google pqc cryptography
– Google

Google bucked forecasting trends on the "quantum apocalypse" by setting 2029 as the deadline for post-quantum cryptography (PQC) migration.

Heather Adkins, VP of security engineering at Google, wrote in a company blog that the world is on the cusp of a quantum computer emerging and thus breaking current encryption. The prediction goes against the usual "in five years' time" verdict on a quantum breakthrough or "Q-day," which is traditionally forecast between 2030 to 2035.

"This new timeline reflects migration needs for the PQC era in light of progress on quantum computing hardware development, quantum error correction, and quantum factoring resource estimates," Adkins wrote, referring to quantum horsemen such as Google's Willow chip.

Google's new timeline also factors in developments such as a decrease in the number of qubits needed to break 2,048-bit RSA encryption, dropping from 20 million to one million, as well as claims Willow can use error correction in a way that improves reliability as it scales up, instead of the opposite.

"Quantum computers will pose a significant threat to current cryptographic standards, and specifically to encryption and digital signatures" Atkins added. "The threat to encryption is relevant today with store-now-decrypt-later attacks, while digital signatures are a future threat that require the transition to PQC prior to a cryptographically relevant quantum computer (CRQC). That’s why we’ve adjusted our threat model to prioritize PQC migration for authentication services – an important component of online security and digital signature migrations. We recommend that other engineering teams follow suit."

Atkins confirmed that as part of Google's new timeline, its new update to the Android operating system will integrate PQC digital signature protection using the module lattice-based digital signature (ML-DSA) post-quantum cryptographic standard. This is aligned with the National Institute of Standards and Technology (NIST), but used in a hybrid form within Android.

As revealed in our most recent Quantum Supplement, NIST somewhat controversially advocates pure PQC, something seen as a technological hurdle by many firms who rely on hybrid as the quickest port of call for securing their systems now instead of later.

Commenting on Google's new quantum position, Certes CTO Simon Pamplin said its revised estimate of 2029 is "a significant wake-up call."

"But the most dangerous window isn't when quantum computers arrive, it's right now," Pamplin noted. "Adversaries are already running harvest-now, decrypt-later campaigns: exfiltrating encrypted data today with the intention of unlocking it once a cryptographically relevant quantum computer exists. If your organization is still relying on RSA, TLS, or standard PKI to protect sensitive data in transit, that data is already at risk, regardless of whether Q-day lands in 2029 or 2035.  With data flowing across legacy systems, multicloud environments, AI and the edge, the potential risk organizations face today is very real, and extremely serious if left unchecked."

Pamplin argued firms need to seek end-to-end PQC solutions that are able to protect data across all apps and environments.

"Specifically, solutions that enforce sovereign, crypto-agile PQC protection (where only the data owners controls the keys) from server to edge, and ones where protection persists with the data, not infrastructure," Pamplin explained. "Quantum readiness isn't about predicting a date. It's about eliminating a long-term exposure before that date becomes irrelevant.”