demo · v131

The harvest-now-decrypt-later timeline

The motivating reason to enable a hybrid post-quantum KEM in Chrome stable was not today's adversaries — it was the adversary recording today's TLS handshakes and decrypting them in 10-15 years once a cryptographically-relevant quantum computer arrives. Drag the "quantum date" slider and the "secret value lifetime" slider to see when a 2026 handshake stops being safe.

harvest a 2026 handshake
secret still sensitive until
CRQC available
X25519 alone

broken once CRQC arrives

X25519Kyber768

safe — secret derived from ML-KEM share

see also