Threat research · 3 min read
The harvest-now-decrypt-later problem, explained
Why encrypted data captured today can be decrypted later — and how to decide which of your data is already exposed.

Most security risks become real when an attacker acts. Harvest-now-decrypt-later (HNDL) is different: the attack starts today, but the damage lands years from now. An adversary records encrypted traffic or copies encrypted files, stores them cheaply, and waits for a cryptographically relevant quantum computer that can break the public-key algorithms protecting them.
Why public-key cryptography is the weak point
Almost every TLS session, VPN tunnel and code signature relies on RSA, elliptic-curve cryptography or Diffie-Hellman to exchange keys or prove identity. Shor's algorithm, running on a sufficiently large quantum computer, solves the mathematical problems behind all three efficiently. Once the key exchange is broken, the symmetric session keys fall with it, and the recorded data can be read in full.
Symmetric algorithms such as AES-256 and modern hash functions are far more resilient. Grover's algorithm weakens them, but doubling key length is generally enough. The urgent problem is the asymmetric layer that wraps them.
Nobody knows the exact date — and that is the point
Expert estimates for when a cryptographically relevant quantum computer will exist vary widely. Rather than betting on a single date, standards bodies have set deadlines. NIST IR 8547 proposes deprecating RSA and ECC for many uses by 2030 and disallowing them by 2035. For long-lived secrets, waiting for certainty means waiting too long.
Mosca's inequality: a simple test
Michele Mosca framed the question with three numbers. X is how long your data must stay confidential. Y is how long it will take you to migrate to quantum-safe cryptography. Z is how long until a quantum computer can break today's algorithms. If X plus Y is greater than Z, you already have a problem — data protected today will still be sensitive when it can be decrypted.
For many organizations the numbers are sobering. Health records, legal files, government data, intellectual property and financial identities often need to stay private for ten to fifty years. Large cryptographic migrations routinely take five to ten years. Even optimistic quantum timelines leave little margin.
Which data is actually at risk?
Not every encrypted byte is equally valuable to an attacker. HNDL risk concentrates where three conditions meet: the data travels over or is stored behind vulnerable public-key cryptography, it has a long confidentiality lifetime, and it is plausibly worth collecting. Internet-facing TLS endpoints carrying customer data, site-to-site VPNs, partner APIs and backups replicated across networks are typical hotspots.
A practical assessment ranks assets by combining algorithm strength, data shelf-life and exposure. That ranking turns an abstract threat into a prioritized list your teams can work through.
What to do now
First, build an inventory. You cannot migrate cryptography you cannot see, and most organizations underestimate how many certificates, keys and libraries they run. Second, classify data by how long it must stay confidential. Third, prioritize the systems where long-lived data crosses vulnerable key exchange, and plan hybrid post-quantum key exchange there first. NIST's ML-KEM (FIPS 203) is designed for exactly this role.
Finally, make the program measurable. A single risk score tracked over time gives executives a clear view of progress and keeps quantum readiness from becoming an open-ended research project.
The bottom line
Harvest-now-decrypt-later turns a future capability into a present-day exposure. The organizations that handle it well treat it like any other long-horizon risk: they measure it, prioritize it and start reducing it before the deadline arrives.