There is a scene near the end of a heist movie where the crew swaps out a painting in a museum so quietly that the guards never notice. The forgery hangs in the gilded frame for years before anyone realizes the original is gone. Something not entirely unlike that is happening right now to the internet’s backbone. Except this time, the “painting” is the cryptographic machinery that protects your banking session, your medical records, your Signal messages, and the forgery is actually better than the original. And almost nobody is talking about it.
In August 2024, the National Institute of Standards and Technology finalized its first post-quantum cryptographic standards: FIPS 203, 204, and 205. After eight years of a global competition that drew submissions from cryptographers in academia, industry, and government labs across dozens of countries, NIST chose the algorithms that will replace RSA and elliptic curve cryptography—the mathematical bedrock of nearly every secure digital connection on Earth. The reason is simple and unsettling: a sufficiently powerful quantum computer, running Shor’s algorithm, could break RSA-2048 in hours. That machine doesn’t exist yet. But the threat is close enough that the largest technology companies on the planet are already moving.
The Quiet Panic
What makes this migration unusual is its tone. Previous transitions in the cryptographic world—the move from DES to AES, the deprecation of MD5, the rollout of TLS 1.3—were accompanied by urgency, debate, and public posturing from security researchers. This one feels different. It is happening in a register somewhere between whispered and muttered.
Part of that is strategic. Governments and major corporations are acutely aware of “harvest now, decrypt later” attacks, in which adversaries scoop up encrypted traffic today and store it for the day a quantum computer arrives. The data you send across HTTPS today—sensitive, identifiable, potentially compromising—could be retroactively cracked in 2032 or 2035 or 2040. Nobody knows exactly when the cryptographically relevant quantum computer arrives. Estimates range from eight to twenty years, and the honest answer is that the error bars are enormous. But the risk is asymmetric: if you wait until the machine exists, you’ve already lost a decade of data.
So the response has been to move early, move quietly, and avoid drawing attention to the fact that you’re moving at all. Signal rolled out post-quantum key agreement in the PQXDH protocol back in September 2023. Google has been experimenting with hybrid post-quantum TLS in Chrome since 2023, mixing classic elliptic curve keys with the NIST-selected ML-KEM (formerly Kyber) so that even if one system proves weak, the other still holds. Apple’s iMessage PQ3 protocol, announced in early 2024, went further—it uses post-quantum cryptography not just for initial key exchange but for ongoing key rotation within a conversation. These are not pilot programs or research demos. They are shipping in production to billions of devices.
Why This Migration Is Different
Every cryptographic migration is hard. The Y2K of the security world is always “we need to replace the primitives.” But this one carries a specific set of burdens that earlier transitions did not:
- Size and performance overhead. Post-quantum public keys and signatures are dramatically larger than their classical counterparts. An RSA-2048 public key is 256 bytes. An ML-KEM-768 public key is 1,184 bytes. A Dilithium2 signature (now ML-DSA-44) is 2,420 bytes. This matters in protocols where every byte is negotiated—DNSSEC, IoT handshakes, satellite links.
- Lack of decades of cryptanalysis. RSA has been attacked continuously since 1977. We know its failure modes intimately. ML-KEM, based on module learning-with-errors lattice problems, has been studied seriously for maybe a decade. There is genuine, nonzero probability that someone finds a catastrophic break in the next ten years.
- Hybrid everything. Because of that uncertainty, almost no one is doing a clean swap. Deployments are hybrid—classical and post-quantum algorithms stacked together. This doubles complexity, increases handshake sizes, and creates new attack surfaces at the boundary between the two systems.
- Embedded systems are stranded. The internet’s visible layer—browsers, phones, cloud servers—will migrate. The invisible layer—industrial controllers, smart meters, medical implants, aging routers—won’t, or will do so over a timescale of decades. Some of these devices can’t be updated at all.
The hardest part of the post-quantum transition isn’t the math. It’s the fact that the internet is an archaeological site. Every layer we’ve built is sitting on top of layers we’ve forgotten about, and we have to replace the foundation without disturbing any of them.
That observation, from a cryptographic engineer at a major cloud provider who asked not to be named because their employer restricts public commentary, captures why this migration is proceeding in near silence. The work is delicate, unglamorous, and carries real risk of breakage. Nobody wants to be the company that broke TLS for three percent of users in a Tuesday deploy.
The Standardization Gamble
NIST’s choices deserve scrutiny, because they are not above controversy. The institute selected ML-KEM (Kyber) for key encapsulation and ML-DSA (Dilithium) for digital signatures, with SLH-DSA (SPHINCS+) as a fallback signature scheme whose security rests on hash functions rather than lattices—a hedge against the possibility that lattice cryptography turns out to have a structural weakness nobody has found yet.
But the process has not been smooth. Falcon, another lattice-based signature scheme that NIST acknowledged as having better performance characteristics than Dilithium, was passed over for final standardization in part because its implementation is notoriously difficult to do securely without leaking side-channel information. NIST also reopened the signature standardization process in 2024 to consider additional algorithms, a tacit admission that relying on lattices alone is a concentrated bet.
Then there is the geopolitical dimension. NIST’s standards carry enormous global weight, and the post-quantum competition drew heavy international participation. But the algorithms that ultimately won were largely designed by teams with significant U.S. and European institutional backing. China has been developing its own post-quantum standards through different channels. The cryptographic world, which likes to think of itself as politically neutral, is not immune to the fractures running through everything else in technology policy.
The Internet Learns to Whisper
What is striking about this moment is how little public awareness exists for a change of this magnitude. When GDPR arrived, every website in Europe greeted you with a cookie banner. When SHA-1 was deprecated, browser vendors plastered warnings across address bars. The post-quantum migration—arguably more consequential than either—is proceeding through commit logs, RFC drafts, and internal infrastructure roadmaps that most users will never see.
That is probably correct. The best infrastructure changes are invisible by design. But it means we are living through one of the most significant transitions in the history of network security, and the evidence is buried in the TLS handshake metadata of your browser tab. The next time you see a little padlock icon in your address bar, consider that the mathematics underneath it may have changed without telling you. The internet is not just being secured against a future threat. It is being quietly rebuilt, one connection at a time, by people who understand that the most important work is often the kind nobody notices.



