Home › Blog

Ninjacast — Apocalypse Now background reading: The big PQC risk for NEwbZ

As described by a recovering lightweight crypto person (well I studied it at RHUL, I get it, and I have done E2E crypto Architectures (in PROD) - blah blah blah, but I am not a cryptographer)

Shor for NEWBZ: Why Quantum Might Make Your Padlock Blush...

yes, it’s “Shor,” rhymes with “shore”... no ‘e’...

If you’ve heard “quantum will kill RSA” and thought “is that a new boy band?”, this one’s for you.

The 10-second version...

RSA hides secrets by multiplying two huge prime numbers. Classical computers take basically forever to split the product back apart. Shor’s algorithm is a quantum party trick that finds a hidden rhythm in the math; once you know the rhythm, splitting the number is easy. Goodbye, RSA padlock!!! - I think Prof. Keith Martin (RHUL) exact words were once this is achieved, whoever does it better run away FAST before someone tracks them down and eliminates them - which we all chortled at 🤪

Imagine if governments/militaries suddenly could not trust their comms, banks could not move money etc etc, cats and dogs started living together - you get the picture...

What Shor actually does:

Pick a number a and look at a^x mod N.

That bouncy function repeats, like a drum loop. Quantum bits try many x at once (superposition), then use interference (the Quantum Fourier Transform) to amplify the correct beat length (the period).

Measure, do a tiny bit of cleanup → the prime factors fall out.

What it DOES break

Schemes based on factoring/discrete logs: RSA, classic Diffie–Hellman, lots of ECC.

What it DOESN’T do

It doesn’t insta-nuke AES. That’s a different quantum speedup (Grover’s), mostly solved by using longer keys.

It doesn’t work on your laptop; it needs a big, error-corrected quantum computer (we’re not there yet)

Did I mention it will take along time, it will take a long time honestly, A long time, did I mention it will take a long time....It will take a long time...

Why you should care now (not in panic font):

Bad guys can harvest now, decrypt later. Your long-lived stuff—backups, archives, CA roots, code-signing—age pretty bad - think the last time you refreshed your X509, your OWASP config strings, and looked at the crypto protecting your 10 year old backups.

The adult move is crypto-agility: design systems so you can swap algorithms without tears.

What to do (zero mysticism):

  • Inventory where crypto lives.

  • Shorten key lifetimes; re-key crown jewels.

  • Ask vendors for PQC roadmaps + Crypto SBOMs.

  • Start testing post-quantum options (Kyber/Dilithium), or at least hybrid modes.

One-liner: Shor finds the secret beat in your math track; once the beat drops, RSA stops. And when it does bring popcorn, cos then it could get ugly...

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing