up:: What To Do
What should I actually do?
Six things, and the first one covers most of it.
The list is short because almost all of the repair happens above your head, by the companies and institutions running the systems you use. A lot of it has already happened without anybody telling you. What’s left for you is free, takes very little time, and is mostly about avoiding permanent decisions rather than taking urgent action.
Anybody handing you a longer list is usually selling something.
The short version:
| What to do | How much it matters |
|---|---|
| Keep devices and apps updated | Most of the value. This is how the protection reaches you. |
| Use a messenger that’s been upgraded | High, for anything private for years |
| Delete what you’re finished with | High, and permanent |
| Think hard before a DNA test | Highest for anything permanent, and can’t be undone |
| Ask the places holding your records | Moderate, and it compounds when many people do it |
| Buy nothing | Saves you money and disappointment |
1. Are your devices and apps updated?
This is the whole consumer action item that matters, and it’s why Signal and iMessage users already have protection they never asked for.
The new encryption arrives through everyday software updates. Signal shipped it in 2023, Apple in February 2024, and the major browsers between November 2024 and February 2025. If you’re running current software, some of your traffic is already protected.
The corollary matters as much: a device that’s stopped receiving updates stops receiving improvements like this one. A phone past its support window will never get this, no matter how well it still works.
Detail at Did my phone already fix this?
2. Which messenger should you use?
For anything that has to stay private for years, use an app that’s done this work. Signal and iMessage have. Apps still using the older method remain copyable in transit.
On Android, the answer is Signal, and it’s the same app with the same protection an iPhone user gets. That matters because iMessage is Apple-only, so Signal is the one option that covers everybody.
Regular texting is a separate thing. Messages between Android phones and iPhones became end-to-end encrypted through the RCS Universal Profile 3.0, which is a real privacy improvement, and it uses classical cryptography, so a recording kept long enough is still readable later. The platform-by-platform picture is at Did my phone already fix this?
For most conversations this genuinely doesn’t matter, because most conversations aren’t worth storing for a decade. It matters for the ones you’d mind being read in 2040.
3. What should you delete?
Underrated, permanent, and completely free.
Data you’ve already deleted can’t be copied from you later. Old email archives, cloud photo backups you’ve forgotten about, health-app history, and dormant accounts holding documents you uploaded once are all worth clearing out.
This is the only item on the list that reduces exposure that already exists rather than protecting you going forward.
4. What decisions can you never take back?
The single highest-stakes decision still fully in your hands.
A DNA test can’t be withdrawn, and it enrolls your relatives who never agreed to anything. Biometric enrollment is similar: a password is changeable, and a fingerprint is yours for life.
That doesn’t mean never. It means treating those as decisions with a permanent horizon, and for genetic testing, treating it as a family conversation rather than a personal one.
Detail at Is my DNA data safe?
5. Who should you be asking?
Your doctor, bank, insurer, and employer hold the categories that actually matter, and none of them are things you can protect yourself.
Asking them what their timeline is does two things. It gets you an answer about your own exposure, and it registers as a customer question, which is one of the few inputs that reliably moves a security budget.
There’s a copy-and-paste template at How do I ask a company what their quantum plan is?
6. Is there anything worth buying?
No consumer product solves this.
Anybody selling you a quantum-proof phone, router, VPN, USB stick, or subscription is charging for a problem their product doesn’t address.
The short answer is no. Nothing on a shelf helps. The protections that matter arrive through updates from the companies running the systems you already use, and through work done by institutions you’ll never see.
Detail at Is anyone selling me something I don’t need?
What can you safely ignore?
As much as possible, because a warning that covers everything is useless.
- Your everyday messages, browsing, and streaming. Worthless to anybody who opens them in 15 years.
- Your passwords themselves. Largely unaffected, and the real threats are reuse and phishing. See Are my passwords at risk?
- Your bank account being emptied. Not the risk. Reading old traffic reveals information rather than granting access to money.
- Any product marketed as quantum-safe for consumers.
- Panic about your medical devices. See Is my pacemaker safe?
Questions people ask
Is that really all? For an individual, broadly yes. The scale of this problem is enormous and almost none of it is at your layer, which is genuinely good news rather than a brush-off.
Should I stop using the internet? No, and it wouldn’t help. Anything already copied is already copied.
Do I need to act this week? No. Update your devices, and think before your next DNA test. Nothing here is an emergency for an individual.
What if I’ve already done all the risky things? Most people have, and that’s fine. Put your attention on decisions still ahead of you rather than ones already made.
Who should be doing more? The institutions holding your records, and the regulators overseeing them. See What should my doctor and my bank be doing?
Does this list change if I’m on Android? Barely. Use Signal instead of iMessage, and make sure your lock screen is a real PIN, pattern, or password, because that’s what encrypts your backups. Everything else on the list is identical.
Should I turn on Advanced Data Protection? Yes, and for reasons other than this. Apple’s published list of quantum-secure features covers iMessage, TLS, VPN, SSH, the Watch connection, and its developer APIs, and iCloud isn’t on it, so count it as a privacy improvement rather than one of the 6 items above.
Source: Apple, “Quantum-secure cryptography in Apple operating systems,” support.apple.com.
Where to go next
- The question template is the highest-leverage thing on this page.
- What of mine is actually worth stealing? helps you decide what applies to you.
- Did my phone already fix this? covers what’s already been repaired.
- Back to the Plain English section.
Go deeper into the technical detail
The technical version, the full executive playbook with the six-phase roadmap, is Own Your Quantum Risk.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.