lattice
Y2Q warning — quantum computers will break RSA & ECDSAtime to quantum 2029 · migrate to lattice
threat: high 48,210 keys get a key

the quantum threat model.

What a quantum computer can and can't break.

A security model is only honest if it says what it does and doesn't defend against. Lattice defends against a quantum adversary recovering your key from its public counterpart. It does not defend against you leaking your key.

shorbreaks rsa · ecdsa
groverweakens symmetric
latticeno known attack
lost keynot defended

where the trust is

The trust boundary is your key. A quantum computer can break the math of ECDSA — it cannot break the math of a lattice. Everything upstream of your key is designed to be verifiable, not trusted.