Ninjacast — Apocalypse Now background reading: The big PQC risk for NEwbZ
As described by a recovering lightweight crypto person (well I studied it at RHUL, I get it, and I have done E2E crypto Architectures (in PROD) - blah blah blah, but I am not a cryptographer)
Shor for NEWBZ: Why Quantum Might Make Your Padlock Blush...
yes, it’s “Shor,” rhymes with “shore”... no ‘e’...
If you’ve heard “quantum will kill RSA” and thought “is that a new boy band?”, this one’s for you.
The 10-second version...
RSA hides secrets by multiplying two huge prime numbers. Classical computers take basically forever to split the product back apart. Shor’s algorithm is a quantum party trick that finds a hidden rhythm in the math; once you know the rhythm, splitting the number is easy. Goodbye, RSA padlock!!! - I think Prof. Keith Martin (RHUL) exact words were once this is achieved, whoever does it better run away FAST before someone tracks them down and eliminates them - which we all chortled at 🤪
Imagine if governments/militaries suddenly could not trust their comms, banks could not move money etc etc, cats and dogs started living together - you get the picture...
What Shor actually does:
Pick a number a and look at a^x mod N.
That bouncy function repeats, like a drum loop. Quantum bits try many x at once (superposition), then use interference (the Quantum Fourier Transform) to amplify the correct beat length (the period).
Measure, do a tiny bit of cleanup → the prime factors fall out.
What it DOES break
Schemes based on factoring/discrete logs: RSA, classic Diffie–Hellman, lots of ECC.
What it DOESN’T do
It doesn’t insta-nuke AES. That’s a different quantum speedup (Grover’s), mostly solved by using longer keys.
It doesn’t work on your laptop; it needs a big, error-corrected quantum computer (we’re not there yet)
Did I mention it will take along time, it will take a long time honestly, A long time, did I mention it will take a long time....It will take a long time...
Why you should care now (not in panic font):
Bad guys can harvest now, decrypt later. Your long-lived stuff—backups, archives, CA roots, code-signing—age pretty bad - think the last time you refreshed your X509, your OWASP config strings, and looked at the crypto protecting your 10 year old backups.
The adult move is crypto-agility: design systems so you can swap algorithms without tears.
What to do (zero mysticism):
Inventory where crypto lives.
Shorten key lifetimes; re-key crown jewels.
Ask vendors for PQC roadmaps + Crypto SBOMs.
Start testing post-quantum options (Kyber/Dilithium), or at least hybrid modes.
One-liner: Shor finds the secret beat in your math track; once the beat drops, RSA stops. And when it does bring popcorn, cos then it could get ugly...
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·