Johan De Villiers

Director’s View

The Strap Didn’t Change. The Load Did.

Quantum computers have not suddenly got bigger. The job of breaking your encryption has got smaller. That is a different problem, and it comes with a different deadline.

Somewhere past Khwai, on the northern edge of Moremi, a man I had never met offered me his snatch strap. The Monster was sitting on her belly in black cotton soil, the light was going, and he was being genuinely decent about it. I thanked him and dug out my own.

If you have never had to use one, a snatch strap is a length of heavy nylon webbing that stretches under load, so that a second vehicle can take a run-up and slingshot a bogged one out of the mud. Every strap carries a breaking strain printed on the label, and the whole recovery rests on that number still being true. When a strap lets go under load, it comes back through a windscreen.

His strap looked perfect. Bright, clean, neatly rolled, not a frayed thread at the eyes. That is the trouble with straps. They do not tell you what they have already survived. One that has been shock-loaded twice and left on a roof rack through two Kalahari summers looks identical to one straight out of the packet, and the number printed on the label is still the number printed on the label. It simply isn’t true any more.

I say that as a reformed offender. For years I carried a strap that lived under a jerry can in the back of a Defender, and I judged it the way most businesses judge their encryption. It looked fine. It had never let me down. Thinking about it harder was a job for another day.

Nobody broke the maths

RSA-2048 and the elliptic-curve cryptography sitting underneath your banking app, your VPN, your code signing and every padlock in your browser are rated components. They were never unbreakable. They were expensive. The rating says that getting through this would take a quantity of arithmetic so large that nobody sane would attempt it.

If RSA could speak, she would be blunt about it. “I never claimed I couldn’t be broken. I claimed I wasn’t worth the trouble. Don’t put that on me.”

Nobody has broken the maths. There is no flaw in RSA, no crack in the algorithm, no clever bit of number theory that undoes thirty years of trust. What has changed, and changed fast, is the cost of the pull.

In 2019, Craig Gidney at Google and Martin Ekerå at KTH in Stockholm published the estimate the industry then planned around: factoring a 2048-bit RSA key would need a quantum computer with 20 million noisy qubits, running for about eight hours. Twenty million was a comfortable number. It put the problem squarely in the next generation’s in-tray.

In May 2025, Gidney revised his own figure down to fewer than one million qubits, running for under a week, on identical hardware assumptions. Same error rate, same grid, same cycle time. A twentyfold reduction bought entirely with better arithmetic and better error correction.

In February 2026, a Sydney startup called Iceberg Quantum published an architecture that, in simulation, takes the requirement below 100,000.

In March 2026, Google’s quantum team, with co-authors from the Ethereum Foundation and Stanford, showed that the elliptic-curve maths protecting most digital signatures and every major cryptocurrency could fall to fewer than 500,000 qubits, in minutes rather than days. Then they did something I have not seen before in this field. They declined to publish the attack circuits, releasing instead a mathematical proof that their numbers hold without showing anyone how. Nobody withholds circuits for a problem that is thirty years away.

On the same day, a team from Oratomic and Caltech, John Preskill among the authors, put the floor lower still, at as few as 10,000 reconfigurable atomic qubits on a different kind of machine.

Notice what did not happen in any of that. Nobody built a bigger machine. The hardware assumptions in 2025 were the same ones used in 2019. What improved was the rigging, and anyone who has run a double line through a snatch block knows that feeling: same winch, same motor, same battery, and suddenly the vehicle moves. The pull did not get stronger. It got organised.

The dates people are putting in their own diaries

You can argue with a resource estimate. It is harder to argue with what serious operators are doing to their own calendars.

Google committed publicly in March to making its own infrastructure quantum-safe by 2029. Cloudflare moved to 2029 in April. Microsoft has moved its programme to 2029. The American executive order signed on 22 June gives federal agencies until the end of 2030 to move their most sensitive systems to post-quantum key exchange, and until the end of 2031 for digital signatures, with a rule in the works to put that same 2030 date on federal contractors. NIST’s transition schedule deprecates RSA and elliptic curve after 2030 and disallows them after 2035.

Not one of those is a prediction of when a machine arrives. Each is an organisation counting backwards from a date it does not control and discovering that the work is longer than the runway.

Michele Mosca reduced the whole thing to one line in 2015, and it remains the only piece of quantum theory a director actually needs. Add the years your data must stay secret to the years your migration will take. If that total is greater than the time until a working machine exists, you are already late.

Run it against your own business. Medical records. Employee files. KYC packs. Litigation. Board papers. Long contracts. Source code. The pricing model that took four years to build. Some of that has to hold into the late 2030s, and the American government has given itself four and a half years to do its own crown jewels, having started long before you did.

Here is the part boards keep missing. An attacker does not need the machine today. He needs the ciphertext today. Traffic captured now costs almost nothing to keep on a disk while the arithmetic gets cheaper around it. I have yet to find the clause in POPIA that forgives a breach on the grounds that the encryption was perfectly adequate on the day you sent it.

Where my own argument is weak

I am not going to pretend this is one-sided.

No cryptographically relevant quantum computer exists. Every number above is a resource estimate, not a machine. The Iceberg and Oratomic architectures are validated in simulation rather than in silicon, and they need qubit connectivity, decoder speeds and clock rates nobody has demonstrated at scale. Every reduction since Gidney’s has come from changing the assumptions rather than from sharpening the arithmetic, and each new set of assumptions carries its own unproven engineering. Holding error-corrected computation together across hundreds of thousands of qubits for days on end, while decoding measurement data in real time, is an unsolved engineering problem, and unsolved engineering problems have a habit of running longer than the papers imply. This field has been ten years away for about thirty years.

There is money in the fear, too. A whole industry sells quantum readiness, this year has been branded the Year of Quantum Security by people selling partnership tiers in it, and there is a queue of vendors ready to sell you a two-year cryptographic inventory before you have protected a single connection. Quantum key distribution is sold hardest of all and solves the least for a normal business. Being sold to does not make a threat false. It does mean reading the invoice as carefully as the white paper.

Who should move now, and who shouldn’t

Move now if you hold anything that has to stay confidential past 2035. Move now if you sell into a supply chain that touches the American federal government, because the contract clause lands well before the machine does. Move now if you run long-lived keys: root certificates, code-signing keys, and equipment sitting in a substation or a plant room on a fifteen-year service life, where the cryptography is effectively soldered to the decade.

Don’t move now if you are a small business whose most sensitive data is worthless in eighteen months, and don’t let anybody frighten you into a programme you cannot staff. Your browser and your cloud provider have quietly done a good deal of the encryption half for you already, at no charge. Don’t buy quantum key distribution hardware. Don’t let a cryptographic inventory become the entire programme either, because a perfect map of a burning building is still not a fire escape.

What I have asked of our own people is short and dull. Know the shelf life of what we hold. Put post-quantum support, at no premium, into every procurement and every renewal from here on. Start with the traffic crossing the public internet, because that is what gets harvested, and then work inward.

I did throw that old strap away in the end. Not because it failed, and not because it looked bad. It never did either. I threw it away because “it has always held” is a statement about the past, and the label was making a promise about a future it knew nothing about.

The strap in the Monster now has a date on it, written on the label in marker, where I have to look at it every time I pack the recovery bag. Not the date it was made. The date it comes out.

Johan de Villiers,
CEO,
First Technology Western Cape