up:: For Policymakers
What does history tell us about broken codes?
That you find out afterward.
Cryptography has roughly 2,500 years of recorded history, and the pattern in it is remarkably consistent. A code is trusted completely. Someone breaks it. The break stays secret for as long as it’s useful, sometimes for decades. The people relying on the code keep using it the entire time, because from their side nothing changed.
For a government deciding how to handle the quantum transition, that’s the most useful evidence available, and it argues against the instinct most institutions have, which is to wait for confirmation before acting.
The short version:
- Venona is the exact precedent. The United States collected Soviet cables it couldn’t read, stored them, and broke them years later, exposing agents long after the messages were sent.
- Enigma shows what a state does with an advantage. Britain broke it and then built an entire apparatus to hide that fact, including a fictional spy, and the secret held for about 30 years after the war.
- The pattern is that breaks are invisible while they matter. That’s precisely when it matters whether you were protected.
- So no announcement is coming. Whoever gets there first has every reason to say nothing and read quietly.
- Which means detection can’t be the plan. The only defense that works is being migrated before, rather than responding after.
Venona: the thing that already happened
During and after the Second World War, U.S. codebreakers intercepted and stored Soviet diplomatic and intelligence cables they had no ability to read. They kept them anyway.
Years later, the Venona project found a weakness in how that traffic had been protected and began working through the backlog. Messages sent long before became readable, and the people who had sent them were identified well after the fact.
Collect while you can’t read. Store. Wait for a break. Read the archive backwards.
That’s not an analogy for what’s happening now. It’s the same operation, and the only thing the quantum era changes is the nature of the break, from a procedural mistake in how keys were used to a machine that undoes the mathematics directly.
Source: NSA, “Venona” historical release; Simon Singh, The Code Book, 1999, chapter on Venona.
Enigma: what a state does when it holds the advantage
The concealment is the more instructive half of the record.
Once Britain could read Enigma traffic, protecting that capability became as important as the intelligence it produced. British intelligence attributed decrypts to a fictional master spy, “Boniface,” and dispatched reconnaissance flights over targets that had already been located by decryption, so that the other side would credit the sighting to the aircraft rather than suspect the cipher.
The German military continued using Enigma throughout, because from their side there was nothing to notice.
And the fact of the break stayed classified for roughly 30 years after the war ended.
Source: John Ferris, Behind the Enigma: The Authorised History of GCHQ. Further detail at The No-Warning Problem.
What’s the pattern, stated plainly?
Three things recur across the record, and each has a direct consequence for how a government should plan.
| What history shows | What it means for policy |
|---|---|
| Breaks stay secret while they’re useful | You will not receive an announcement, so planning that depends on one fails |
| The victim keeps using the broken system | Absence of an incident is not evidence of safety |
| Concealment is deliberate and well resourced | The party with the advantage is actively investing in your not knowing |
| Exposure is retroactive | Material already sent is already committed, whatever you do afterward |
| Discovery comes decades later | Accountability arrives long after the people responsible have moved on |
So why does this matter for the quantum decision?
Because the ordinary way institutions handle security risk depends on a warning that isn’t going to arrive.
Normally an organization waits for evidence, responds to the incident, and adjusts. That works when attacks are noisy. This one produces nothing to detect, and the historical record says that whoever reaches a capability like this first will have strong reasons to keep it quiet and use it, exactly as states have done every previous time.
The consequence for a policymaker is narrow and specific: the arrival of the capability and the knowledge of its arrival are separate events, possibly separated by many years. Any timeline built on “we’ll move when it’s confirmed” is a timeline built on the second event, and the exposure is set by the first.
The counterpart in the technical layer is The No-Warning Problem.
Does this apply to allies as well as adversaries?
It applies to the structure rather than to any particular country.
Alliances share intelligence, and shared intelligence depends on compatible cryptography. When members migrate on different schedules, the practical consequence is that secure channels between them fall back to whatever both ends still support, which is the older method. A member that finishes early inherits the exposure of one that finishes late.
Long-lived platforms make this concrete. Aircraft, ships, satellites, and command systems are procured with service lives measured in decades, and the cryptography inside them is frequently fixed at the point of manufacture. A platform entering service today may still be flying well past the dates by which the current encryption is meant to be retired.
More on how the national deadlines diverge at What are other countries doing?
Questions people ask
Isn’t this just an argument from analogy? Venona is the same operation rather than an analogy: collection of unreadable material, storage, and later decryption. Enigma is offered as evidence of institutional behavior, which is a claim about what states do rather than about mathematics.
Could a break be announced for deterrence? Possibly, and it would be a choice rather than a necessity. The historical default runs the other way, because announcing it ends the intelligence value immediately.
How long did these things stay secret? Venona’s existence was withheld for decades, and the Enigma break stayed classified roughly 30 years past the end of the war. Both are far longer than most planning horizons.
Does this mean adversaries already have the machine? No, and nothing here supports that claim. It means the absence of an announcement is uninformative either way, which is a much weaker and much more defensible statement.
What’s the practical instruction? Treat migration as insurance against something you won’t be told about, and set the schedule from how long your material must stay secret rather than from a forecast of the machine.
Where to go next
- What laws and rules already exist? covers the instruments already in force.
- What critical infrastructure is exposed? covers the systems with the longest lives.
- When is this going to happen? covers what the forecasts actually say.
Go deeper into the technical detail
The technical treatment is The No-Warning Problem and Store-Now-Decrypt-Later Actor Landscape.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.