Preparing for the Quantum Threat
Cybersecurity experts have been warning that in the next 10-20 years, quantum computers will reach a level of processing power that will allow them to decipher common cryptography techniques like RSA and ECC. This event is known as ‘Q-Day,’ and it’s a pressing concern for individuals and businesses that handle sensitive information.
Post-quantum encryption (PQE), also known as quantum-safe encryption, is a new encryption protocol that uses complex mathematical puzzles that even quantum computers struggle with. This feature is being offered by several VPN providers, including NordVPN, ExpressVPN, and Mullvad, as a way to protect user data from hackers who might hold onto it until quantum computers can decrypt it.
How Post-Quantum Encryption Works
When you access the internet through a VPN tunnel, it scrambles your traffic data into unreadable code that can only be unlocked using a cipher key. This key is then securely transmitted to your device using a VPN handshake. However, with the advent of quantum computing, security researchers estimate that it will be possible for hackers to decrypt this data without access to the actual key.
Attackers are already using ‘harvest now, decrypt later’ (HNDL) attacks to hoard encrypted network data so that they can decrypt it as soon as Q-Day arrives. This means that they’ll gain access to years of private user data the second that quantum computers gain enough processing power through hardware improvements.
Why You Need Post-Quantum Encryption
If your work involves sensitive data, high-value financial transactions, or you’re in a regulated industry with strict compliance requirements, PQE is worth looking into. While its availability is limited to certain VPN providers on specific pricing tiers only, security-conscious businesses and professionals operating in sensitive industries will find it genuinely useful.
NIST standardized new encryption algorithms from an open competition in August 2024, which included three models that are complex enough to resist attacks from quantum computers: ML-KEM (aka Kyber) for key exchange, along with ML-DSA and SLH-DSA for digital signatures.
VPNs That Support Post-Quantum Encryption
NordVPN, ExpressVPN, and Mullvad are three mainstream providers who offer PQE as an opt-in feature on several plans. NordVPN rolled out PQE in its Linux VPN app in 2024, followed by Windows, Android, and Apple operating systems, while ExpressVPN has PQE enabled on every user plan by default. Mullvad introduced a pilot version of its post-quantum encryption key exchange protocol in 2017, but the experimental implementation was replaced by a new version based on the Classic McEliece algorithm on top of all existing WireGuard servers.
To enable PQE on NordVPN, go to Settings > Connections on Windows, Settings > General on macOS, or tap your profile icon on iOS, Android, tvOS, or Android TV. On Linux, navigate to terminal and run the command: nordvpn set pq on. On ExpressVPN, make sure you’re using the Lightway protocol and not a legacy alternative like OpenVPN. Mullvad doesn’t have a feature-based pricing tier to worry about, and every paying customer has access to PQE with no add-on purchases necessary.
Whether or not it’s worth using PQE right now depends on your typical workflow and the level of security you need. Quantum computers are still years away from being able to decrypt current security protocols like RSA and ECC, even by the most generous estimates. However, HNDL attacks are a big enough security red flag that companies or people operating in sensitive industries and dealing with confidential information should be paying attention.
For regular browsing workflows, PQE may be overkill. But when dealing with financial data, accessing healthcare portals, or sending sensitive information that you can’t afford to have intercepted, quantum protection offers additional peace of mind.