up:: 00 Start Here

What’s At Risk

Most of what you send will never matter to anybody. That’s the honest starting point, and it’s what makes the rest of this believable.

The question that sorts it is simple: in 15 years, would this still be sensitive? Your lunch plans, no. Your genome, your fingerprints, and your psychiatric history, yes, and none of those can be changed once they’re out.

5 things you must understand about Q-Day

  1. It only reaches information that’s still sensitive when it arrives. Most of what you send is worthless to somebody opening it in 15 years, and that’s the honest half of this.
  2. Permanent identifiers are the worst case. A credit card gets reissued by Friday. Your genome, your fingerprints, and your medical history stay yours for life.
  3. Your DNA exposes your relatives too. Roughly 60% of searches in genealogy databases for a person of European descent in the U.S. already return a third cousin or closer, so 1 person’s test reaches a whole family.
  4. No notification is coming. Copying encrypted data breaks nothing and triggers no alarm, and every breach-notification law is built around an intruder being detected.
  5. Your passwords are largely a separate story. Well-run services store a one-way fingerprint of a password rather than the password, and that method survives.

Source: Erlich, Shor, Pe’er, and Carmi, “Identity inference of genomic data using long-range familial searches,” Science 362(6415), November 2018, science.org; NIST, “Report on Post-Quantum Cryptography,” NISTIR 8105, csrc.nist.gov.

The short version:

  • Anything permanent is the worst case. Your DNA and your fingerprints stay yours for life, where a stolen credit card gets reissued by Friday.
  • Your DNA also exposes your relatives. Roughly 60% of searches in genealogy databases for a person of European descent in the U.S. already turn up a third cousin or closer.
  • Medical history stays true and stays consequential for the rest of your life, which puts it near the top.
  • Most day-to-day traffic is worthless to somebody opening it in 15 years, and saying so is the honest half of this.
  • You’ll never receive a notification, because nothing gets broken into and no law covers what actually happens.
  • Some things can’t be repaired at all. Pacemakers, insulin pumps, and cars carry encryption frozen into the hardware.

What lives here

  1. Is someone stealing my data right now? What’s actually being taken, why they’d keep something they can’t read, and what the government has said about it.
  2. What of mine is actually worth stealing? The full sort, from things that can never be changed down to things nobody will ever care about.
  3. Is my DNA data safe? Why genetic data is the worst case, and what already happened to 23andMe’s customers.
  4. Are my medical records safe? Diagnoses, therapy, fertility apps, and why a lifetime of sensitivity is the problem.
  5. Will anyone ever tell me if it happens? The short answer is no, and the reason is worth understanding.
  6. Are my passwords at risk? Largely no, and here’s the actual reason.
  7. What about my Bitcoin? A genuinely different situation from everything else here.
  8. Is my pacemaker safe? Devices that outlive the deadline and can’t be updated over the air.

Where to go next

Go deeper into the technical detail

The arguments go further than this page does. The No-Warning Problem explains why no announcement is coming, and The Quantum Capability Asymmetry covers why recording your data is cheap today while reading it will stay expensive and rare. The technical catalog, sorted by how long each category stays sensitive, is What Data Is Vulnerable to Harvest Now, Decrypt Later.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.