Nyheter

The threat landscape facing encryption: vulnerabilities, backdoors and quantum computers

Published: Sep 7, 2026
Kryptologins historia 2

The threat landscape facing encryption looks different from the one facing other security solutions. The protection often stands alone, and its weaknesses can be hard to spot. But what is it that actually threatens encryption?

The difference becomes clear if you compare it with how IT security is otherwise built. In an IT system, security is normally built in layers. Firewalls, intrusion detection, logging and monitoring work together, and if one layer fails another can catch the attack. An encrypted message that has already been sent cannot be recalled. A firewall that does not hold up against a new type of threat, by contrast, can be replaced, and the damage stops there.

"If I have encrypted something and sent it out, and it then turns out the encryption was not good, I can replace the device, the mechanism or the algorithm. But what I sent out is already out there," says Jens.

A message that cannot be broken today may be breakable in two years, or in ten. Anyone collecting encrypted traffic now can therefore simply wait for the methods to catch up. The approach is usually called harvest now, decrypt later: gather ciphertext today, decrypt it once the means exist. The protection therefore has to be right from the outset.

Attacks that leave no trace

A cryptosystem that has been broken looks exactly as though it were still working.

"If a cryptosystem does not hold up, and someone is sitting there reading what I have sent out, I will never know. There is nothing to indicate that the system has been broken," says Jens.

An intrusion into an IT system, by contrast, is noticed sooner or later. Information disappears, systems stop working and the activity leaves traces in the logs. A clear example of the difference is the Second World War, when the Allies were able to read German traffic encrypted with Enigma without Germany realising it. The machines did exactly what they were supposed to do, but the system was not secure enough. Operational handling accounted for the rest: repeated key settings, predictable phrasing and carelessly chosen keys.

Four surfaces to attack

The threat landscape can be divided up according to what an attacker actually targets.

The first is the method, meaning the algorithm or the cryptosystem itself. Here the protection is comparatively strong today. Open algorithms that are scrutinised by independent experts, tested in several rounds and adopted as standards make it difficult to conceal mathematical weaknesses. Standardisation work is driven to a large extent by NIST, the US standards agency.

The second is the implementation. The right algorithm can be implemented wrongly. A product can use an approved method and still contain flaws in its design, hardware or code. This is why cryptographic products are scrutinised considerably more rigorously than most other IT products.

The third is key management. Keys are generated, distributed, used and destroyed, often in processes that sit partly outside the system itself and that require human handling. That leaves room for both mistakes and carelessness.

The fourth is operational handling. A system used in the wrong way can become breakable even if everything else is correct. Enigma is an example of how the surfaces connect: the weakness in the design only became useful in combination with how the machines were handled.

Backdoors

Beyond unintentional errors there is a category of threat particularly associated with cryptography: deliberately built-in weaknesses.

Perhaps the best-known example is Crypto AG, the Swiss cryptography company that for decades sold equipment to much of the world while being owned by American and West German intelligence services. Its customers believed they were protecting their communications. In practice, they were handing them over. The company has Swedish roots. Crypto AG grew out of Boris Hagelin's cipher machine manufacturing in Stockholm, AB Cryptoteknik. Hagelin moved to Switzerland in 1948 and founded Crypto AG four years later.

Backdoors need not be planted in a product, though. They can be planted in the standard. According to the Snowden documents, the American intelligence agency NSA placed people in standardisation work in order to push through a standard containing a weakness, without the other participants realising it.

One documented case is the random number generator Dual EC DRBG, which is based on elliptic curves and was standardised by NIST in 2006. The generator uses two fixed points on the curve, and anyone who knows the relationship between them can predict the numbers to come after seeing a small amount of output. As early as 2007, researchers showed that such a backdoor was constructible. The algorithm nevertheless remained preselected in one of the most widely used cryptographic libraries on the market, which meant that anyone who did not actively choose otherwise got it by default. After the Snowden documents in 2013, NIST advised against the algorithm within days, and in 2015 it was formally removed from the standard.

The case also illustrates a general problem in modern cryptology. Very few people have the expertise to judge whether a cryptosystem is actually secure, while a great many depend on that judgement being right.

"It is both neatly done and fairly brutal. You take part in a standardisation committee with the opposite aim to what the committee is there to do, and nobody notices," says Jens.

The fact that backdoors are hard to detect is bound up with the complexity of modern cryptosystems. They contain a great deal of electronics and often hundreds of thousands of lines of code. That is one of the reasons most countries regulate how cryptosystems may be used to protect national security, and impose particular requirements on cryptography suppliers, including security-cleared personnel and scrutiny of the products.

Compared with the past, the centre of gravity has shifted.

"Historically we had weak methods, but there was usually nothing wrong with the device itself. Enigma did what it was supposed to do. Today it is almost the other way round. We have a good grasp of the methods, but less of a grasp of these complex devices," says Jens.

Quantum computers

The single largest threat on the horizon for today's cryptosystems is quantum computers.

An ordinary computer works with bits that are either one or zero. A quantum computer works with qubits, which can be in both states at once. This rests on quantum physical properties that only persist as long as the particles are completely isolated from their surroundings, which for most of today's platforms requires a vacuum and temperatures close to absolute zero. That is why quantum computers are extremely difficult to build.

Quantum computers exist today, but not at a size and stability sufficient to break encryption. The design principles, on the other hand, are known.

The threat applies above all to the asymmetric algorithms, which are used for key exchange in most systems. Break the key exchange and the attacker has the key, and with it the content.

Since quantum computers do not yet exist, it is reasonable to ask why upgrades should be made today. The answer lies in the time dimension.

"If you have a secret, you have to consider how long it needs to stay secret. If it is the identity of an intelligence officer, for instance, the classification may need to last a lifetime. Send it with a cryptosystem that is not quantum-safe, and if a quantum computer comes along later, the information can be broken while it is still sensitive," says Jens.

Researchers in the field tend to say that a sufficiently powerful quantum computer could exist within ten to fifteen years. Information that has to be protected for longer than that therefore needs quantum-safe protection today.

The standards are in place. NIST established the first algorithms for quantum-safe encryption in August 2024, with a further algorithm selected in 2025 to broaden the mathematical basis. Work on introducing them into existing systems is under way, and it is extensive.

The threat landscape facing encryption has always been in motion. Someone builds a system, someone else finds a way to break it, and a new system takes over. What changes is not the principle, but the resources and the time horizon available to the attacker.

Linked In 9

About Jens

Jens Bohlin has been CEO of Tutus since 2009 and has a long background in cryptology and information security. He has previously worked as a technical cryptologist at both MUST and FRA, as well as at the Ministry for Foreign Affairs on joint initiatives relating to cryptography and secure systems. Jens holds a master's degree in computer science and engineering.

Namnlos design 20

About Tutus

Tutus is a Swedish cybersecurity company providing comprehensive solutions in information and network security, with a particular focus on encryption and secure communication. Since 1992, we have developed advanced solutions for critical societal functions with high security requirements — offering products approved for handling security-classified information up to the level of Restricted at the national level, as well as EU Restricted and NATO Restricted.