Quantum computers will break the signatures that secure the web. The transition forces everyone to touch every certificate anyway. That makes this the one moment when fixing the deeper problem — who gets to speak for your website — costs almost nothing extra.
A sufficiently large quantum computer will break RSA and elliptic-curve cryptography — the mathematics behind every padlock, every digital signature, every certificate on today's internet. Nobody knows the year. Serious governments are planning for the 2030s.
But the deadline isn't "when the machine exists". Adversaries are recording encrypted traffic today to decrypt it later — the strategy known as harvest now, decrypt later. Anything that must stay confidential for ten years is already on the clock.
That's why NIST finalised post-quantum standards in 2024, why browsers are already rolling out post-quantum key exchange, and why the EU's migration roadmaps say: start now.
Post-quantum signatures are up to 40× larger than today's. Bolted onto the existing certificate system, they make every website connection noticeably heavier — extra data, on every visit, for every user. ConsensusPKI avoids this by moving the heavy signatures off the connection entirely: they're checked once per hour, not once per visit, and a fully post-quantum proof stays no larger than today's certificates.
Every few years, the single-point-of-failure design produces the same headline with a different name on it.
A breached Dutch authority issued 500+ fake certificates, used to intercept an estimated 300,000 people's communications. The authority went bankrupt; the design survived.
One of the world's largest certificate authorities was found to have mis-issued thousands of certificates over years. Browsers eventually distrusted it entirely — a multi-year, ecosystem-wide cleanup.
Mis-issuance incidents surface routinely in the transparency logs: wrong domains, skipped checks, compromised registrars. Each one is accepted by every browser until noticed and revoked.
Transparency logging made these visible. It didn't make them impossible. The certificates all worked.
The post-quantum transition forces new keys, new certificates and new software on every website and browser. A once-in-a-generation upgrade window is open.
Bolting big signatures onto the old design taxes every connection, for every user, indefinitely. Redesigning what travels per connection removes the tax once, permanently.
New algorithms mean re-establishing every trust relationship anyway. That's exactly the moment to stop rebuilding single points of failure.