Skip to main content
RelixQ
Menu

HNDL

Harvest Now, Decrypt Later Fundamentals

Harvest-now-decrypt-later (HNDL) risk exists before any quantum computer does: an adversary who can capture protected data today can decrypt it later, once a cryptographically relevant quantum computer exists. This course builds a repeatable way to reason about that exposure — from a single piece of data, through how long it must stay confidential and where it can actually be captured, to what cryptography really protects it and whether migration is already late. Prior completion of [PQC Foundations](/academy/pqc-foundations) is recommended but not required.

Beginner to intermediateLevel
30-45 minutesDuration
7Lessons
HNDL Fundamentals — Certificate of CompletionCredential

Who this course is for: Security engineers, architects, developers, security leaders, and risk professionals who need to decide what to migrate first, not just that migration is coming.

Your progress

Checking your progress in this browser…

The core question

"What data may already be at risk before cryptographically relevant quantum computers arrive?"

Outcomes

What you can do when you finish.

  • Explain what harvest-now-decrypt-later means and why it creates risk today even though no cryptographically relevant quantum computer exists yet.
  • Distinguish the confidentiality risk HNDL creates from the separate, future-only forgery risk facing signatures and long-lived signing keys.
  • Evaluate a specific data flow against four variables — confidentiality lifetime, harvestability, protection path, and evidence confidence — to judge its exposure.
  • Apply Mosca's inequality (X + Y > Z) as a planning heuristic to judge when migration is already late, without treating it as a measurement.
  • Rank concrete data classes into a defensible migration priority order, and state which variable drove each ranking.

Topics

What the course covers.

What harvest-now-decrypt-later (store-now-decrypt-later) meansWhy HNDL creates risk before any quantum computer existsConfidentiality risk vs. future forgery risk for signaturesData confidentiality lifetimeHarvestable surfaces: transit, backups, third parties, logs, and replicasThe protection path from data to the cryptography actually guarding itShor's algorithm vs. Grover's algorithm and why the difference mattersWhy forward secrecy does not stop HNDLHybrid key exchange and X25519MLKEM768Evidence confidence and what "unknown" meansMosca's inequality (X + Y > Z) and the exposure windowPrioritizing migration candidates across real data classes

Recommended first

Consider these before starting.

Course outline

Modules and lessons.

Module 1

The exposure

What harvest-now-decrypt-later actually means, why it creates risk before any quantum computer exists, and why it is a confidentiality problem rather than a forgery problem.

  1. What HNDL means6 min

    Define HNDL, its adversary model, and why it is a confidentiality problem, not a forgery problem.

Credential

HNDL Fundamentals — Certificate of Completion

Awarded after the final assessment, which is graded server-side so the score cannot be a number the browser chose.

Explaining HNDL exposure without invented timelinesDistinguishing confidentiality risk from signature and integrity riskAssessing data confidentiality lifetimeMapping realistic data-capture surfacesApplying Mosca's inequality as a planning heuristicPrioritizing migration candidates with defensible reasoning

Every issued credential can be checked at RelixQ Academy credential verification.

Final assessment

14 questions · 80% to pass

Scenario-based, timed only by your own pace. Retake it as many times as you need.

Go to the final assessment