Video companion
After Jeremy Allison on HNDL: what your security team should do now
Jeremy Allison's conversation on post-quantum cryptography lands a point most board decks skip: adversaries are collecting encrypted data now because storage is cheap and migration takes years.
What practitioners emphasize
Open-source maintainers and platform engineers face a brutal reality: FIPS validation is expensive, embedded systems are everywhere, and post-quantum algorithms require coordinated library, certificate, and load-balancer updates. The video correctly frames HNDL as a today problem for data with long confidentiality requirements.
What boards miss
Boards ask whether quantum computers will break encryption tomorrow. The harder question is whether ciphertext captured today will still be confidential when your migration finishes. Michele Mosca's inequality — X + Y > Z — turns that into a planning formula:
- X = years data must stay secret
- Y = years to migrate
- Z = years until quantum breaks your algorithms
When X + Y exceeds Z, you have HNDL exposure now — even while today's crypto still works.
Where Qtangl aligns
Every Qtangl assessment includes Mosca HNDL scoring mapped to your data retention horizon and migration runway. You get a prioritized backlog, CycloneDX CBOM export, and signed verify links — evidence for audit conversations, not a attestation claim.
This quarter
- Inventory quantum-vulnerable algorithms on external TLS — not a spreadsheet snapshot.
- Tag findings by data shelf-life tier (healthcare, finance, and gov records often exceed 20 years).
- Pilot hybrid TLS on a non-production path and attach re-scan proof after remediation.
Continue on the Q-Day hub: Harvest now, decrypt later guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-03
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- What Is Q-Day? Quantum Computing and Cyber RiskPalo Alto Networks · 2026CRQC definition, HNDL threat model, and migration guidance for enterprise security teams.
- Why Your Encrypted Data Is Already Being Stolen (Jeremy Allison, CIQ)YouTube · 2025Practitioner perspective on HNDL, PQC migration complexity, and FIPS certification for open source.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.