Harvest now, decrypt later

Harvest now, decrypt later is the strategy of recording encrypted traffic or signed artifacts today in order to break them once quantum computers can. It inverts the usual risk calculus: data does not need to be crackable now to be at risk now, it only needs to still matter when the cryptography falls. Long-lived identity evidence, audit logs, credentials, signed attestations, is the canonical exposure.

The exposure to test for is not sensitivity but longevity. A session token that expires in an hour is uninteresting to an adversary recording traffic; a signed attestation that a regulator may examine in eight years, or an audit log that must remain provably untampered, is exactly the thing worth storing until the cryptography under it weakens.

This is the argument for signing long-lived evidence with a post-quantum layer now rather than re-signing it later, since re-signing after the fact cannot prove what the artifact said at the time.

The strategy is unfalsifiable from the defender's side, which is what makes it awkward to plan against. Nobody can demonstrate that their traffic is being recorded, so the decision has to be made on the structure of the risk rather than on evidence of collection, and that argument is easier to make about specific long-lived artifacts than about traffic in general.

Sorting by longevity produces a short and actionable list. Signed evidence a regulator may examine years from now, credentials with long validity, audit records that must remain provably untampered, and archived data under a retention obligation all qualify; session tokens, short-lived caches and ephemeral traffic do not.

For signed artifacts the timing argument is stronger than for encrypted ones, because re-signing later does not help. A signature applied today attests to what the artifact said today; one applied in five years attests only to what it says then, so the post-quantum layer has to go on at creation time. That is the specific reason to sign long-lived evidence with hybrid signatures now rather than planning to upgrade.

The migration this motivates is the subject of post-quantum cryptography.

PasskeyBridge verifies identity signals like these inside the request, with zero PII stored. See how the platform works or test the live API.