up:: What To Do
Did my phone already fix this?
Probably some of it, and nobody told you.
Between 2023 and 2025, Signal, Apple, and the major browsers all quietly replaced the encryption that sets up your private connections. Hundreds of millions of devices were upgraded against a threat their owners had never heard of, through routine updates that mentioned nothing about it.
That’s genuinely good news, and it’s also the most under-covered fact in this whole subject. The companies with the most to lose from being wrong decided this was worth engineering against years before any machine existed.
The short version:
- Signal shipped protection in 2023, and extended it across the whole conversation from October 2025. It works the same on Android as on an iPhone, which makes it the answer on both.
- Apple shipped it for iMessage in February 2024, with iOS 17.4 and the matching Mac and Watch releases.
- Chrome and Edge turned it on by default in November 2024, and Firefox followed in February 2025.
- What they upgraded is the part that sets up a private connection, which is the part being harvested today.
- What they haven’t finished is the part that proves who you’re talking to, and that’s on a slower schedule everywhere.
- Email, most other messaging apps, and anything older than this are still using the old method.
Who’s already done it?
| Product | What shipped | When |
|---|---|---|
| Signal | PQXDH, post-quantum protection for setting up conversations | 2023 |
| Apple iMessage | PQ3, with iOS 17.4, iPadOS 17.4, macOS 14.4, watchOS 10.4 | February 21, 2024 |
| Chrome and Edge | X25519MLKEM768, on by default | November 2024 |
| Firefox | mlkem768x25519, in release | February 2025 (Firefox 135) |
| Signal | The Triple Ratchet, extending the protection across the whole conversation rather than the opening handshake, rolling out gradually | Announced October 2, 2025 |
Source: Signal, “The PQXDH Key Agreement Protocol,” signal.org; Apple Security Research, “iMessage with PQ3,” February 21, 2024, security.apple.com; Google Security Blog, “A new path for Kyber on the web,” September 13, 2024, security.googleblog.com; Mozilla, “Firefox 135.0 release notes,” February 4, 2025, mozilla.org; Signal, “Signal Protocol and Post-Quantum Ratchets,” October 2, 2025, signal.org.
The two Signal rows apply on Android and iPhone alike, since it’s one app on both. The iMessage row is Apple’s platforms only.
If you’re running a current iPhone, a current Android phone, a current Mac, or a recent version of Chrome, Edge, or Firefox, a meaningful share of your traffic is already protected without you doing anything.
Why did they move before anyone made them?
This is the part worth sitting with, because it’s the strongest available evidence that this is real.
Nobody required Signal or Apple to do this. There was no regulation forcing it, no incident to respond to, and no machine in existence capable of the attack. They spent engineering years on it anyway.
The reason is specific to how the threat works. A message harvested today is exposed the day the machine arrives, so waiting means every conversation in the interim is already lost. For a company whose product promise is confidentiality for things people need private for years, that math resolves quickly.
What did they actually fix?
The upgrade covers the step where two devices that have never met agree on a secret, in public, before anything private is exchanged. That’s the step being harvested right now, which is why it went first.
Two honest limits belong with the good news.
The identity half isn’t finished. The part that proves a message genuinely came from your friend’s device, rather than somebody impersonating it, still uses the older method almost everywhere. That’s on a slower replacement schedule across the whole industry, and it’s a real gap rather than an oversight, because it depends on infrastructure that’s years behind.
Support isn’t the same as use. A browser supporting the new method is a different claim from any particular connection actually using it, which depends on the site at the other end too. The upgrade only helps when both sides have it.
Detail at Apple iMessage PQ3, Signal PQXDH, and Cloud and Browser PQC Status.
What’s still using the old method?
Quite a lot, and it’s worth knowing where you stand.
- Email is largely unprotected in this sense, whatever your provider says about encryption.
- Most messaging apps other than Signal and iMessage haven’t announced this work.
- Regular texting, including the newly encrypted RCS messages between Android phones and iPhones, uses classical cryptography for now.
- Anything you haven’t updated in a couple of years, including phones the manufacturer has stopped supporting.
- Websites that haven’t upgraded their side, which your browser can’t fix alone.
- Smart home devices, cars, and medical devices, which mostly can’t be updated this way at all. See Is my pacemaker safe?
What if you’re on Android?
Signal is the answer, and it’s the same answer as on an iPhone.
Signal is one app on both platforms, so an Android user gets the 2023 protection and the 2025 extension exactly as an iPhone user does. It’s free, it takes a few minutes to install, and the encryption work happens invisibly. For anything that has to stay private for years, this is the whole recommendation.
Regular texting is a separate question. Texting between Android phones and iPhones got its own encryption upgrade through the GSMA’s RCS Universal Profile 3.0, which defines end-to-end encryption for RCS using the MLS protocol. That’s a genuine privacy improvement and it’s worth knowing about on its own terms.
It’s a different kind of protection from the one this page is about. MLS as published uses classical elliptic-curve cryptography in its standard configurations, and neither Google nor the GSMA has published a post-quantum claim for RCS. A text recorded today stays readable to a future quantum computer, which is exactly the gap Signal closed.
Source: GSMA, “RCS Universal Profile 3.0 specifications,” gsma.com; Google, “How end-to-end encryption in Google Messages provides more security,” support.google.com; R. Barnes et al., “The Messaging Layer Security (MLS) Protocol,” RFC 9420, July 2023, rfc-editor.org.
Your backups are already encrypted, and have been for years. Since Android 9 in 2018, backups from a phone with a screen lock set are encrypted with a key derived from that screen lock, which Google doesn’t hold. The condition is a real PIN, pattern, or password rather than a swipe, so the one thing worth checking is that your lock screen is an actual secret.
Source: Google Security Blog, “Google and Android have your back by protecting your backups,” October 2018, security.googleblog.com.
If you’re a journalist, an activist, or otherwise likely to be targeted, Android 16 added an Advanced Protection mode that bundles the platform’s strongest defenses and stops them being switched off individually. It hardens the device against spyware and intrusion, which is a different problem from the one on this page and often a more immediate one. See If you are a high-risk person.
Source: Google Security Blog, “Advanced Protection: Google’s Strongest Security for Mobile Devices,” May 2025, security.googleblog.com.
How do I make sure I’m covered?
- Update everything, and keep updating. This is the whole action item. The protection arrives through everyday updates, which is exactly why so many people already have it without knowing.
- Use Signal or iMessage for anything that has to stay private for years.
- Don’t run a phone that’s stopped receiving security updates. Once the manufacturer drops support, you stop getting improvements like this one.
- Buy nothing extra. No product adds this to your life. It arrives from the companies running the systems you already use.
Questions people ask
How can I tell if a specific message was protected? For practical purposes you can’t, from the outside. Use apps that have published this work rather than trying to verify individual conversations.
Does WhatsApp have it? Check the company’s current published statements rather than trusting a summary. This area moves, and the honest answer for any app is whatever its own security documentation says today.
I’m on Android, so is any of this for me? All of it. Signal works identically on Android and carries the same protection, your backups have been encrypted to your screen lock since Android 9 in 2018, and Chrome on Android gets the browser upgrade the same way it does on a laptop.
My texts say they’re encrypted now, so am I covered? For someone reading your messages today, yes, and that’s worth having. Encrypted RCS uses classical cryptography, so a recording kept until a quantum computer exists is a different matter. Use Signal for anything in that category.
Does turning on Advanced Data Protection help with this? It’s worth turning on, for reasons of its own. Apple’s published list of quantum-secure features covers iMessage, TLS, VPN, SSH, the iPhone-to-Watch connection, and its developer APIs, and iCloud isn’t among them, so treat it as a privacy improvement rather than a step against this particular threat.
Source: Apple, “Quantum-secure cryptography in Apple operating systems,” support.apple.com.
Is my old iPhone protected? Only if it can still run iOS 17.4 or later and you’ve installed it. Devices past their support window don’t receive changes like this.
Does a VPN help? Not with this. A VPN changes who can see your traffic on the local network, and the encryption question is the same underneath it.
If my phone’s fixed, am I done? No, and it’s worth being clear about why. Your phone protects what you send from now on. It does nothing about copies already taken, and nothing about the records your doctor, bank, and insurer hold about you on their own systems.
Where to go next
- What should I actually do? covers everything else on the personal list.
- What should my doctor and my bank be doing? covers the records you don’t control.
- Is someone stealing my data right now? explains what’s being taken and why.
Go deeper into the technical detail
The technical status of every major platform is Cloud and Browser PQC Status.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.