Blog

The post-quantum future already fits in a pocket

When we talk about quantum computing, the first images that come to mind are generally specialized laboratories, complex cryogenic installations, and experimental machines that still seem very far removed from our everyday computing environment. It is therefore quite telling to now see the phrase “quantum resistant” appear on something as ordinary as a USB key.

ZDNET recently tested an Apricorn Aegis Secure Key offering 4 TB of capacity and using AES-256 XTS hardware encryption. Authentication and encryption are carried out directly by the device, and the manufacturer notably presents its product as “quantum resistant.”

That phrase obviously deserves a few technical nuances. Above all, it raises a question far more interesting than that of this particular USB key: what will our transition toward a computing environment prepared for the post-quantum world actually look like?

The answer is likely to be far less spectacular than we imagine. The post-quantum world will probably not begin on the day a sufficiently powerful quantum computer appears. Its construction is already under way and will advance through our software, our networks, our equipment, our phones, our cloud infrastructures and, indeed, certain small objects we carry in our pockets.

We first have to understand what quantum resistance means here. The key presented by ZDNET uses AES-256, a well-established symmetric encryption algorithm. It therefore does not use the new post-quantum cryptography algorithms such as ML-KEM or ML-DSA, designed to address certain vulnerabilities that sufficiently powerful future quantum computers could create in public-key cryptography.

This distinction is essential since not all forms of cryptography are affected in the same way by quantum computing. Grover’s algorithm can theoretically speed up certain symmetric key searches, but practical constraints considerably reduce that advantage. AES-256 is therefore still considered to offer a substantial security margin against the quantum capabilities currently envisaged, subject of course to future developments in cryptanalysis.

This situation perfectly illustrates the nature of the transition ahead of us. Preparing for the post-quantum world does not mean indiscriminately replacing all the cryptography currently in use. Some technologies will have to evolve quickly, some will remain relevant for a long time, and others will progressively be combined with new mechanisms.

We can therefore continue to use excellent existing technologies while methodically preparing the migration of the components that genuinely have to change. This approach is far more useful to organizations than a view in which all cryptography would suddenly become obsolete the day a sufficiently powerful quantum machine appears.

The transition has in fact already begun. NIST has finalized its first post-quantum cryptography standards, and organizations can now start preparing their implementation. In parallel, they must identify the systems, applications, equipment, and protocols that still depend on RSA, elliptic curve cryptography, or other mechanisms liable to be affected by the evolution of quantum computing.

This is where our little USB key becomes interesting, almost in spite of itself. It shows how the quantum question is starting to come down from laboratories and discussions between cryptographers to appear in the specifications of ordinary computing products. The mention may seem unusual today. Over time, similar considerations could become perfectly normal in network equipment, mobile devices, industrial systems, vehicles, connected objects, software, and digital services.

We will then witness a transformation that is far more diffuse than spectacular. Some equipment will adopt new cryptographic mechanisms when it is renewed. Operating systems will progressively integrate new capabilities. Protocols will evolve. Applications will be updated. Cloud infrastructures will offer new mechanisms, and organizations will change their architectures at the pace of their needs, their risks, and the life cycle of their technologies.

This progression is also a reminder that extremely robust cryptography is never enough on its own to secure an entire environment. A USB key using AES-256 can be lost. Its user can choose a weak passcode. Once decrypted, the data can be copied onto a compromised computer or sent by mistake to a recipient who should not receive it. A legitimate user can themselves become the entry point for an incident.

The device tested by ZDNET does in fact incorporate several complementary mechanisms, notably authentication performed directly on the device, locking functions, and various protections designed to make brute-force attacks more difficult. This combination represents real security far better than a technology presented in isolation as a definitive solution.

Cryptography protects an essential component of the digital environment, while security also depends on identities, permissions, devices, data, applications, users, suppliers, and the architecture in which all these components interact. The post-quantum transition will therefore also have to fit into this reality.

This is precisely where Hypersecurity brings a useful perspective. It is not about labeling every product “quantum” or replacing existing cybersecurity disciplines. It makes it possible to place cryptographic evolution within a broader architecture in which data, identities, systems, knowledge, suppliers, and resilience mechanisms must continue to work together while certain technology components evolve.

An organization could perfectly well deploy post-quantum algorithms and remain vulnerable because of poorly protected identities, excessive privileges, needlessly retained data, or a critical dependency on a supplier. Hypersecurity is thus a reminder that the strength of an algorithm is one part of the protection, while the ability to anticipate, resist, detect, contain, recover, and adapt depends on the architecture as a whole.

Paradoxically, one of the first concrete effects of quantum technology could therefore be to force us to better understand the cryptography we already use. For a long time, it was able to remain relatively invisible to executives. HTTPS connections worked, VPNs established their tunnels, certificates authenticated systems, backups were encrypted, and applications exchanged their data. Cryptography did its job in the background.

The post-quantum transition is gradually changing this situation, since it becomes impossible to properly replace what you cannot locate. An organization must know the algorithms, certificates, protocols, systems, applications, equipment, and data flows that depend on cryptographic mechanisms in order to determine which will eventually require intervention.

Cryptographic inventory then becomes a question of organizational visibility. It makes it possible to discover cryptographic assets and then to understand the dependencies around them. An application may depend on a certificate, a piece of equipment on a particular protocol, a supplier on a software library, and a business process on a digital signature. Changing one component can therefore have consequences well beyond cryptography itself.

This work can in fact reveal a problem far more immediate than the eventual arrival of a cryptographically relevant quantum computer: many organizations do not yet have a complete view of their cryptographic dependencies. The first benefit of post-quantum preparation can therefore be to improve, today, the understanding of the environment the company has to protect.

This visibility leads naturally to crypto-agility. The objective is not only to select the best algorithms available today, but to build the ability to replace and adapt the cryptographic mechanisms used in applications, protocols, software, hardware, firmware, and infrastructures while preserving security and operational continuity.

This approach is fundamental because post-quantum cryptography will not be the final chapter in the history of cryptography. Algorithms will continue to be studied, cryptanalysis methods will advance, computing capabilities will evolve, and new vulnerabilities will be discovered. Some mechanisms currently considered promising may be improved or eventually abandoned, while new families will appear.

Maturity therefore consists in learning how to change. A crypto-agile organization can integrate new standards, progressively replace mechanisms that have become inadequate, and manage different cryptographic generations without turning every change into a crisis project.

This is the approach Quantum Beyond favors with its Post-Quantum Readiness & Cryptographic Transition service. The objective is to help organizations discover their cryptographic assets, map their dependencies, assess risks, identify information that is particularly sensitive to Harvest Now, Decrypt Later, measure their crypto-agility, and build a roadmap that prioritizes migrations according to their actual exposure and operational constraints.

An organization does not need to become a quantum computing specialist to undertake this work. Above all, it needs to know what it is protecting, how long certain information must remain confidential, which technologies currently provide that protection, and which other components they interact with.

That last question is particularly important. A company may discover that a cryptographic mechanism is used in software it controls directly and can easily update. It may also discover that an essential technology depends on industrial equipment with a fifteen-year life cycle, on an external supplier, on firmware that is rarely modified, or on a legacy application whose replacement would take several years. Two uses of the same algorithm can therefore present completely different transition difficulties.

Post-quantum preparation then becomes an exercise in technology governance. It requires distinguishing what can be changed quickly from what will take several years, identifying the information whose confidentiality lifespan justifies faster intervention, and progressively embedding future cryptographic requirements into architecture, procurement, and technology renewal decisions.

This approach also helps avoid a common mistake when a new technology attracts a great deal of attention: looking for a definitive solution. The history of computing shows us instead that durable architectures are those that retain enough flexibility to absorb change. Post-quantum preparation should follow the same logic.

The USB key presented by ZDNET certainly does not, on its own, herald a quantum revolution. It does, however, offer a surprisingly concrete image of a much broader transformation. Considerations once reserved for researchers, cryptographers, and specialized teams are gradually starting to appear in products that organizations and individuals can use today.

In a few years, we will probably talk less about “quantum resistant” products because some of those characteristics will have become normal. The mechanisms will have been integrated into operating systems, applications, equipment, cloud services, and security architectures. Some current technologies will have been replaced, others will still be in use, and several cryptographic generations will coexist.

For companies, the real challenge is therefore less about predicting the exact arrival date of a sufficiently powerful quantum computer than about making sure they will be able to adapt their environment when changes become necessary. The useful question becomes their ability to see their dependencies, understand their risks, set their priorities, and evolve their cryptography without compromising their operations.

We readily imagine the shift to the post-quantum world as a spectacular technological event. Yet its most concrete manifestation could be far more ordinary. A software update will adopt a new cryptographic mechanism. A supplier will change its protocols. New equipment will replace an older generation. A certificate will evolve, a VPN will be modernized, an application will integrate a new standard, and a procurement policy will start requiring certain cryptographic capabilities.

Technology after technology, the transition will thus take place within the existing computing environment. It will not instantly eliminate mechanisms that still work, and it will not turn every piece of equipment into a quantum product. It will progressively change the components that need to evolve while keeping those that remain robust enough.

This evolution gives organizations an interesting opportunity: using post-quantum preparation to better understand their current environment. Inventorying cryptographic assets, mapping dependencies, determining how long information needs to remain confidential, improving crypto-agility, and embedding these considerations into the architecture strengthens, starting today, the company’s ability to absorb future changes.

Quantum Beyond can support this work alongside internal teams and their technology partners through Post-Quantum Readiness & Cryptographic Transition, while placing the cryptographic transformation within a broader vision of Hypersecurity. The objective is to prepare a gradual, controlled evolution compatible with operational continuity rather than chasing the illusion of definitive protection.

This little USB key ultimately has a symbolic value greater than its size. It reminds us that the post-quantum future will probably not show up at our door all at once. It will settle in around us, update after update, device after device, and standard after standard. Until the day when the words “quantum resistant” on an object that fits in a pocket no longer seem futuristic at all.