up:: Start Here
Is this overhyped?
Parts of it, genuinely and badly. Being specific about which parts is what makes the rest believable.
There’s real money riding on you feeling urgent about this. Quantum hardware companies raise capital on the machine seeming close, and security vendors sell products on the threat seeming imminent. Both can be entirely right about the underlying problem while still having a stake in how alarmed you are.
So here’s the strongest case against everything else in this section, stated at full strength rather than knocked down.
The short version:
- No machine capable of this exists, and current ones are orders of magnitude short.
- The engineering may not work. Getting from error-prone parts to a reliable large machine is unsolved.
- A serious mathematician argues it may never work, and that’s a real scientific position rather than denial.
- People selling things have reasons to exaggerate, and some of them do.
- The skeptics are right that nobody can name the year.
- The counterargument doesn’t dispute any of that, and rests on the damage being retroactive and the fix being cheap.
What’s the strongest case against all this?
Four parts, and each one is legitimate.
1. No such machine exists. Today’s quantum computers have hundreds to low thousands of error-prone qubits. Breaking a real encryption key is estimated to need thousands of stable ones, each assembled from many error-prone ones correcting each other. The threat is a projection rather than a demonstration, and that distinction is fair.
2. The engineering problem is unsolved. Getting from noisy parts to a large error-corrected machine means holding error rates below a threshold at enormous scale. Nobody has done it, and treating it as a foregone conclusion overstates what’s actually been built.
3. A credible minority argues it may never work. The mathematician Gil Kalai has argued for over a decade that noise in quantum systems is a fundamental barrier rather than an engineering obstacle, because the correlated noise that accompanies quantum computation defeats the error correction the whole approach depends on. This is a mathematically framed position held by a serious researcher, and it deserves an honest hearing rather than a dismissal.
Source: G. Kalai, “How Quantum Computers Fail,” arXiv:1106.0485, June 2011, arxiv.org.
4. There’s money in urgency. Quantum hardware companies raise on imminence. Some security vendors market products by inflating near-term danger. A financial interest doesn’t make a threat fake, and it does mean specific timeline claims deserve a skeptical read.
Put together, the skeptic case is genuinely strong on one point: nobody can honestly promise the year, and some people naming years are selling something. That much is correct, and anyone pretending otherwise loses credibility.
So what’s the response?
The counterargument doesn’t dispute any of the four points above. It says the decision doesn’t depend on resolving them.
The damage is retroactive. If the risk were only that a future machine reads your future traffic, waiting would be sensible. The risk is that a future machine reads the traffic being collected today, so anything with a long secrecy life is already committed. That holds whether the machine arrives in 10 years or 30.
The fix is cheap relative to the downside. The replacement standards are published, tested, and shipping in everyday software. Deploying them costs money and effort at a scale organizations spend routinely. Being wrong in the other direction is unbounded and irreversible.
So the asymmetry settles it, rather than the probability. Even taking Kalai’s position seriously as a real chance the machine never arrives, a low-probability catastrophic and irreversible outcome against a modest known cost is exactly the shape of risk that justifies insurance. That’s a judgment most institutions make about far less serious things.
What does a calibrated position sound like?
Someone honest about this can say plainly which claims are hype and still conclude that migrating now is correct. Those aren’t in tension.
Hype, and you should push back on it:
- A specific near-term date for when encryption breaks.
- “Quantum breaks all encryption.” It breaks a specific half.
- Any product sold as making you quantum-proof.
- A qubit-count headline presented as meaningful progress toward breaking encryption.
- Claims that encryption is already broken.
Sober, and it holds up:
- Data with a long secrecy life is exposed to collection today.
- The replacement standards exist and are being deployed.
- Real deadlines exist in published government policy.
- Nobody knows the arrival date, and the range is wide.
The tell of a trustworthy source is that they’ll say the first list out loud.
The two sides, side by side
| The skeptic’s point (fair) | The response |
|---|---|
| No capable machine exists today | True, and data collected now is exposed whenever one arrives |
| The engineering may never work | Possible, which makes this insurance rather than a certainty |
| Kalai may be right that noise defeats it | A real minority view, weighed against growing experimental progress |
| Vendors exaggerate for funding | Read timeline claims critically; the retroactive logic stands on its own |
| Adopting new encryption seems premature | The standards are published, tested, and cheap to deploy |
How do you check a claim yourself?
Five questions, and they catch most of what’s wrong in coverage of this.
- What did the machine actually do? Simulating a molecule, sampling a distribution, and factoring a number relevant to real encryption are three entirely different achievements. The third has never happened publicly.
- Which number are they quoting? Qubit counts are the most quoted and least informative figure available.
- Who checked it? A company blog, a preprint, and an independently reproduced peer-reviewed result are three very different confidence levels.
- Real key or toy key? Demonstrations factoring tiny numbers recur every few years and get reported as breaks each time.
- Who benefits from the framing? Ask what the source sells.
Questions people ask
Is the person telling me this selling something? Reasonable question, always. Ask it about anybody, including this Guide, and check whether they’ll name what’s overhyped.
Could the whole thing turn out to be nothing? Yes, and Kalai’s position is exactly that argument. It’s a minority view held against a growing body of experimental progress, and it’s a real possibility rather than a comfort.
If it’s uncertain, why act? Because the cost of acting is modest and known, and the cost of being wrong is unbounded and can’t be undone afterward.
Isn’t this just Y2K? A fair comparison, and it doesn’t resolve the way people assume, since Y2K was largely averted precisely because people spent years and billions quietly fixing it. See When is this going to happen?
Where to go next
- When is this going to happen? has the actual expert numbers.
- What of mine is actually worth stealing? is the honest sort of what does and doesn’t matter.
- Is anyone selling me something I don’t need? covers the consumer products.
Go deeper into the technical detail
The technical version, with the full steelman and rebuttal, is Is the Quantum Threat Overhyped.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.