Technical
HNDL collection vectors: breach, backups, and TLS capture
Harvest-now-decrypt-later does not require nation-state quantum computers — it requires storage and patience. These collection vectors appear in every mid-market threat model.

Collection vectors
| Vector | What is captured | Why it matters post-Q-Day |
|---|---|---|
| Network interception | TLS handshakes + ciphertext | ECDH/RSA key exchange recoverable |
| Breach exfiltration | Database backups, archives | Bulk encrypted blobs stored offline |
| Cloud object storage | S3/GCS buckets with encrypted objects | Long retention, shared keys |
| Email archives | S/MIME, PGP, TLS-wrapped SMTP | Legal hold = decades of shelf life |
| Legal/compliance hold | eDiscovery exports | High-value, immobile datasets |
Palo Alto on Q-Day and Unit 42 IR data show exfiltration often completes faster than incident response — copying ciphertext is cheap.
PostQuantum.com frames HNDL as present-day risk. CISA recommends migration planning now.
Jeremy Allison's embedded talk covers practitioner migration complexity — FIPS validation, embedded systems, and library coordination.
Prioritization framework
- Tag data classes by confidentiality lifetime (X in Mosca's inequality).
- Map which vectors can reach each class.
- Migrate highest X × exposure vectors first — often finance, health, and IP archives.
Related: how encrypted data is harvested.
This quarter
- Add HNDL collection vectors to your enterprise threat model.
- Extend scanning beyond web TLS to email, backups, and JWKS.
- Quantify Mosca exposure for top three data classes.
Continue on the Q-Day hub: Harvest now, decrypt later guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- Why Your Encrypted Data Is Already Being Stolen (Jeremy Allison, CIQ)YouTube · 2025Practitioner perspective on HNDL, PQC migration complexity, and FIPS certification for open source.
- Unit 42 Incident Response Report — exfiltration timelinesPalo Alto Networks Unit 42 · 2025Incident response data showing compressed exfiltration timelines — copying ciphertext is faster than breaking crypto today.
- What Is Q-Day? Quantum Computing and Cyber RiskPalo Alto Networks · 2026CRQC definition, HNDL threat model, and migration guidance for enterprise security teams.
- What Is Harvest Now, Decrypt Later (HNDL)?PostQuantum.com · 2024Mosca theorem, HNDL urgency, and why migration must start before Q-Day headlines.
- CISA Post-Quantum Cryptography InitiativeCISA · 2024US government guidance on quantum risk, migration planning, and PQC adoption.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.