up:: 00 Start Here
For Press
If you’re covering Q-Day, or quantum computing’s impact on cybersecurity, this is for you.
I’ve been taking these notes for years, and I compiled them for press because there’s a lot of confusion and misinformation in this field. Who I am and where the background comes from is on About Addie.
Everything here is cited. Every load-bearing figure traces to its original document. The primary documents behind every claim is the annotated index of every source, and Every figure and where it comes from gives every number with the wording that states it accurately, including what each figure does not establish.
It’s kept current. Standards finalize and governments publish new deadlines, so pages carry a verified date and corrections are logged in public at Corrections and verification. I’d rather you tell me I’m wrong before you publish than after.
It’s free, there’s no email gate, and I answer on deadline. addie@lamarrlabs.com · Signal by request, just email and ask.
Somebody is copying encrypted data off networks today and storing it until a machine exists that can read it. Nobody will ever be told it happened, because copying encrypted traffic breaks nothing and creates no incident any disclosure law recognizes. The day that machine arrives, everything in storage becomes readable at once, going back to whenever the copying started.
The mathematics was settled in 1994. What’s missing is hardware. The replacement encryption is finished and already shipping into phones and browsers.
This page is the index. Start with the resource for your audience. Each one is self-contained and carries the story, the numbers, the quote, and the correction traps. Below those sit the 5 things anyone covering this needs, the reference pages, a topic index, and the questions reporters ask most.
Are you looking for something more technical?
The Post-Quantum Field Guide is the technical layer, written for security engineers, architects and cryptographers. The facts and the citations are the same ones behind this page, with the mechanism worked in full: how each algorithm breaks, what the standards actually specify, and what a migration looks like inside a real estate.
Start here: the 4 resources
Each resource is self-contained and ordered the way a piece usually gets built: the story in one paragraph, the 5 things that matter including what its readers should do, the sourced numbers, the questions that audience asks, and the errors that draw corrections.
A piece often spans 2 of them. For a business audience and For a policy audience share the liability and who-pays material, and For a security or technology audience carries the mechanism in full that For a general audience states without the detail.
5 things you must understand about Q-Day
- No machine capable of it exists, and no verified break has occurred. Periodic claims involve very small numbers or methods that don’t scale. Estimates of what a break would require fell from 20 million noisy qubits in a 2019 analysis to under 1 million in a 2025 revision, and the largest machines built so far hold low thousands of noisy qubits.
- The mathematics has been settled since 1994. Peter Shor published the method that year. It’s been checked continuously since and has never been overturned, so the disputed part is hardware timing rather than whether it works.
- “Breaks all encryption” is the most common error in coverage. Public-key cryptography (RSA, Diffie-Hellman, elliptic curve) breaks completely. Symmetric encryption (AES-256) and hashing (SHA-256) survive with larger sizes, which is why the same NSA advisory that retires RSA keeps AES-256 in place.
- The present-tense element is collection, and it’s undetectable. Encrypted data recorded today can be stored and read later. Copying breaks nothing, triggers no alarm, and creates no incident any disclosure law recognizes, which is the structural reason this rarely produces a news event.
- The replacement standards are finished and already deployed. NIST published the first 3 on August 13, 2024, and added a fifth algorithm in March 2025. Signal, Apple, Chrome, Edge, and Firefox shipped protection between 2023 and 2025, so “waiting for a solution” is inaccurate as a description of where things stand.
Source: Peter W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,” SIAM Journal on Computing 26(5), 1997, arxiv.org; C. Gidney and M. Ekerå, 2021, arxiv.org and C. Gidney, 2025, arxiv.org; NIST, “Report on Post-Quantum Cryptography,” NISTIR 8105, csrc.nist.gov; NSA, “Announcing the Commercial National Security Algorithm Suite 2.0,” September 2022, nsa.gov; NIST, August 13, 2024, nist.gov.
Reaching me
I run this myself, so an email reaches the person who wrote it.
addie@lamarrlabs.com · UTC-6 year round, with no daylight saving, so I’m 1 hour behind New York in winter and 2 hours behind in summer.
What you can ask for:
- A claim confirmed, with the primary document attached. If it’s public you get the document, which is worth more than my confirmation.
- On the record or on background. Your call, agreed before we speak.
- A passage checked for accuracy before you file, with no expectation of a quote or a credit.
- Same day when you’re on deadline, and the subject line has to make that unmistakable. Lead with the word DEADLINE and the hour you need it by, in your timezone. Anything less explicit joins the normal queue, and on a filing day that’s the difference between making your piece and missing it.
- Signal, by request. Email first and ask, and I’ll send the details.
I’m a former U.S. Air Force cryptographer working on post-quantum migration full time. I’m vendor-independent, so there’s no product I’d be steering you toward, and nothing in this resource is gated or tracked.
Everything below routes into the same material by other paths.
Reference pages built for reporters
Pages that exist because a reporter needs them, rather than because a reader does.
| Page | What’s in it |
|---|---|
| Charts you can reuse | Every chart in this resource, free to republish with attribution, as print-ready vector and 300 dpi, with the data behind each one |
| Protecting your sources | The part of this story about you rather than your readers: source identity has a lifetime horizon, and email is the gap |
| Corrections and verification | How to report an error, how to verify a claim before publishing, and what this resource commits to |
| What changed recently | What has moved and when, newest first, so a piece written from older material can be checked for staleness |
| The primary documents behind every claim | Every primary source in one annotated index, with the issuer, the date, what each document establishes, and a direct link |
| Every figure and where it comes from | Every number in one table, with the wording that states it accurately, its source, and the qualifier that gets dropped |
| A glossary of the terms you will meet | Every term defined for use in a piece, the pairs that get confused, the algorithm names, and the terms to handle carefully |
| What gets reported wrong | Every recurring error with the accurate version of each, plus a 5-question test for any new-machine announcement |
| A timeline of the quantum transition | Every dated event from 1994 to now, with what each one actually established |
| Is this just Y2K again | The comparison every editor raises, with the $100 billion figure and the 3 ways this one differs |
| Is this overhyped | The strongest case against the whole subject, stated at full strength |
| Did AI just break post-quantum encryption | The July 2026 HAWK withdrawal, what the coverage got wrong, and the 4 checks that resolve any AI-broke-cryptography headline |
| Is anyone selling me something I dont need | The marketing claims to treat as claims, and the phrases that give them away |
By topic
Questions reporters ask
Has anyone broken encryption with a quantum computer? No, and there’s no public evidence of it. Periodic claims involve very small numbers or methods that don’t scale.
When will it happen? Nobody credible names a year. The honest answer is the range: 28% to 49% within 10 years, 51% to 70% within 15. Attribute it as a survey of 26 specialists, and don’t describe the spread as experts disagreeing. Each one picks a coarse option like “likely, above 70%,” the report reads every answer twice at the bottom and top of the chosen band, and it says the gap between the 2 figures “largely reflect[s] the width of the likelihood bins.”
Why is this a story now? The standards finished in August 2024, the deadlines are dated, the migration is live in consumer products, and the collecting is present-tense. The only thing that hasn’t happened is the machine.
Is my reader’s bank account at risk? No. Reading old traffic reveals information about a person rather than granting access to their money.
What’s the government actually said? CISA, the NSA, and NIST wrote in August 2023 that attackers “could be targeting data today that would still require protection in the future… using a catch now, break later or harvest now, decrypt later operation.”
Source: Quantum-Readiness: Migration to Post-Quantum Cryptography, CISA, NSA, and NIST joint factsheet, August 21, 2023.
Is this a US-only story? No, and treating it that way is a common error. Australia is 5 years ahead of everyone.
Who’s doing the collecting? Nobody can name a party and prove it. What’s sayable: copying traffic leaves no trace, and storage costs a fraction of a cent per gigabyte per month.
How would anyone know it happened? They wouldn’t, and that’s the structure of the thing rather than a gap in reporting.
Where to go next
- A glossary of the terms you will meet is the full glossary, expanded.
- What gets reported wrong is the full accuracy reference, expanded.
- For a security or technology audience carries the full technical layer, indexed 13 ways.
- 00 Start Here is the section hub.
Go deeper into the technical detail
Straight into the technical Guide: Foundations MOC · The Threat MOC · The New Standards MOC · The Mandates MOC · Quantum Computing MOC
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-08-04 · Maintained by Addie LaMarr, LaMarr Labs.