1
Threat Overview
The 'Harvest Now, Decrypt Later' (HNDL) risk exposes long-lived sensitive data due to the potential of Cryptographically Relevant Quantum Computers (CRQCs) breaking current encryption methods. This threat affects organizations storing sensitive data, particularly those using long-lived encryption keys. The attack vector is the vulnerability of current encryption methods to quantum computers.
2
Key Intelligence Points
1. The HNDL risk relies on the 'quantum computers' threat, which exploits the vulnerability of current encryption methods to quantum computers. 2. The impact scope is organizations storing sensitive data, particularly those using long-lived encryption keys. 3. The attack chain involves the potential for quantum computers to break current encryption methods, allowing for decryption of previously encrypted data. 4. Detection opportunities include monitoring for unusual encryption key usage patterns and analyzing system logs for potential quantum computer activity.
3
MITRE ATT&CK Techniques
T1110 - Brute Force: The potential for quantum computers to brute-force current encryption methods
4
Mitigation & Detection
Organizations should consider implementing quantum-resistant encryption methods and regularly reviewing and updating their encryption key management practices.