惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V2EX - 技术
V2EX - 技术
博客园 - 司徒正美
F
Fortinet All Blogs
D
Docker
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
N
Netflix TechBlog - Medium
U
Unit 42
The Register - Security
The Register - Security
Martin Fowler
Martin Fowler
IT之家
IT之家
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
Security Archives - TechRepublic
Security Archives - TechRepublic
Project Zero
Project Zero
T
Tenable Blog
S
Security Affairs
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Google DeepMind News
Google DeepMind News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
W
WeLiveSecurity
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
Tailwind CSS Blog
TaoSecurity Blog
TaoSecurity Blog
T
The Blog of Author Tim Ferriss
L
Lohrmann on Cybersecurity
雷峰网
雷峰网
Forbes - Security
Forbes - Security
Recent Announcements
Recent Announcements
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
P
Palo Alto Networks Blog
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
Attack and Defense Labs
Attack and Defense Labs
Latest news
Latest news
大猫的无限游戏
大猫的无限游戏
H
Help Net Security
Last Week in AI
Last Week in AI
Scott Helme
Scott Helme
A
Arctic Wolf
L
LINUX DO - 最新话题
A
About on SuperTechFans
K
Kaspersky official blog
博客园 - Franky

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is Trust Now, Forge Later (TNFL)?
Marin Ivezic · 2026-05-05 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

Trust Now, Forge Later (TNFL) describes the risk that digital signatures created today using RSA or ECC could be forged retroactively once a quantum computer capable of running Shor’s algorithm becomes available. I first introduced this concept in 2018 (originally as Sign Today, Forge Tomorrow, or STFT) as the signature-side counterpart to Harvest Now, Decrypt Later (HNDL). Where HNDL threatens the confidentiality of encrypted data, TNFL threatens the integrity and authenticity of signed data.

How TNFL Works

Digital signatures prove that a specific entity created or approved a specific piece of data. A document signed with an RSA or ECDSA key can be verified by anyone holding the corresponding public key. The security depends on the assumption that only the legitimate signer could have produced the signature, because only they possess the private key.

Shor’s algorithm breaks this assumption. Given a public key (which is, by definition, publicly available), a quantum computer running Shor’s can derive the corresponding private key. With the private key in hand, an attacker can forge signatures that are cryptographically indistinguishable from legitimate ones.

The “forge later” element is what distinguishes TNFL from a simple future vulnerability. Signatures made today will still be relied upon for years or decades. A software update signed with an RSA key in 2025 will still be trusted by systems that verify it in 2035. A legal contract signed with ECDSA today retains its binding force for the duration of the agreement. A root certificate issued today anchors a chain of trust that may extend for 20 years. If a quantum computer can forge the signing key at any point during that period, every signature ever made with that key becomes suspect.

Why TNFL May Be More Urgent Than HNDL

HNDL gets more attention because it is easier to explain and its threat model is more intuitive: someone steals your encrypted data and reads it later. TNFL is subtler, but I have argued that its consequences may be more disruptive than the encryption threat.

The argument rests on three observations.

Signatures are harder to migrate than encryption. Encryption protects data in transit or at rest; once you upgrade the algorithm, new data is protected immediately. Signatures, however, are attached to artifacts that persist: signed firmware, signed certificates, signed legal documents, signed software packages. Migrating signatures means re-signing existing artifacts or establishing new trust chains, which is operationally more complex than encrypting new data with a new algorithm.

The failure mode is systemic. A compromised encryption key exposes the data encrypted under that key. A compromised signing key undermines every artifact that was ever signed with it, and every system that trusts those signatures. In software supply chains, a single forged code-signing certificate could be used to distribute malicious updates to millions of endpoints. The signature supply chain runs deeper than most organizations realize.

Verification happens in the future. Encryption is consumed at the time of decryption; once data is read, the encryption has served its purpose. Signatures are verified at the time of reliance, which may be years after signing. A document signed today and verified in 2035 is vulnerable if a CRQC exists by 2035, even if no quantum computer existed when the signature was created.

What TNFL Threatens

The scope of TNFL exposure extends across every domain where digital signatures establish trust.

PKI and certificate hierarchies depend on signed root and intermediate certificates. If the root CA’s signing key can be forged, the entire certificate chain collapses. Software distribution relies on code-signing certificates to verify that updates and applications come from legitimate publishers. Forged signatures could enable supply chain attacks at massive scale. Legal and financial instruments increasingly carry digital signatures with long-term validity. A forged signature on a contract, regulatory filing, or financial instrument creates disputes that may be impossible to resolve. Identity systems use signed tokens and certificates for authentication. Forged identity credentials undermine access control across every connected system.

The Defense

The defense against TNFL is the same as the defense against HNDL: migrate to post-quantum cryptography. Specifically, migrate digital signature infrastructure to ML-DSA (FIPS 204), SLH-DSA (FIPS 205), or FN-DSA (FIPS 206, once finalized).

The sequencing matters. As I argue in my analysis of why signature migration should come before encryption migration, the trust infrastructure that signatures protect is both more difficult to migrate and more consequential if compromised. Organizations with limited resources should prioritize their certificate hierarchies, code-signing infrastructure, and long-lived legal signature workflows before turning to bulk data encryption.

For the full treatment of digital signatures in the post-quantum era, my article on the future of digital signatures in a post-quantum world covers the technical and operational dimensions in depth.

Go Deeper

Harvest Now, Decrypt Later (HNDL) — the encryption-side counterpart

Sign Today, Forge Tomorrow (STFT) / Trust Now, Forge Later (TNFL) — the original concept

Trust Now, Forge Later: The Overlooked Quantum Threat — full analysis

Signature Migration Before Encryption — why trust infrastructure comes first

The Signature Supply Chain — how deep digital trust goes

The Future of Digital Signatures in a Post-Quantum World — technical and operational outlook

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum