A very nice explainer why "if you're so worried about quantum computers, why haven't they factored 21 yet?" isn't a very convincing argument. Look at the labels of the graph, and how extremely close the various lines are for factoring 21 and 2048 bit numbers. Polynomial scaling remains polynomial, unfortunately, and by the time you can factor 21 you're almost ready to break RSA.

https://bas.westerbaan.name/notes/2026/04/02/factoring.html

Factoring is not a good benchmark to track Q-day

Homepage of dr. Bas Westerbaan, principal research engineer at Cloudflare, working on making the Internet post-quantum secure

@sophieschmieg I suspect people will listen to cryptographers and quantum-focused computer scientists on this subject with the same focus and rigor they did when they said "no, no, don't roll your own cryptography, that's a bad idea".
@sophieschmieg so when we quanting? When's quanting time?
@sophieschmieg just as clarification: not meant to make fun of you but to make fun of me and how little I understand of this topic. I always thought I'm somewhat understandable in IT stuff, but every time I try to understand quantum computing, I feel like a toddler trying to understand quantum computing
@leberschnitzel that is the billion dollar question. There is a non negligible chance of it being as early as 2029, but it might very well be several years later, we just can't ignore it being possible in 2029.
@sophieschmieg yeah, totally get that.
At work we also preparing for it and especially the certificates team is working on things.

@sophieschmieg A physicist I used to work for said quantum computing is very good right now for getting grant money to develop very nice ADC's and detector circuitry, which is useful for astronomy and particle physics.

He admitted when I pressed him that he agrees that the actual computing part is complete bunk and going nowhere.

@sophieschmieg This articlae say, you shouldn't take factoring as a good metric to measure progress, fair enough, but then you argue, in fact it's gonna be very soon we can factor. Isn't this a contradiction? THis is not a snarky remark. Personally I think QC is a risk, like there are many others. But I think there are biger, known risks.

And the store now decrypt later stuff I think is non-sense. Storing everything is not feasible, storing select stuff means you have a problem now, because some one ass already access to select important stuff. That boils down to a quote from Adi Shamir: NSA is not a crypto breaking agency, it's a crypto evading agency,