Tag Archives: auIGF

AuIGF 2026 Panel Report: Is the Internet Ready for Q-Day? 

Executive Summary 

During auIGF 2026, we brought together experts across academia, industry, and internet governance to explore whether the internet is prepared for “Q-Day” (the point at which quantum computing becomes powerful enough to break modern cryptography). Moderated by Professor Robin Doss (Deakin Cyber Research & Innovation Hub), the panel examined the underlying mechanics of quantum computing, the specific technical and infrastructure risks facing protocols like DNSSEC, TLS, and PKI, and the practical and policy hurdles to migration.  

The overarching consensus among the panel is that while standardized post-quantum cryptography (PQC) algorithms are now available, the internet as a whole remains largely unprepared. On a scale of 1 to 10, the panelists gave the internet’s current readiness an average score of only 3 to 4. Panelists emphasized that migrating legacy infrastructure, incorporating post-quantum cryptography directly in protocols, ensuring cryptographic agility, preventing a “two-speed internet,” and driving government-led readiness planning are critical priorities before Q-Day arrives. 

Introduction 

Below are the findings and discussions of our panel discussion during the auIGF 2026 on “Is the internet prepared for Q-Day?”. During this panel, we posed the question of what will happen if quantum computers become reality and how we can mitigate their threats. We encourage readers to research this topic and think about how we can prepare the internet for such an eventuality. The report below is solely based on responses given by the audience and panelists. If readers are interested in more information about quantum computing, post-quantum cryptography, and Q-Day, we refer to the following resources: 

  1. Quantum Computing Explained 
  2. Can We Stop Quantum Computing Breaking the Internet? 
  3. What Is Post-Quantum Cryptography? 
  4. Q-Day has already begun. Are you ready? 

        What is Quantum Computing? 

        We asked the panelists to explain the differences between quantum computing and traditional computers. 

        Emeritus Professor Glenn Wightwick (auDA) outlined the fundamental differences between classical and quantum computing. Classical Computing is built on traditional computing models that use binary data (0s and 1s) processed through millions of transistors in microprocessors. Quantum Computing, on the other hand, uses principles of quantum mechanics to process information via quantum bits or “qubits”. Unlike standard bits, qubits can represent 0 and 1 simultaneously.  

        Assembling enough qubits allows a system to represent exponentially larger informational states than classical computers, enabling computations at a much larger and faster scale. A sufficiently powerful quantum computer can run specific studied algorithms to break cryptography by factorizing the product of very large prime numbers; the core mechanism underpinning most current public-key cryptographic algorithms. 

        Quantum Risks 

        The panelists highlighted several explicit technical, infrastructure, and operational risks introduced by quantum computing. 

        Cryptographic Vulnerabilities 

        Associate Professor Sushmita Ruj (UNSW) clarified that public-key (asymmetric) algorithms are vulnerable to being broken by quantum algorithms, whereas symmetric key algorithms are not affected in the same way.  

        Both Sushmita Ruj and Glenn Wightwick highlighted the threat of “Harvest Now, Decrypt Later”. Adversaries can steal and store encrypted sensitive data today (e.g., medical records or personal data). Even though it is safe against current classical technology, attackers can hold the data and decrypt it years down the road once a quantum computer is available.  

        Internet Infrastructure and Protocol Risks 

        Glenn talked about how quantum impacts certain protocols, such as DNS/DNSSEC. He explained that while DNS data itself is public (meaning “harvest now, decrypt later” is not a primary threat to DNS), DNSSEC relies on digital signatures to ensure records are not tampered with. A quantum computer could break this signature scheme, allowing attackers to re-sign DNS zones and maliciously redirect traffic (e.g., redirecting users visiting anz.com.au to steal money and credentials).  

        Dr. Syed Shah (Deakin Cyber Research & Innovation Hub) noted that post-quantum digital signature algorithms feature significantly larger signatures and keys. In DNSSEC, these larger payloads cause responses to exceed standard UDP packet limits, leading to packet fragmentation (which harms security) or forcing fallback to TCP (which adds connection overhead).  

        Dr. Dongxi Liu (CSIRO) emphasized that quantum risks extend well beyond replacing basic RSA/elliptic-curve algorithms. Cryptosystems are more than only the cryptographic algorithm; there is also the protocol itself. Changes need to happen on the protocol level as well as the cryptographic level to become quantum safe. 

        Dr. Warren Armstrong (Quintessence Labs) pointed out that newly standardized PQC algorithms have received relatively limited public examinations compared to classical algorithms. He noted that candidate algorithms have previously fallen apart late in the standardization process due to classical cryptanalysis, a risk that may increase if AI begins synthesizing different fields of mathematics. 

        What is Q-Day? 

        The term “Q-Day” is often used in the media, but what exactly does it mean? We asked our panelists. 

        Sushmita Ruj explained that Q-Day refers to a future point in time when quantum computers become capable of breaking classical public-key cryptography. She also noted a common misconception: Q-Day will not be a single catastrophic day where the entire internet instantly stops, all bank accounts are suddenly hacked, or everyone’s messages are decrypted at once. 

        The exact arrival of Q-Day is unknown. Panelists noted that unlike Y2K, which had a fixed, definite deadline that forced urgent code rewrites and system migrations, Q-Day has no fixed date.  

        We asked the panelists and the audience what would happen in the first 24 hours after Q-Day. 

        Warren Armstrong noted that an announcement would likely come from a public or commercial entity rather than a government nation-state (which would likely keep the capability secret). He added that an immediate risk would be losing the ability to rely on digitally signed audit records and financial log files, causing trust to collapse.  

        Glenn Wightwick stated that impact depends on who holds access, predicting a potential surge in ransomware where adversaries monetize previously harvested, newly decrypted data.  

        Sushmita Ruj noted it could trigger widespread geopolitical disputes, sector riots, or societal panic depending on the sensitivity of exposed data. 

        How Prepared Are We for Q-Day? 

        When asked to rate the internet’s current readiness on a scale of 1 (completely unprepared) to 10 (fully prepared), the panel scored it as follows:  

        • Glenn Wightwick: 1 to 2  
        • Sushmita Ruj: 2  
        • Warren Armstrong: 3  
        • Dr. Dongxi Liu: 4  
        • Dr. Syed Shah: 4 to 5  

        Dr Syed Shah gave some more context regarding his score, noting positive movement in standardized algorithms and industry testbeds, but balanced by the massive installed base of legacy systems and Q-Day timeline uncertainty. 

        On Average, the panelists gave a score of 3 to 4 out of 10.  

        Sector and Organizational Awareness 

        Warren Armstrong observed that awareness varies significantly. In regions like the US, Australia, Singapore, and parts of the EU, awareness is higher, whereas visibility is limited in places like New Zealand and Indonesia. Critical sectors (like banking and ASX Top 50/150 companies) are actively engaged due to governance requirements, while many other organizations are distracted by immediate AI threats.  

        Major Migration Obstacles 

        Sushmita Ruj emphasized that the sheer size and interconnected complexity of the internet make seamlessly stitching new algorithms into protocols a massive hurdle.  

        Syed Shah and Glenn Wightwick highlighted that updating TLS, digital certificates, VPNs, software, and decades-old legacy hardware across the entire internet will take years. 

        Glenn Wightwick warned that while well-resourced cloud providers (e.g., Google) and large enterprises will migrate safely, small businesses, rural communities, and developing economies lack the resources and attention span to transition, risking a broad digital security divide.  

        Responsibility and Policy Roles 

        Dongxi Liu argued that vendors bear primary operational responsibility to integrate standardized PQC algorithms into commercial products so customers can deploy them easily.  

        Warren Armstrong and Glenn Wightwick stressed that governments must establish mandatory readiness milestones for critical infrastructure. Government elevation provides necessary visibility to corporate boards, elevates priority alongside broader cybersecurity agendas, and acts as a neutral arbiter. However, Warren cautioned that technical implementation and algorithm selection should remain with engineering and standards bodies (e.g., IETF, ICANN). 
         

        Conclusion 

        The panel concluded that solving the Q-Day challenge requires far more than just mathematical algorithms; it requires a coordinated, multi-year overhaul of protocol engineering, legacy hardware, and governance frameworks.  

        To prepare effectively, each panelist offered a closing priority for the internet community: 

        • Dr. Syed Shah: Modify protocols and transport modes (e.g., exploring QUIC or Merkle-tree authentication) to accommodate PQC requirements.  
        • Dr. Warren Armstrong: Design systems for cryptographic agility, the architectural flexibility to swap algorithms on the fly as threats evolve.  
        • Emeritus Professor Glenn Wightwick: Educate, build national plans, and invest in testing and remediation.
        • Dr. Dongxi Liu: Map system vulnerabilities and clarify roles across the migration lifecycle.  
        • Associate Professor Sushmita Ruj: Drive broad education and awareness across all sectors of society.  

        Moderator Robin Doss closed the session with an open challenge to the audience: “If Q-Day arrived earlier than expected, would we be able to say as an internet community that we have done enough?”