CyOne Security AG
Luzern
"Harvest now, decrypt later": How real is the quantum threat?
- 07 August 2026
- 100%
- Permanent position
- Luzern
About the job
Quantum computers are considered gamechangers – also for IT security. In the interview, Esther Hänggi, Professor of Computer Science at Lucerne University of Applied Sciences and Arts, explains the opportunities and risks quantum technologies bring for today’s encryption methods. She assesses the current state of research, dispels common misconceptions, and shows why companies should already be taking action today.
Quantum computing and quantum cryptography are no longer purely theoretical concepts. While public debate swings between hype and scepticism, research and practice are intensively dealing with the concrete impacts on security architectures. In the interview, Esther Hänggi talks about real threat scenarios, regulatory pressure, and the path towards quantum-secure systems.
Ms Hänggi, your teaching and research focuses include quantum computing and cryptography. What opportunities, but also risks, arise from scientific advances in quantum technology regarding the security of encryption methods?
When we talk about quantum technologies, most people first think of quantum computing. Quantum computers are especially good at performing certain calculations. This includes breaking many cryptographic algorithms used today. From an IT security perspective, quantum computers therefore pose a risk.
However, besides quantum computers, there are other quantum technologies that can also be useful in IT security. For example, quantum cryptography: quantum effects can be used to generate secure random numbers – e.g. for use as keys – and to create a secure shared key between two endpoints. These technologies are already well developed and devices for them are already available for purchase. In our Quantumlab at HSLU, we have both quantum random number generators and quantum key distribution devices and use these in IT projects. A good explanation of quantum cryptography can be found on the HSLU blog.
Furthermore, we are researching additional applications of quantum technology in IT for the future. For example, there are proposals to use quantum effects as copy protection for money or to connect quantum computers into a quantum internet.
The Quantumlab at HSLU investigates how quantum cryptography can be integrated into IT applications. The quantum key distribution devices use quantum properties of light particles, which are exchanged via fibre optic cables.
In media and specialist journals, there is currently frequent talk of alleged as well as actual breakthroughs in quantum computing. How do you assess the current state of research in your field?
In science, this hype is viewed critically. Public perception swings between "quantum computers are already enormously large and useful today" and "it’s all just hot air." In my opinion, the truth, as so often, lies in the middle.
Today’s quantum computers are indeed still relatively small and error-prone. Claims that quantum computers already bring economic advantages in practical applications are therefore often exaggerated.
On the other hand, I find the technical progress made in the last 10-15 years absolutely impressive: from manipulating individual qubits (quantum bits) to quantum computers with several dozen qubits. And quantum computers have not only become larger but also much more precise – which is equally important for applications.
Where do you see the biggest misunderstandings in the public perception of quantum computing?
I see two misunderstandings about quantum computers:
What quantum computers can do: Quantum computers cannot perform magic. It is often suggested that quantum computers could "guess" any secrets or keys or "read out" information from data that is not even contained in that data. That is not possible. Quantum computers can make certain calculations more efficient. This is important because in calculations we are often limited by how much can be computed within a useful timeframe. The security of modern cryptography also relies on the fact that an attacker cannot perform calculations arbitrarily fast. However, a quantum computer cannot calculate something that is not computable.
What quantum computers are: Quantum computers are not simply new supercomputers and cannot solve all computational problems "immediately." We only know of a few very specific computational problems that quantum computers can solve particularly well. These include – unfortunately from a security perspective – tasks from cryptography. For other calculations, using a quantum computer brings no benefit. Finding further applications for quantum computers is an active research area.
How do attack models in the quantum age conceptually differ from classical cyber-attacks?
Quantum computers will not replace today’s attacks but will complement attackers with a very specific capability: that they can break certain cryptographic algorithms. This must be considered in risk analysis and systems must be adapted accordingly.
The fact that individual cryptographic algorithms are broken is nothing new and has happened in the past. However, quantum computers now threaten a large number of algorithms.
What is special about the threat scenario posed by quantum computers? What does this threat look like?
A misunderstanding regarding the threat from quantum computers is that one can still wait because quantum computers are still small and cannot break cryptographic algorithms today. Unfortunately, it is not enough to act only when quantum computers are powerful: an attacker can record encrypted communication today and, as soon as a large quantum computer exists, use it to decrypt it. This is called "harvest now, decrypt later."
"Mosca’s Law" states that one must start early enough to switch to quantum-secure systems. One must consider how long an algorithm must remain secure in the future. Additionally, time must be planned for migration to a quantum-secure algorithm.
For encryption, the time an algorithm must remain secure depends on the type of data. For signature algorithms, it depends on how long an electronic signature or contract must remain valid, which can sometimes be very long. Conversely, there are applications that only need to be secure for a short time, for example during authentication when establishing an encrypted connection.
From an IT risk perspective, it must also be noted that this does not depend solely on the technical development of quantum computers. From a regulatory perspective, it is required that systems be made quantum-secure in the coming years. Companies must therefore address this topic – regardless of technical progress.
Would you like to gain deeper insights? Download the full interview with Prof. Dr Esther Hänggi!
Prof. Dr Esther Hänggi has been Professor of Computer Science at Lucerne University of Applied Sciences and Arts (HSLU) since 2019 and since 2023 also Co-Head of the Applied Cyber Security Research Labs. She is also a member of the Swiss Quantum Commission. She earned her Master’s degree in Physics at EPFL Lausanne before completing her doctorate on quantum cryptography at ETH Zurich.
In research and teaching, she focuses on application and information security, (quantum) cryptography, and quantum computing. In her research projects, she particularly investigates how quantum technologies can be made usable for computer science and how IT systems can be protected from potential attacks by quantum computers.