TENDAI . G
Back to journal
security08 Dec 2025

Post-Quantum Cryptography: What Every Developer Needs to Know

Tendai Gumunyu11 min read
Post-Quantum Cryptography: What Every Developer Needs to Know

A practical developer guide to post-quantum cryptography: harvest-now-decrypt-later risk, the new NIST algorithms, and what to migrate first.

Post-Quantum Cryptography: What Every Developer Needs to Know

The uncomfortable part of post-quantum cryptography is not the future. It is the present. Encrypted traffic captured today can be stored cheaply and decrypted years later, once a sufficiently capable quantum computer exists. Cryptographers call this harvest now, decrypt later, and it means the deadline for protecting long-lived secrets has already passed.

If the data you transmit still matters in 2035 — medical records, legal files, identity documents, state contracts — this is a today problem.

What breaks, and what does not

PrimitiveQuantum impactAction
RSA, ECDSA, Diffie-HellmanBroken by Shor's algorithmMust be replaced
AES-128Effective strength halvedMove to AES-256
SHA-256Modest weakeningFine; prefer SHA-384 for new work
bcrypt / Argon2 password hashingLargely unaffectedNo change

In short: symmetric cryptography survives with bigger keys. Public-key cryptography — the part that protects every TLS handshake, every signed token, every code signature — does not.

The replacements

  • ML-KEM (Kyber) — key encapsulation. This is what replaces the key exchange in TLS.
  • ML-DSA (Dilithium) — general-purpose digital signatures.
  • SLH-DSA (SPHINCS+) — hash-based signatures, slower and larger but resting on very conservative assumptions. Good for firmware and root-of-trust signing.

All three are standardised. Support is already shipping in OpenSSL, Go, BoringSSL and the major CDNs, generally as hybrid modes that combine a classical algorithm with a post-quantum one — so you are no worse off if the new maths disappoints.

What to do, in order

  1. Build a cryptographic inventory. You cannot migrate what you cannot list. Where do you use TLS, JWT signing, code signing, database encryption, VPN tunnels, third-party APIs? Most teams are surprised by how long this list is.
  2. Classify by lifetime. Session cookies expiring in an hour carry no harvest risk. Patient records, ID copies and signed contracts carry decades of it. Migrate by data lifetime, not by system importance.
  3. Turn on hybrid TLS. The cheapest real win. If you sit behind Cloudflare or a modern load balancer, this is often a configuration toggle plus a modern TLS library.
  4. Achieve crypto-agility. The actual engineering work is removing hardcoded algorithm choices so the next change is a config edit, not a rewrite. Assume there will be a next change.
  5. Push your vendors. Payment providers, identity providers and HSM suppliers all need roadmaps. Ask now; procurement takes longer than code.

The practical costs

Post-quantum keys and signatures are larger — ML-KEM handshakes add roughly a kilobyte, ML-DSA signatures are several kilobytes against ECDSA's sixty-four bytes. For a web app this is invisible. For constrained IoT devices, embedded firmware or protocols squeezed into single packets, it is a genuine design constraint worth measuring before you commit.

Frequently asked questions

When will quantum computers actually break RSA?

Nobody credible gives a firm date; estimates cluster in the 2030s and have a wide error bar. The date does not change the plan, because harvest-now-decrypt-later already makes today's traffic vulnerable.

Do I need to do anything for a normal business website?

Keep TLS current and let your CDN or host enable hybrid key exchange. That covers you. The heavy work belongs to teams handling long-lived sensitive data or building their own protocols.

Is this relevant to POPIA compliance?

POPIA requires appropriate technical safeguards for personal information. For data you are obliged to retain for years, "appropriate" is drifting towards quantum-resistant transport. Not a requirement today; a defensible position tomorrow.

The takeaway

You do not need to rewrite your cryptography this quarter. You do need to know where it lives, how long your secrets must last, and whether swapping an algorithm is a config change or a six-month project. Answer those three and the migration becomes routine.

Continue Reading

Need a security-minded build? See services, projects, or get in touch.

Work with me

LET’S TALK

Have a project in mind after reading this? Send a brief and I usually reply within 24 to 48 hours.

Start a project →

More reading

All articles