“Quantum-resistant” and “post-quantum encryption” have started appearing in VPN marketing over the past couple of years, usually with little explanation of what’s actually changed under the hood. The short version: this is a real, significant shift in cryptography with an official government standard behind it – but it’s worth understanding what the standard actually covers before treating any given VPN’s claim about it at face value.
Why this change is happening at all
The concern behind post-quantum cryptography is specific and well understood in the security research community: a sufficiently powerful quantum computer would be able to solve the mathematical problems that current encryption – including RSA and ECDH, both widely used in VPN protocols – relies on for its security, far faster than any classical computer could. NIST, the US government’s National Institute of Standards and Technology, has been explicit that while such a computer doesn’t yet exist, experts anticipate one capable of breaking today’s encryption could emerge within roughly a decade – which matters right now because data encrypted today could be captured and stored by an adversary, then decrypted retroactively once that capability exists.
What NIST actually finalised
In August 2024, after an eight-year public evaluation process, NIST finalised its first three post-quantum cryptography standards. FIPS 203 (ML-KEM, based on the CRYSTALS-Kyber algorithm) is the primary general-purpose encryption standard, designed specifically as a replacement for the key exchange mechanisms – RSA and ECDH – that a quantum computer could eventually break. FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) cover digital signatures, using different underlying mathematics as a safeguard in case one family of approaches is later found to be weaker than expected. NIST has been direct in urging adoption now rather than later, stating that organisations should “start integrating them into their systems immediately, because full integration will take time.”
Why this matters specifically for a VPN
VPN protocols rely on exactly the kind of key exchange mechanism ML-KEM is designed to replace – the process where your device and the VPN server agree on an encryption key at the start of a connection. A VPN implementing ML-KEM (or a hybrid approach combining it with existing classical encryption during the transition period) is addressing the “harvest now, decrypt later” risk directly: traffic protected this way should remain secure even if a future quantum computer eventually becomes capable of breaking today’s classical key exchange methods.
What a marketing claim should actually specify
Because “quantum-resistant” isn’t a protected or regulated term the way a specific certification is, it’s worth treating vague use of the phrase with some scepticism, and looking for whether a provider names the actual standard involved – specifically ML-KEM or FIPS 203, or the algorithm it’s based on, Kyber – rather than the phrase alone. A provider using a hybrid implementation (combining ML-KEM with existing, already-proven classical encryption rather than replacing it outright) is generally taking the more cautious, currently recommended approach during this transition period, since post-quantum algorithms are newer and have had less real-world cryptanalysis than long-established methods.
What this doesn’t change about a VPN’s other protections
Post-quantum key exchange addresses one specific, forward-looking threat – a future quantum computer breaking today’s captured, encrypted traffic. It has no bearing on a provider’s logging policy, jurisdiction, kill switch reliability, or any of the other factors that determine a VPN’s overall trustworthiness; a provider can genuinely implement ML-KEM and still fall short on those separate, unrelated questions.
Why “harvest now, decrypt later” makes this relevant today, not just in the future
The reason this matters before a working quantum computer actually exists is specifically that encrypted traffic can be captured and stored now, by an adversary with the resources to do so, and simply held until decryption becomes possible later. For most everyday browsing this risk is fairly abstract, but for anyone whose traffic could plausibly be a long-term target – journalists, activists, or anyone handling genuinely sensitive long-lived information – the gap between “not currently breakable” and “will never be readable” is exactly what post-quantum key exchange is designed to close, which is why some providers are rolling it out well ahead of any actual quantum threat materialising.
Why the transition is happening gradually rather than all at once
Post-quantum algorithms are newer than the classical cryptography they’re replacing, and newer algorithms generally carry more residual uncertainty simply because they haven’t had decades of public cryptanalysis the way RSA and ECDH have. That’s the main reason the current recommended approach favours hybrid implementations – combining a post-quantum algorithm with an already-proven classical one, rather than switching over entirely – so that a connection stays protected by whichever of the two approaches turns out to be stronger, rather than betting everything on the newer method alone during this transition period.
The bottom line
Post-quantum encryption is a real, NIST-standardised response to a genuine future threat, built specifically to replace the key exchange methods current VPN protocols depend on. A credible claim should point to the actual standard – ML-KEM or FIPS 203 – rather than resting on the phrase “quantum-resistant” alone, and it addresses one specific risk rather than substituting for the rest of what makes a VPN provider trustworthy.
Sources
- National Institute of Standards and Technology, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards” – nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards