Quantum Series · Part Three

Why We Command the Keys

Staying aware and engaged within our community protects our sovereignty.

Recently I had the chance to visit several universities across the American West. Everywhere I went, I stopped students, faculty, and folks just passing by, and asked them one plain question: what do you know about quantum — about quantum physics? Most gave me the same honest answer: “I don’t know, really.” That held right up until I asked around at Stanford and Cal Berkeley. Those students were sharp. They were ready. Why? Because their campuses and their communities are aware, confident in what they know, use it smartly, and determined to be the boss of new technologies as they evolve. It helps, too, that Silicon Valley — the incubator of so many of these new technologies — sits right in their backyard. That is the learning curve I want for our people. That is the example worth reaching for.

Because here’s what I keep coming back to: staying aware and staying engaged is not busywork. For us, it is how we protect our sovereignty.

In the earlier pieces of this series, you learned more than just an introduction to quantum. You discovered it’s already living in your house, and you learned to ask which quantum — so no salesman could mislead you with a word.

Now we come to the one real concern, the one issue that matters most. It is a lock. Knowing what they are, how to spot them, and simply asking: who holds the key?

We already use locks we never named. The little padlock in the corner of your browser. The word “secure” on your bank app. Mail that’s scrambled so a snoop on the wire sees only gibberish. That scrambling is encryption: you turn a message into a puzzle, you send the puzzle, and only the right key turns it back into words.

Some of those puzzles are old. They were built back when the idea of a machine that could pick them — a new kind of computer, good at the exact math those old locks lean on — was still science fiction. A big, stable quantum computer, still rare, still fussy, still not sitting on a shelf at the grocery store, might one day pick certain of those old puzzles. Not all of them — just the ones that start a private conversation on the public internet, the handshake that says “yes, this really is your bank,” and the digital signatures that prove a program or a message is the real thing.

Here’s the part worth understanding. Someone doesn’t have to open your locked box today to be interested in what’s inside it. They can quietly make a copy of the sealed, scrambled pile now, set it on a shelf, and simply wait. A copy can slip out the door and you’d never feel it gone. If the new machine ever arrives, they pull that copy back down and try the key then. It even has a name: harvest now, decrypt later. The information worth that kind of patience is the long-life kind — health files, court records, a Nation’s business. Last Tuesday’s grocery-list text? Nobody’s waiting years for that.

So the world is already changing the locks, before the villain in the movie ever shows up. Nobody knows if that machine is a few years away, decades away, or never — but changing every lock takes years, so the smart move is to start now.

The new locks are called post-quantum cryptography, or PQC — new math running on the very same phones and servers we already own. Our own U.S. standards lab, the National Institute of Standards and Technology (NIST), has already published the first official recipes. One name you may hear in an IT meeting is ML-KEM — that stands for Module-Lattice-Based Key-Encapsulation Mechanism, and you’re free to forget those words the second you read them. Just think of it as one new official lock. You won’t install it yourself; a vendor, a hospital system, or an office you work with will. These new locks aren’t a fourth kind of salesman — they’re plumbing, quietly upgraded on pipes you already own.

Now, there’s just one more product with “quantum” stamped on it. What does it mean when someone starts talking about a beam? A few companies sell a way of sending keys on a special beam of light down a fiber-optic line — the fancy name is quantum key distribution. It’s real. It’s also expensive, it’s point-to-point, and it is not how your phone talks to the clinic down the road. So if someone shows up selling a beam-and-satellite kit as “the only way to be safe,” hear it for what it usually is: a sales pitch. Somebody wants your signature more than they want to protect you.

So what is this not?

You do not need to buy a quantum computer to stay safe.

A big new building with “quantum” on the sign is not “new locks” — it’s real estate. Don’t confuse the two.

“Quantum-secure” printed on a flyer is not the same as your files never leaving the security of your home or office.

So what can any of us actually do?

Keep enrollment, health, and unpublished business out of random chat tools. That’s still the single strongest move you can make.

Ask the people who already run your systems three plain questions: When do you move to the new NIST locks? Where are the backups? Who can read them?

Don’t sign a quiet paper about anything with “quantum” on the label before the people it affects have had their say. Big decisions deserve transparency.

Before you let anyone handle your systems or your data, get their promises in a signed contract that protects your sovereignty — not a handshake and a smile.

Let the updates on your phones and office machines arrive through their normal, trusted channels. That’s how the new locks actually show up. Boring is good.

Being the BOSS never changes:

a) whose information is it?

b) who has a copy?

c) who can pull the plug?

New locks help. They do not replace any of those questions.

The Try. Take one thing you protect — a bank app, a clinic portal, a shared drive at work. Write three questions on a card: Who already has a copy? How long does this need to stay secret — months, or decades? Did anyone say “quantum” when they meant a building, when they should have meant a lock update? If you can’t answer that first one, start there — and assume there are more copies out there than you think.

Catch It! “We need a quantum computer, or we’ll be left unlocked.” No. What you need is for the systems you already use to change their locks — and you need to keep the filing cabinet, keys and all, out of the hands of anyone who won’t put it in a signed contract.

Catch It! #2 “They said it’s quantum-secure, so we’re covered.” Not so fast. Ask which quantum — out loud, just like this: “Do you mean the science that’s already in our phones? A brand-new machine that barely exists yet? Or a lock update we should already be getting from the systems we own?” Make them answer in plain words.

Remember those students at Stanford and Berkeley? They weren’t smarter than our young people — not by a mile. They were just earlier: handed the word sooner, in a community that expected them to hold it. That’s the only real difference, and it’s a difference we can change — in our homes, our communities, and our work — starting today, not tomorrow.

Quantum is already in your house. It’s a growing technology doing more than one job, so you learn to ask which one. And it is a lock — one we can help choose, if and when we’re at the table when the choosing happens. Across all three, one thing never moved: YOU, and the knowledge you carry confidently, knowing that YOU are the BOSS of the technology.

We command the keys not because we became physicists — we didn’t, and we don’t need to. We command them because we stayed aware, stayed engaged, and refused to let a big word decide our future for us. Knowledge has always been the one thing nobody could take from a people. This is simply the newest kind. Let’s be the community that’s ready — confident in what we know, and holding our own keys.

Whose information is it? Ours. It always was.

The cape was never the lock — and the key was always meant for our hands.

THE ONE-CARD VERSION

For the Curious: A Little Deeper

Everything above is the whole truth, told plainly — and you can stop at the card and not have missed a thing. But if you’re the kind who likes to look under the hood, or you’ll be in the meeting where these decisions get made, here’s a little more, in slightly bigger words. You chose to be here, so the acronyms are welcome.

1. ML-KEM is a handshake, not a safe. ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism, published by NIST as FIPS 203) doesn’t scramble your whole message by itself. It’s a quantum-resistant way for two computers to agree on a shared secret key across an open line. That shared key then feeds an ordinary, fast encryption system — usually AES (Advanced Encryption Standard) — which does the actual scrambling. So when we call it “one new official lock,” what it really is, is a new and safer way to hand over the key.

2. There’s more than one new standard. NIST finalized three at once in August 2024. ML-KEM (FIPS 203) is for agreeing on keys. The other two are for digital signatures — ML-DSA (Module-Lattice-Based Digital Signature Algorithm, FIPS 204) and SLH-DSA (Stateless Hash-Based Digital Signature Algorithm, FIPS 205). Signatures are how your device knows a website, an app, or an update is genuine and not a forgery — so they matter every bit as much as the locks.

3. The danger is to “public-key,” not to everything. The systems at real risk are the public-key ones — names like RSA, Diffie-Hellman, and elliptic-curve — used to set up secure sessions and prove identity. A big enough quantum computer running Shor’s algorithm could crack those. The everyday “symmetric” locks like AES-256 are far tougher: against them a quantum computer gets only a modest head start (Grover’s algorithm), and simply using longer keys handles it. That’s why we said “certain old puzzles,” never “all encryption.”

4. Quantum key distribution hands over a key — it doesn’t prove who you are. QKD (quantum key distribution, the “beam” product) can deliver a key that’s provably un-eavesdropped. But on its own it cannot tell you the party on the other end is really your bank and not an impostor. You still need a separate way to prove identity — authentication. That’s one more reason it’s a specialized tool for special links, not a replacement for the whole system.

5. Nobody knows the timeline. Serious estimates for a code-breaking quantum computer run from a handful of years to a few decades — or never. But moving the world’s systems onto the new locks takes years all by itself, which is exactly why careful organizations are starting now instead of waiting for an alarm.

6. “Post-quantum” does not mean “safe forever.” New math resists today’s known attacks, but security still rides on the people, the devices, weak passwords, stolen logins, honest key-handling, and good backups. The new locks help. They never replace the three Boss questions: whose information is it, who has a copy, and who can pull the plug.

Selected sources

Check it yourself (that’s the whole point): NIST FIPS 203, ML-KEM (csrc.nist.gov/pubs/fips/203/final) · NIST, “What Is Post-Quantum Cryptography” (nist.gov) · NIST CSRC, first PQC standards finalized, August 2024 · U.K. Government, Quantum Key Distribution research report (gov.uk) · CISA, “Quantum-Readiness” guidance (cisa.gov).
© Bobby W. Chambers · Information Managers · AI — “AI for the Rest of Us.”
Shared under Creative Commons BY-NC-ND 4.0 — please share freely with credit; no commercial use, no changes.
← Back to all articles