Harvest Now, Decrypt Later
What is Harvest Now, Decrypt Later?
Harvest Now, Decrypt LaterAn attack strategy where adversaries record encrypted traffic today to decrypt it once cryptographically relevant quantum computers become available.
Harvest now, decrypt later (HNDL), also called store-now-decrypt-later, describes adversaries who intercept and archive encrypted communications today, betting that a future cryptographically relevant quantum computer (CRQC) will break the underlying public-key schemes — RSA and elliptic-curve Diffie-Hellman — via Shor's algorithm. The data need not be readable now; it only has to still be valuable when decryption becomes feasible.
The threat is governed by Mosca's inequality: if the time data must stay secret (X) plus the time to migrate systems (Y) exceeds the time until a CRQC arrives (Z), you are already exposed. It is most acute for long-lived secrets — state intelligence, health and genomic records, intellectual property, and root or CA keys — whose value persists for decades.
Defences center on migrating to NIST's post-quantum standards, finalized on 13 August 2024: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures. In practice, deployments favour hybrid key exchange such as X25519MLKEM768, already shipping in Chrome, Firefox and Cloudflare TLS, so a session stays safe if either component holds. The NSA's CNSA 2.0 suite sets a phased migration timeline. Shortening secret lifetimes and enforcing crypto agility let organizations swap algorithms without redesign.
flowchart LR A[Attacker intercepts encrypted traffic today] --> B[Store ciphertext in long-term archive] B --> C[Wait years for quantum computer] C --> D[CRQC runs Shor's algorithm] D --> E[Break RSA / ECDH key exchange] E --> F[Decrypt archived sessions] G[Defence: hybrid PQC key exchange now] -.blocks.-> F
● Examples
- 01
A nation-state tapping a transatlantic cable to archive encrypted diplomatic traffic for future quantum decryption.
- 02
Mandating hybrid X25519+ML-KEM in TLS to neutralize captured 2026 sessions in a post-quantum world.
● Frequently asked questions
What is Harvest Now, Decrypt Later?
An attack strategy where adversaries record encrypted traffic today to decrypt it once cryptographically relevant quantum computers become available. It belongs to the Cryptography category of cybersecurity.
What does Harvest Now, Decrypt Later mean?
An attack strategy where adversaries record encrypted traffic today to decrypt it once cryptographically relevant quantum computers become available.
How do you defend against Harvest Now, Decrypt Later?
Defences for Harvest Now, Decrypt Later typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for Harvest Now, Decrypt Later?
Common alternative names include: HNDL, Store now, decrypt later.