them. Current devices have a few hundred to a few thousand, and these are error-prone. That’s why estimates for Q-Day range from around 2030 to well into the 2040s. No precise year can be stated with any credibility.

New methods that are already being built in

The answer is called post-quantum cryptography. These are encryption methods based on computational problems for which even quantum computers know no shortcut. The US standards agency NIST established the first three such methods as standards in 2024. Important: this involves classical software, not quantum technology. It runs on perfectly ordinary computers and phones.

A common misconception is that all of this is distant future music. In fact, the transition is already well underway. Signal, Apple in its iMessage service, and Google in the Chrome browser have already built in quantum-safe methods. Usually they run in parallel with the old method, so that if there’s a flaw in the new method, not everything is immediately exposed.

That’s why Q-Day regularly appears in business news. Banks and insurers report their transition plans, security firms advertise “quantum-safe” products. Such marketing claims are worth a closer look, since the term is not protected. For you personally, there’s little to do: the transition happens in the background as long as you keep your software up to date.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.