Workshop: “Quantum Circuits and Algorithms for Cryptography”, and poll results

We voted on a name for not-post-quantum crypto, and landed on: “quantum-insecure crypto.”
quantum
Published

July 14, 2026

The poll

Last week, I organized the workshop Quantum Circuits and Algorithms for Cryptography at the Simons Institute on UC Berkeley campus. During my opening talk, I asked attendees to consider the following question:

Somehow we haven’t converged on a name for the category of cryptographic primitives that aren’t quantum-safe (i.e. discrete logarithm and factoring). Let me know if you have ideas, and at the end of the workshop we will vote!

Submissions included:

  • pre-quantum crypto.
  • classical asymmetric crypto.
  • quantum-vulnerable crypto.
  • quantum-insecure crypto.
  • quantum-ignorant crypto.
  • doomed crypto (lol)

At close of the workshop there was an overwhelming majority for quantum-insecure crypto. Thanks to Helen Propson for this submission!

The workshop

Thanks also to everyone who participated in the workshop for fruitful and intriguing discussions. For anyone who couldn’t make it, a primary takeaway was:

Takeaway

Timelines for cryptographically relevant quantum computation have moved up quite dramatically, as is reflected in recent decisions by Google and Cloudflare to move migration timelines to 2029, and an executive order from the US government to migrate by 2030/2031.

But also importantly, the variance in our estimates of the timeline has also increased, because the quantum computing architecture we will ultimately run on now seems much less settled than it once did.

If you are in charge of implementing post-quantum cryptography for applications: don’t switch to PQC with reckless abandon because that could have even worse impacts, but do the work to be ready for the switch as soon as possible!

Key moments

Moments I am proud of from the workshop include communicating important scientific ideas via meme:

… and drawing a QR code by hand on the whiteboard:

Closing note

I also feel the name “post-quantum cryptography” is not ideal—it’s less precise than something like “quantum-secure cryptography.” But that name has become sufficiently established that I think we’re stuck with it…