A very nice explainer why "if you're so worried about quantum computers, why haven't they factored 21 yet?" isn't a very convincing argument. Look at the labels of the graph, and how extremely close the various lines are for factoring 21 and 2048 bit numbers. Polynomial scaling remains polynomial, unfortunately, and by the time you can factor 21 you're almost ready to break RSA.

https://bas.westerbaan.name/notes/2026/04/02/factoring.html

Factoring is not a good benchmark to track Q-day

Homepage of dr. Bas Westerbaan, principal research engineer at Cloudflare, working on making the Internet post-quantum secure

@sophieschmieg so when we quanting? When's quanting time?
@sophieschmieg just as clarification: not meant to make fun of you but to make fun of me and how little I understand of this topic. I always thought I'm somewhat understandable in IT stuff, but every time I try to understand quantum computing, I feel like a toddler trying to understand quantum computing
@leberschnitzel that is the billion dollar question. There is a non negligible chance of it being as early as 2029, but it might very well be several years later, we just can't ignore it being possible in 2029.
@sophieschmieg yeah, totally get that.
At work we also preparing for it and especially the certificates team is working on things.