6 min read
Post-quantum encryption means key-exchange algorithms that a quantum computer cannot break. In August 2024 NIST approved the first three standards: ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures. In a VPN the first one matters: key exchange is precisely what is vulnerable to the "harvest now, decrypt later" scenario. Below: what that scenario is, who it genuinely threatens, and how to tell a real implementation from a marketing sticker.
The scheme is simple and requires no quantum computer today. Traffic is intercepted and stored in encrypted form right now, on the bet that in a few years hardware will exist capable of recovering the exchange key retroactively. Decryption happens not at the moment of interception but once the capability arrives.
The key point that changes the risk assessment: what is at stake is not the session itself but its longevity. If the content loses value within an hour, the scenario is irrelevant to you. If it stays sensitive ten years from now, it is relevant today, because the interception is happening now.
| Who | Relevance | Why | |---|---|---| | Transmits data with a long sensitivity horizon | high | medical, legal and research data stay valuable for years | | Works with sources and is under surveillance | high | the target is specific and the observer's resources are large | | An organisation under regulatory requirements | high | in the US, national security systems must migrate by 2030, with classical algorithms disallowed by 2035 | | An ordinary user: social media, streaming, shopping | low | the content devalues faster than the hardware arrives |
The honest conclusion, rarely written down: for most everyday scenarios post-quantum encryption is not what addresses your actual risk today. Your passwords are taken not by a quantum computer but by an infostealer or by phishing. That is not an argument against post-quantum cryptography — it is an argument for doing things in the right order.
Shor's quantum algorithm breaks asymmetric schemes: RSA and elliptic curves, on which key exchange rests. Symmetric encryption of the stream itself — AES and ChaCha20 — is vulnerable in a fundamentally different way: quantum search cuts the strength roughly in half in exponent terms, and AES-256 remains beyond practical reach.
Hence the consequence: what needs replacing is not the stream cipher but the key agreement mechanism. That is why implementations look like hybrid schemes — a classical exchange plus ML-KEM, where the resulting key depends on both. If one mechanism breaks, the other keeps holding.
Four questions worth asking any service claiming post-quantum protection:
Among public examples: NordVPN reported moving its WireGuard variant to ML-KEM in 2025, and other services later announced adding post-quantum exchange. That confirms the implementation is available, not that everyone has it.
The service runs on VLESS with Reality masking. The Reality mechanism itself is built on X25519 key exchange — a classical elliptic curve; that is a property of the protocol, not a setting of any particular service. We do not claim post-quantum key exchange — and we do not hide that behind the phrase "modern strong encryption".
What that means in practice. If your scenario is the bottom row of the table above — ordinary private use — it does not affect your security today: the contents of your sessions will devalue long before hardware capable of recovering the key exists. If your scenario is one of the top rows — working with data of long sensitivity under targeted surveillance — you need a tool that states ML-KEM, and today that is not us.
On the other hand, the problem the service does solve is usually unsolved in post-quantum implementations: getting through filtering that cuts off tunnels by the appearance of their traffic. Reality gives you a handshake with a real site and no signature of its own — how that works. You have to choose by which threat is actually yours.
In order of risk-to-effort ratio:
The quantum threat is real and deferred. The ones listed are real and present.
What is post-quantum encryption in plain words? Algorithms a quantum computer cannot break. In a VPN what gets replaced is the key exchange mechanism: instead of a purely classical scheme, a hybrid with ML-KEM is used.
Do I need it right now? It depends on how long your data stays valuable. For messaging, streaming and shopping, no: the content devalues first. For data that is sensitive years from now, yes.
Will a quantum computer break AES? Practically, no. Quantum search cuts strength roughly in half in exponent terms, and AES-256 remains out of reach. It is key exchange that is vulnerable, not the stream cipher.
Does BessyConnect have post-quantum encryption? We do not claim it: the key exchange is classical. If your scenario requires ML-KEM, choose a service that states it and names the algorithm.
When will quantum computers become a practical threat? There is no verifiable date. Regulatory deadlines serve as a reference point: in the US, national security systems must migrate by 2030, with classical algorithms banned by 2035.
Instagram won't open or keeps lagging? BessyConnect VPN on VLESS+Reality restores access to Instagram so your feed, stories, and Reels load block-free. More
BessyConnect is a VPN for Telegram: restore chats and calls when Telegram isn't working. The VLESS+Reality protocol bypasses blocks and DPI on all devices. More
BessyConnect is a VPN for WhatsApp that restores voice and video calls when they're blocked. The VLESS + Reality protocol beats DPI. Get it for iOS and Android. More