up:: What’s At Risk

What of mine is actually worth stealing?

Almost none of it, and that’s the honest place to start.

Someone copying your data today has to store it for years before they can read a word of it. That only pays off for information that’ll still be worth something when they finally open it. Most of what you send won’t be.

So there’s one question that sorts your entire digital life: in 15 years, would this still be sensitive?

The short version:

  • The sorting rule is how long something stays sensitive, and nothing else.
  • Tier 1 is anything you can never change back, covering DNA, fingerprints, and date of birth. These fail the test under any timeline.
  • Tier 2 is health, which stays true and stays consequential for the rest of your life.
  • Tier 3 is money, movement, and paperwork, sensitive for years or decades rather than forever.
  • Tier 4 is the material that’s harmless right up until your circumstances change.
  • Everything else, which is most of what you send, is genuinely fine.

Tier 1: what can you never change back?

This is the worst tier, and it’s worst for one reason. A stolen credit card gets reissued by Friday. Nothing here can be reissued at all.

Your DNA. A genome identifies you for life, and it partially identifies your children, parents, and siblings, none of whom agreed to anything. The NIH’s genome institute says plainly that a DNA sample can never be truly anonymized.

Research published in Science found that roughly 60% of searches in genealogy databases for a person of European descent in the U.S. already turn up a third cousin or closer, which is enough to identify people who never took a test. A kit bought as a gift enrolls your whole family by implication.

Source: NHGRI, “Genomic Data Privacy,” genome.gov; Erlich, Shor, Pe’er, and Carmi, “Identity inference of genomic data using long-range familial searches,” Science 362(6415), November 2018, science.org.

Your fingerprints and face. The things that unlock your phone, cross a border, or clock you in at work only work as identification because they can’t change. A scan opened in 12 years is exactly as usable as one taken today. NIST’s own guidance puts it flatly: biometric characteristics don’t constitute secrets.

Source: NIST SP 800-63B § 5.2.3, pages.nist.gov.

The identity basics. Your date of birth, your mother’s maiden name, your Social Security number, and that photo of your passport still sitting in an old email. Almost none of it can be changed, and together it’s the raw material for identity theft across a whole life.

Your kids. Everything above applies harder to a child, because they’ll live another 80 years with it and consented to none of it. A newborn’s genome, a pediatric record, and the biometrics collected at a school gate all belong to someone who had no say.

Tier 2: what happens to your health records?

Your medical history. Diagnoses, prescriptions, therapy, psychiatric treatment, reproductive-health decisions, addiction treatment, disability records. The facts stay true, and they stay consequential for insurance, employment, custody, and how you get treated, for as long as you live.

Your health apps. Heart rate, sleep, period and fertility tracking, workout routes. They sync constantly over connections that are vulnerable right now, and together they rebuild much of the medical record above without a doctor being involved at all.

Your messages and photos. One mailbox opened is decades of relationships, arguments, money, and secrets, all searchable at once. Cloud photo libraries and phone backups, intimate pictures included, hold an entire life in one place.

Tier 3: what about your money and paperwork?

Your financial life. Bank records, tax filings, retirement accounts. A 30-year fixed mortgage, which Freddie Mac describes as the product of choice for nearly 90% of American homebuyers, is one set of documents that stays live for three decades.

Source: Freddie Mac, “Finding the Right Loan,” myhome.freddiemac.com.

Where you’ve been. Years of location history from a phone and a car shows where you live, work, worship, seek medical care, and who you spend time with. The pattern stays identifying long after any single trip stops mattering.

Legal and immigration paperwork. Family-court files, custody disputes, asylum claims, expunged criminal records. For these, exposure years later can undo the exact protection the legal process was meant to give you.

Password vaults and crypto wallets. A captured password manager is every account you had at the moment it was taken, and a decrypted seed phrase is the coins, for as long as those keys still control them.

Tier 4: what turns dangerous only if your life changes?

Some information is completely harmless until a situation turns, and then it’s the most dangerous thing you own. Who you voted for and donated to. Whether you organized at work. What you believe. Your sexual orientation and gender identity. An abortion. An affair. An immigration status. A diagnosis you never disclosed.

None of it’s a problem while your government, employer, landlord, insurer, and family stay friendly. Retroactive decryption means the safety of that information depends on your circumstances 15 years from now, and nobody gets to pick their future circumstances.

Because harvested data gets decrypted in bulk, this would surface for very large numbers of people at once rather than one person at a time.

How long does each one stay dangerous?

What it isStays sensitive forSource anchor
DNABeyond a lifetime, and it reaches relativesNHGRI; Erlich et al., Science 2018
Fingerprints and face scansA lifetime, and they can’t be reissuedNIST SP 800-63B § 5.2.3
Date of birth, Social Security numberA lifetime, and they’re rarely changeableIdentity-theft mechanics
Medical recordsA lifetime45 CFR § 164.316; lifelong clinical relevance
A 30-year mortgageUp to 30 yearsFreddie Mac
Court and immigration paperworkThe life of the matter plus yearsRetention floors and the durability of the facts
Email and photo archivesAs long as the archive existsBackup and retention reality
Everyday texts and browsingDays to weeksRotation and retention reality

Stacked bar chart showing how long each kind of data must stay confidential plus 10 years to migrate, against the 15-year mark where a majority of surveyed experts first rate a capable machine likely or better. A 30-year mortgage file, classified information, health records and broker-dealer records all run past that mark. Routine operational traffic does not.

Source: 45 CFR 164.316; 17 CFR 240.17a-4; EO 13526; Freddie Mac; NCSC, Canada TBS and EU NIS CG schedules; Global Risk Institute.

The 10 years in that chart is the span the UK, Canada, and the EU each allow their own institutions for a completed migration, which makes it the most defensible figure available for how long this takes when somebody actually plans it.

What can you honestly stop worrying about?

This part matters as much as the rest, because a warning that covers everything is useless.

Your everyday messages, what you streamed last night, your food delivery orders, your search for a plumber, and the overwhelming majority of your normal traffic will be worthless to anybody who opens it in 15 years. Anything already public stays public and reveals nothing new. Session logins expire on their own.

If someone tells you all of your data is equally at risk, they’ve stopped describing the actual problem.

What does this look like for one person?

The numbers above describe a population. Here is how the same timeline lands on a single life.

A woman takes a consumer DNA test in 2018 to find out about her grandparents. In doing so she also puts her siblings, her parents, and her future children into a genetic database, because a genome identifies relatives who never consented.

Somewhere between then and now, her traffic crossing the internet gets copied and stored. She is never told, because nothing broke.

In 2023 her account details are exposed in the 23andMe breach, one of 6.9 million people caught through relative matching, though she personally did nothing wrong. In 2025 the company files for bankruptcy and her genetic data becomes a saleable asset, and a state attorney general tells her, through a press release she may never see, that she has a right to delete it.

Meanwhile the therapy she started in 2019, the fertility app she used in 2021, and the immigration paperwork she filed for her mother all crossed the same networks under the same encryption.

Say a machine capable of reading the stored copies arrives in 2038. She will be in her fifties. Her genome will be exactly as identifying as it was in 2018. Her diagnoses will still be true. Her mother’s immigration file will still describe her mother. Whether any of it harms her depends entirely on who holds it and what the world looks like then, and none of those are things she gets to decide.

At no point in that sequence does she receive a notification, and at no point could she have bought anything to prevent it.

Questions people ask

Why does it matter how long something stays sensitive? Because the person copying it can’t read it for years. They’re making a bet about what’ll still be worth something later, and most of your traffic loses that bet.

Isn’t my data encrypted already? Yes, and that’s exactly why this works the way it does. It gets copied while encrypted and stored until the encryption can be undone. See Is someone stealing my data right now?

Which tier should worry me most? Tier 1, and it isn’t close. Everything else can eventually be changed, replaced, or outlived.

Does deleting things help? Yes, genuinely. Anything you’ve already deleted can’t be copied from you later, and it’s the cheapest protection available to you.

Where to go next

Go deeper into the technical detail

The technical catalog, covering business data as well and with a source behind every row, is What Data Is Vulnerable to Harvest Now, Decrypt Later.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.