up:: Whats At Risk MOC
If you are a high-risk person
Most of this resource says, correctly, that the majority of what you send stops mattering and that the calm response is the right one.
This page is for the people that reassurance doesn’t fit. If you’re an activist, a human rights defender, a dissident, someone fleeing an abusive person, an asylum seeker, or anybody whose safety depends on certain things staying unknown, the calculation is different in a specific way: your confidentiality horizon is your lifetime, and the people interested in you may be well resourced and patient.
That combination is exactly what makes recorded traffic worth storing.
Not legal advice
This page is general information rather than operational security advice for a specific threat. If you’re in immediate danger, a specialist organization working in your context can help in ways a general resource cannot.
The short version:
- A lifetime horizon changes everything. Data that stops mattering in a year is a different problem from data that never stops mattering.
- Who you contacted is usually more dangerous than what you said, and it’s the part protected least well.
- The tools you’re most likely already using are among the best protected, and Signal deployed post-quantum protection in 2023.
- This has happened before, to roughly 300,000 people, behind a padlock that looked correct.
- Communications already sent can’t be recalled. That’s the part with no remedy.
- Your relatives are exposed through your genetic data, whether or not they ever consented.
Why does a lifetime horizon change the calculation?
Because the standard reassurance depends on data expiring, and yours doesn’t.
The reason most people can be relaxed about this is that a message from 2026 read in 2040 is usually worthless. A dinner plan, an invoice, a work thread. Nobody stores what nobody will want.
For a high-risk person the opposite holds. The fact that you attended a meeting, contacted an organization, crossed a border, sought a shelter, or spoke to a journalist can remain dangerous for as long as you live, and in some contexts dangerous to your family after that. An adversary deciding what to keep is looking for exactly that: material whose value survives a decade in storage.
The other half is resources. Recording and storing encrypted traffic at scale is something states and well-funded actors do. If the people interested in you are in that category, the assumption that nobody would bother is not one you can rely on.
What is actually exposed?
Usually the connection rather than the content, and this is the part most guidance underplays.
| What travels | How well it’s protected | What it reveals about you |
|---|---|---|
| Message content | Well, in modern encrypted messengers | What was said |
| Who you contacted, and when | Much less consistently | That you contacted them, which is often the whole risk |
| Location, over time | Varies, frequently poorly | Where you were, and who else was there |
| Email headers | Routinely exposed | Sender, recipient, timing |
| Account and device identifiers | Persistent by design | Links separate activity to one person |
| Genetic data | Held by a company, indefinitely | You, and your relatives who never consented |
An adversary who learns that you contacted a particular organization on a particular date may need nothing else. That’s true today without any quantum computer, and stored traffic makes it retroactively available later.
Has this actually happened to people like me?
Yes, and the documented case is worth knowing precisely.
In 2011 an attacker breached a Dutch certificate authority and issued at least 531 fraudulent certificates. One was used to read the email of roughly 300,000 users in Iran, among them dissidents and journalists. Throughout, their browsers showed a valid padlock, because the certificates were mathematically correct and the encryption was working exactly as designed.
Source: Fox-IT, “Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach,” 2012, Fox-IT Black Tulip report, hosted by ENISA.
No quantum computer was involved. The point is the shape of the failure: the protection appeared to be working, the people relying on it had no way to know otherwise, and the exposure reached those least able to absorb it.
What is already protecting you?
More than you might expect, and the tools most widely recommended in high-risk contexts happen to be the ones furthest ahead.
| Tool | Post-quantum status | What to know |
|---|---|---|
| Signal | Deployed 2023 | Among the first systems anywhere. The strongest widely available option |
| Apple iMessage | Deployed February 2024 | Between Apple devices |
| Web traffic | Deployed 2024 to 2025 | Your connection to a website is likely protected |
| Largely not | Content and headers. Treat as exposed | |
| SMS and phone calls | No | Carrier records exist regardless of content |
Source: Signal, “PQXDH,” signal.org; Apple Security Research, February 2024, security.apple.com; Google Security Blog, September 2024, security.googleblog.com; Mozilla, Firefox 135 release notes, mozilla.org.
The practical read: if you’re already using Signal for sensitive contact, the single most important protection is in place, and it has been since 2023.
What can you do about it?
Seven things, ordered by how much they change.
- Use Signal for anything sensitive, from the first message. Protection applies from the start, and the first contact is often the identifying one.
- Treat email as visible. Use it to move a conversation, rather than to hold one.
- Reduce what exists at all. Contact that never happened electronically leaves nothing to store. This remains the most reliable protection available.
- Delete on a schedule. What you’ve deleted can’t be collected from you later.
- Keep devices and apps updated. Post-quantum protection arrives inside normal updates, and an out-of-date app doesn’t have it.
- Think very carefully about genetic testing. It can’t be withdrawn, it identifies relatives who never consented, and roughly 60% of genealogy-database searches for a person of European descent in the U.S. already return a third cousin or closer.
- Ask organizations that hold your records what their timeline is. Shelters, clinics, legal aid, and advocacy organizations hold exactly the categories that matter, often with the thinnest budgets.
Source: Erlich, Shor, Pe’er, and Carmi, “Identity inference of genomic data using long-range familial searches,” Science 362(6415), November 2018, science.org.
What are the honest limits?
Four things this page can’t do for you, stated plainly because false reassurance is worse than none.
- Communications already sent can’t be recalled. If it crossed a network under the older encryption and somebody recorded it, nothing done now changes that.
- Nobody can tell you whether you were collected. Recording leaves no trace, so there’s no way to check and no way to be told.
- Encryption doesn’t protect against a compromised device. If somebody has access to your phone, what happens on the network is beside the point, and for many people in danger the device is the actual threat.
- This is one risk among several, and often not the largest. For someone fleeing an abusive person, shared accounts, location sharing, and physical access to a device are usually more urgent than anything on this page.
That last point matters. The correct response is proportion rather than fear: this is worth understanding, and for most high-risk people it sits below more immediate concerns.
Questions people ask
Should I stop using encrypted messaging? No. The tools most recommended in high-risk contexts are the ones furthest ahead on this, and using them remains far better than not.
Is my old activity already compromised? Unknowable. What’s worth doing is identifying which past contacts would still be dangerous if revealed in 15 years, and treating those as the priority for anything you can still control.
Does a VPN help? It moves where your traffic is visible rather than removing the exposure, since your connection to the provider uses the same kind of encryption. It can help against a local observer.
What about organizations that hold my records? Shelters, clinics, and legal aid hold long-lived, highly sensitive records and frequently have minimal budgets. The question template at How do I ask a company what their quantum plan is works for them.
I’m not sure whether I’m high-risk. A useful test: would it endanger you or someone else if it became known, in 15 years, who you contacted and when? If yes, this page applies. If no, If you read one thing is the right page.
Is this an argument against encryption backdoors? It’s adjacent to that debate and this resource doesn’t take a position on it. What’s stated here is that the protection you rely on has a lifetime, and yours needs to outlast it.
Where to go next
- If you read one thing is the general 3-minute version.
- Protecting your sources covers the same problem from a journalist’s side.
- Is my DNA data safe covers genetic data, which is the least reversible category.
- What should I actually do is the general action list.
- Whats At Risk MOC covers what’s exposed generally.
Go deeper into the technical detail
The technical version, on who is plausibly recording traffic today and what the evidence for it actually is, is Store-Now-Decrypt-Later Actor Landscape.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.