The security industry is currently executing the largest cryptographic migration in history, shifting from RSA and elliptic curves to post-quantum algorithms. Most teams are doing this because the NSA told them to, without fully internalizing the fragility of the assumptions they are now trusting. This conversation with ETH Zurich's Renato Renner is a direct antidote to that blind spot. Recorded at QIP 2026, Renner explains why he co-authored a widely cited response advocating for a hybrid approach right now: layering classical elliptic-curve crypto with lattice-based schemes. The reason is brutally practical. Lattice problems have been tested by an order of magnitude fewer mathematicians than factoring, meaning the confidence that they are hard is significantly lower. Post-quantum cryptography remains a bet on computational complexity that could be broken by purely classical advances. Renner then draws the ultimate contrast: quantum cryptography rests on physical law, not mathematical assumptions. It ends the perpetual arms race between cryptographers and attackers because the laws of physics cannot be overturned by a clever algorithm. This is not a theoretical debate. It is a roadmap for how to think about the next ten years versus the next fifty.

Key Takeaways

  • Post-quantum cryptography is the correct decision for a 5-10 year security horizon, but it is a temporary bet on poorly tested mathematical hardness assumptions.
  • Lattice-based problems have been scrutinized by an order of magnitude fewer mathematicians than integer factorization, making single-scheme reliance dangerously premature.
  • A hybrid model combining elliptic-curve cryptography with lattice-based and hash-based schemes is necessary right now to avoid putting full trust in immature primitives.
  • Quantum cryptography eliminates the attacker-cryptographer arms race permanently because its security derives from physical laws, not computational complexity assumptions.
  • The NSA's migration mandate is pragmatically correct for the short term, but it does not solve the long-term problem of classical cryptanalysis potentially breaking post-quantum schemes.

Who should watch: Security architects and applied cryptographers designing migration roadmaps who need to distinguish between immediate compliance requirements and long-term provable security guarantees.

Why This Matters

The industry is sleepwalking into a new monoculture of lattice-based trust without acknowledging that post-quantum cryptography inherits the same fundamental weakness as RSA: it assumes a math problem is hard. Renner's framing makes clear that the real endgame is physics-based security, and the next decade is just a bridge.

Watch the full video →