Is Harvest Now, Decrypt Later (HNDL) Real? What I Can and Can’t Prove


Table of ContentsIntroductionThe Skeptic Has a Point, and a Blind SpotThis Has Already HappenedWhat a Dozen Governments Have Put in WritingFrom “Cannot Be Ruled Out” to “Collecting Now”The Caveats, and Why They Strengthen the CaseThe Harvest Is the Easy PartA Perfect Copy of the LightThe Tap a Superpower Couldn’t FindBuffering the Cables That Carry the InternetNow It Costs $800Adversaries Already Accept Being SeenA Foothold in the BackboneLondon’s Mega-Embassy Is an Argument About HarvestingThe Storage Math That Should End the DebateWhat Would It Actually Cost?Which Secrets Survive the Wait?What a Single Decryption Would Be WorthThe Question You Should Ask YourselfSo, Is Harvest Now, Decrypt Later Real?The Case Holds Even If You’re Not SureWhat to Do NowThe Answer I Give Now
Introduction
A few times a month, in a board briefing, a training room, or a closed session with a security team, someone interrupts me with a version of the same question. It tends to arrive right after I explain Harvest Now, Decrypt Later (HNDL): the idea that a foreign service may already be copying an organization’s encrypted traffic and warehousing it to read once quantum computers mature. The question comes out somewhere between genuine curiosity and open suspicion. Is this actually happening, or is the quantum industry manufacturing fear to sell products?
It is a fair question, and for years my answer was unsatisfying. I could not hand anyone a seized drive or a leaked intercept order showing a named adversary hoovering up their ciphertext for a machine that does not yet exist. No one could. The honest version of the answer is that nobody can show you a specific quantum-motivated harvest, and nobody needs to: the collection is passive, cheap, undetectable, and already routine, which is why a dozen governments have built migration deadlines around it. This is the fuller answer I never have time to give in the room.
I am not a member of the…