up:: What To Do
Is anyone selling me something I don’t need?
Yes, and it’s going to get worse as more people hear about this.
The structure is familiar. A real, complicated, frightening problem gets public attention, most people can’t evaluate technical claims, and products appear promising to solve it. Y2K had exactly this. So did every major security scare since.
The useful thing is that the tell is unusually clear here, because there is no consumer product that addresses this problem. Not a better one, not a worse one. The category doesn’t exist.
The short version:
- No product you can buy protects you from this. The fix arrives through updates to systems you already use.
- Anything marketed as a quantum-proof phone, router, VPN, USB stick, or subscription is charging for a problem it doesn’t address.
- “Military-grade” and “bank-level” encryption are marketing phrases that describe the half that survives anyway.
- Quantum key distribution is real and is almost certainly irrelevant to you, and its name is frequently borrowed by things that aren’t it.
- The genuine protections are free, arrive automatically, and nobody sells them to you.
Why can’t a product fix this?
Because the problem isn’t on your device.
The vulnerable encryption is in the connections between systems, and in the systems holding your records. Your bank’s servers, your hospital’s network, the certificate system underneath the web. A product installed on your phone or plugged into your laptop has no ability to change any of that.
The fix has to happen at both ends of every connection, which is why it’s arriving through software updates from Apple, Google, Mozilla, Signal, and the companies running the services you use, rather than through anything you could buy.
Detail at Did my phone already fix this?
What are the specific tells?
| What you’ll see | Why it’s a problem |
|---|---|
| ”Quantum-proof” or “quantum-safe” consumer hardware | No consumer device addresses this. The category doesn’t exist. |
| ”Military-grade encryption” | Not a technical term. Usually refers to AES, which is the half that survives. |
| ”Bank-level security” | Same. It’s marketing language, and banks are working on this problem too. |
| ”256-bit encryption” | Describes the surviving half. True, and irrelevant to the question. |
| ”Unhackable” or “unbreakable” | Nobody serious uses these words. |
| A countdown clock to Q-Day | Nobody can date it. A specific countdown is a sales device. |
| ”Protect your data from quantum computers today” sold to consumers | The protection isn’t purchasable by an individual. |
| A subscription for personal quantum protection | Recurring revenue for a service that can’t do anything. |
What about quantum key distribution?
This one’s genuinely real, and it’s almost certainly irrelevant to you, and its name gets borrowed constantly.
Quantum key distribution uses physics rather than mathematics to share a key, and it requires special hardware and usually dedicated fiber between two fixed points. It’s deployed in a small number of specialized settings, and it has nothing to do with the replacement encryption being rolled out across the internet.
Two things follow. If someone offers you consumer quantum key distribution, that isn’t what it is. And if a news story conflates quantum key distribution with post-quantum cryptography, the author hasn’t checked, because they’re completely different technologies solving different problems.
Who’s actually vulnerable to this marketing?
Worth naming, because it isn’t only individuals.
Small businesses get pitched quantum-safe products by resellers, and often have nobody able to evaluate the claim. The honest advice for a small business is the same as for a person: update things, and ask your major vendors what their timeline is.
Nervous executives buy reassurance. A product that lets someone say the company has addressed quantum risk is commercially attractive and rarely does what the name implies.
Anyone who just read a scary article. The moment of maximum fear is the moment of maximum susceptibility, which is why the marketing tends to follow coverage.
What does legitimate look like?
The line is easier than you’d expect.
Legitimate: a company saying it has deployed post-quantum key exchange in its own service, naming the standards, giving a date. That’s a description of work they did on their infrastructure, and you benefit without buying anything.
Not legitimate: a thing sold to you that claims to make you quantum-safe.
The distinction is whether they’re describing their own migration or selling you a personal shield. The first is the whole point. The second doesn’t exist.
Questions people ask
Is my existing VPN useless then? For this, it doesn’t help. VPNs have other legitimate uses, and protecting you from quantum decryption isn’t one of them.
What if a product genuinely uses the new algorithms? Some do, and it’s still not solving your problem, because your exposure is in the systems holding your records rather than on your device. A messaging app using them is meaningful. A USB stick isn’t.
Should I report these products? Consumer-protection agencies take complaints about deceptive marketing, and this is an area where the claims are checkable.
Is this Guide selling me something? Fair question and worth asking of anybody. The whole thing is free with no email gate, and the honest answer to “what should a person buy” is nothing.
Will it get worse? Almost certainly, as coverage increases. The tells above stay reliable.
Where to go next
- What should I actually do? is the list of things that genuinely help, all free.
- Is this overhyped? covers where the hype is and isn’t.
- Did my phone already fix this? covers the protections you already have.
- Back to the Plain English section.
Go deeper into the technical detail
The technical version, three questions that turn any quantum-safe claim into a certificate number, is The Vendor-Claims Checklist.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.