Skip to content

Video companion

After minutephysics on Shor's: what CISOs must know about RSA and ECC

minutephysics explains Shor's algorithm without requiring a physics degree. The gap for security leaders is translating period-finding into a concrete inventory of quantum-vulnerable algorithms.

Diagram of quantum threat to RSA and ECC versus AES.
How Quantum Computers Break Encryption | Shor's Algorithm Explained Watch on YouTube

What the video gets right

Shor's algorithm turns factoring large numbers — the hard problem behind RSA — into finding the period of a modular function. A cryptographically relevant quantum computer (CRQC) running Shor's breaks public-key crypto: RSA, Diffie-Hellman, and elliptic-curve variants (ECDH, ECDSA).

The video correctly notes that symmetric crypto like AES is not destroyed overnight; Grover's algorithm weakens it, which is why NIST recommends larger key sizes — but the urgent migration target is PKI and key exchange.

For background on period-finding, see the PennyLane period-finding demo.

What it does not cover

Explainers rarely answer operational questions: which certificates still use RSA-2048, which SaaS dependencies embed legacy algorithms, and who owns remediation. NIST's PQC overview describes the solution — standardized ML-KEM and ML-DSA — but inventory comes first.

Qtangl Assess tags quantum-vulnerable algorithms on external TLS and exports a CycloneDX CBOM — an inventory aid, not a formal attestation.

This quarter

  1. Watch the embedded video, then skim NIST's post-quantum cryptography explainer.
  2. Run a baseline scan on external TLS — list RSA, ECDSA, and ECDH dependencies.
  3. Tag findings by data shelf-life tier for Mosca HNDL scoring on the HNDL hub.

Continue on the Q-Day hub: What is Q-Day? guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.