Somewhere between the breathless headlines ("quantum computers will break all encryption!") and the dismissals ("decades away, ignore it") sits a precise, genuinely interesting answer. Quantum computers threaten one specific pillar of modern cryptography - Public-key algorithms like RSA and elliptic curves - Through Shor's algorithm. Against passwords, hashes, and symmetric ciphers like AES, quantum machines get only a modest, arguably impractical speedup from Grover's algorithm. Knowing which is which tells you what actually needs to change, what already has, and what your passwords have to do with any of it.
Two algorithms, two very different threats
The entire quantum-cryptography story rests on two algorithms discovered in the mid-1990s, and conflating them is where most bad coverage starts.
Shor's algorithm (1994) - The wrecking ball. Public-key cryptography rests on math problems that are easy forward and brutally hard backward: multiplying two huge primes is instant, factoring the product takes longer than the universe's lifetime - Classically. Peter Shor showed a sufficiently large quantum computer solves factoring and discrete logarithms in polynomial time - Not slightly faster, but categorically faster. A machine that runs Shor at scale breaks RSA, Diffie–Hellman, and elliptic-curve cryptography completely. No longer keys can save them; the schemes must be replaced.
Grover's algorithm (1996) - The modest discount. For unstructured search - Including "guess the key" - Grover offers a quadratic speedup: a search of N possibilities takes roughly √N quantum steps. That sounds dramatic, but it merely halves the effective bit strength. AES-256 drops to 128-bit effective security, which remains beyond any conceivable attack. And Grover's advantage is hollower than the bit-math suggests: it parallelizes badly (a million quantum machines don't divide the work the way a million GPUs do) and requires enormous sequences of coherent quantum operations, leading NIST and academic cryptographers to conclude its real-world threat to symmetric crypto is marginal.
Quantum impact, target by target
| Cryptography | Quantum algorithm | Verdict |
|---|---|---|
| RSA, Diffie–Hellman key exchange | Shor | Broken at scale - Must migrate |
| Elliptic curves (ECDSA, X25519 - TLS, passkeys, crypto wallets) | Shor | Broken at scale - Must migrate |
| AES-128 | Grover | 64-bit effective - Margin thins; AES-256 preferred |
| AES-256 | Grover | 128-bit effective - Safe indefinitely |
| SHA-256, password hashes (Argon2id, bcrypt) | Grover | Effective strength halved on paper; no practical break |
| Post-quantum lattice schemes (ML-KEM, ML-DSA) | None known | Designed to resist both classical and quantum attack |
The pattern jumps out: quantum computing threatens the asymmetric layer - How strangers agree on keys and verify signatures - Not the symmetric workhorses doing the bulk encryption, and not hashing.
So where do passwords fit?
Almost entirely outside the blast radius, for three reasons.
First, stored passwords are protected by hashing, and hashes only face Grover. A quantum attacker guessing through a keyspace gets the square-root discount - Equivalent to halving your password's entropy bits. The defense is embarrassingly simple: length. Password entropy stacks so fast that a few extra characters erase the entire quantum advantage. A random 16-character password from a password generator carries roughly 100 bits of entropy; even fully Groverized, the effective ~50-bit search outruns any projected quantum hardware - Which, unlike a GPU rig, can't be cheaply parallelized into a warehouse of guessing machines. A five-word diceware passphrase achieves the same with memorable words. The math behind those entropy numbers is laid out in our password entropy guide.
Second, slow password hashes compound the problem for attackers. Argon2id's memory-hardness translates miserably into quantum circuits; each Grover iteration must evaluate the entire expensive hash coherently.
Third - And this is the part worth internalizing - No attacker with a nation-state quantum computer would point it at your Netflix password. Passwords today fall to phishing, infostealer malware, reuse, and plain weakness. The ranking of threats to your accounts doesn't change in a quantum world; weak and reused passwords lose to a laptop, no qubits required.
Quantum rule of thumb: worry about the locks between computers (key exchange, signatures - Being replaced now), not the locks on your secrets (AES-256, long random passwords - Fine as they are).
The real deadline: harvest now, decrypt later
If symmetric crypto and passwords are fine, why the urgency in government and industry? Because encrypted traffic can be recorded today and decrypted later. TLS sessions negotiated with classical key exchange are only as durable as RSA/ECC - An adversary warehousing intercepted traffic now could unwrap it the day Shor-scale hardware exists. For state secrets and health records with decades-long sensitivity, that future breach happens retroactively. This "harvest now, decrypt later" logic - Not any current capability - Drives the migration timeline, including the U.S. government's target of moving national security systems to post-quantum algorithms in the 2030s.
Hence the replacement program: NIST finalized its first post-quantum standards in August 2024 - ML-KEM (FIPS 203, key exchange, formerly Kyber), ML-DSA (FIPS 204, signatures, formerly Dilithium), and SLH-DSA (FIPS 205, hash-based signatures) - Built on lattice and hash problems with no known quantum shortcut. Deployment is far along: Chrome and Firefox negotiate hybrid X25519+ML-KEM key exchange with major sites, Signal's PQXDH and Apple's iMessage PQ3 already blend post-quantum protection into messaging, and the TLS 1.3 handshake absorbs the change invisibly. Hybrid mode - Classical and post-quantum run together, so security holds unless both fall - Is the sensible bridge while the new math accumulates mileage.
How close are the machines, really?
Today's largest quantum processors offer on the order of a thousand physical qubits - IBM's Condor crossed 1,121 in 2023 - And Google's Willow chip demonstrated in late 2024 that error-corrected logical qubits can improve as systems scale, a genuine milestone. But physical qubits are noisy; useful attacks need fault-tolerant logical qubits, each built from hundreds or thousands of physical ones. Credible estimates for breaking RSA-2048 with Shor sit in the range of millions of physical qubits running for hours to days - Several orders of magnitude beyond anything demonstrated, even as a 2025 Google research result trimmed the theoretical requirement to under a million noisy qubits running for about a week. Expert surveys (such as the Global Risk Institute's annual poll) put meaningful odds on a cryptographically relevant machine somewhere in the 2030s. Uncertain, not imminent, not ignorable.
What actually deserves your attention
For individuals, the quantum era arrives as software updates you'll barely notice. The genuinely useful moves are the timeless ones. Long random passwords neutralize Grover with a rounding error's worth of extra length. Password vaults already encrypt with AES-256. The one asymmetric technology in your daily life - passkeys, which rest on elliptic curves - Will migrate to post-quantum signatures at the platform level, with FIDO Alliance work underway; no action needed on your part. Meanwhile the boring truths keep governing reality: this year, next year, and the year the first cryptographically relevant quantum computer boots, the overwhelming cause of hijacked accounts will still be a reused "Summer2026!" - A problem no physics can solve and thirty seconds of generating a proper password does.
FAQ
Can a quantum computer crack my password today?
No. Today's quantum machines are noisy, small-scale research devices that can't run cryptographically relevant attacks of any kind - And even future ones offer only Grover's square-root speedup against hashed passwords, which a reasonably long random password absorbs easily. Every password compromised this decade will fall to classical means: phishing, malware, reuse, and weak choices.
Will quantum computers break AES-256?
By every current understanding, no. Grover's algorithm reduces AES-256 to 128-bit effective security - Still far beyond physical feasibility - And Grover's poor parallelization makes even that theoretical bound optimistic for attackers. This is why standards bodies simply recommend AES-256 and move on; the migration effort targets public-key algorithms, where Shor's algorithm does real damage.
What is "harvest now, decrypt later"?
It's the practice of recording encrypted traffic today in hopes of decrypting it once quantum computers can break the key exchange that protected it. It only pays off against data still valuable in the 2030s-plus - State, medical, financial archives - Which is why governments are migrating early. Your personal browsing carries this risk mostly in theory; the fix (post-quantum TLS) is deploying through browser updates already.
Do I need a "quantum-safe" password?
There's no such product category, despite marketing efforts - A strong password is already the quantum-safe kind. Aim for 16+ random characters or a five-plus-word passphrase: the entropy comfortably exceeds what Grover-assisted guessing could ever search, especially through a memory-hard hash like Argon2id. Length and randomness were the answer before quantum computing and remain the answer after.
Should businesses do anything now?
Yes - Inventory and agility, not panic. Catalog where RSA and elliptic-curve crypto live in your stack (TLS, VPNs, code signing, long-lived encrypted archives), prefer AES-256, and track vendor support for NIST's ML-KEM and ML-DSA standards. The organizations that struggle with this migration will be the ones that don't know where their cryptography is - The same ones that struggled with every previous deprecation.