Store Now, Decrypt Later: Why Your Encryption Protocols Are Already at Risk
You don’t need a working quantum computer to steal data that quantum computers will later be able to read. That’s the uncomfortable core of “Store Now, Decrypt Later” (SNDL) — and it’s why the protocols protecting your data right now deserve a second look, even though large-scale quantum decryption is still years away.
What “Store Now, Decrypt Later” Actually Means
Encrypted traffic captured today — a VPN session, an API call, a signed email — can simply be stored. It doesn’t need to be broken today. Intelligence agencies, state actors, and increasingly well-funded criminal groups can archive terabytes of intercepted, still-encrypted data and wait. Once a cryptographically relevant quantum computer exists, that stored traffic can be decrypted retroactively.
For data with a short shelf life, this isn’t a huge concern. But for anything that needs to stay confidential for 10, 15, or 20 years — patient records, government communications, IP filings, M&A documents, source code, long-lived credentials — the math is already running against you. The attack window opened the day you sent the data, not the day the quantum computer arrives.
Which Protocols Are Actually Exposed
Almost every protocol securing enterprise communication today leans on the same two mathematical problems: integer factorization (RSA) and elliptic curve discrete logarithms (ECC/ECDH). Both are the exact problems Shor’s algorithm was designed to solve. That includes:
- TLS 1.2/1.3 — the backbone of HTTPS and most API traffic, using RSA or ECDHE key exchange
- IPsec/IKEv2 VPNs — corporate site-to-site and remote-access tunnels
- S/MIME and PGP — signed and encrypted email
- SSH — administrative access to servers and infrastructure
None of these protocols are “broken” today. But the key exchange happening inside them is precisely what a future quantum computer will target — and that exchange is visible to anyone capturing the traffic now.
What Quantum-Safe Protocols Look Like
The practical fix isn’t waiting for a single “quantum-proof” replacement — it’s hybrid key exchange: combining a classical algorithm (like ECDH) with a post-quantum algorithm (like ML-KEM, formerly Kyber) in the same handshake. If either algorithm holds, the session stays secure. Major browsers and TLS libraries have already started rolling this out for HTTPS; the same logic needs to extend to VPNs, internal APIs, and machine-to-machine communication — not just the public web.
The catch: most organizations don’t actually know where RSA/ECC key exchange is buried in their stack. It’s inside load balancers, IoT firmware, legacy APIs, and third-party libraries nobody has audited in years.
Closing the Window Without a Rebuild
This is exactly the gap QuantumConnect is built for: it protects communication between applications, APIs, and systems with quantum-resistant encryption without requiring a redesign of existing architecture. Combined with PQInfraProtect, which delivers infrastructure-wide post-quantum protection without touching individual applications or protocols one by one, organizations can close the SNDL window on their most exposed traffic in days rather than a multi-year migration project.
The uncomfortable truth about SNDL is that it rewards procrastination the least. Every week of exposed key exchange is another week of data sitting in someone’s archive, waiting.
Next in this series: a new Caltech/Google paper just cut the number of qubits needed to break RSA and ECC by orders of magnitude — we’ll break down what that means for your migration timeline.
Want to know which of your protocols are still relying on classical key exchange? Request a Security Audit.






