top of page

Harvest Now, Decrypt Later: What VENONA Already Proved



Audio cover
Harvest Now, Decrypt Later

Starting in the 1940s, American codebreakers collected Soviet cables they had no way to read. They filed them away and waited.


The messages were protected by one-time-pad encryption — OTP — the one system that's genuinely unbreakable when it's used correctly. Perfect randomness, never reused, kept secret. That's not a marketing claim. It's mathematically true.


But under the strain of the war, the Soviets duplicated their OTP key material instead of generating it fresh. Pages that were supposed to be unique got used more than once. That duplication became the thread American analysts eventually pulled.


It took them a long time to pull it. The effort, later code-named VENONA, didn't break its first message until 1946, and it ran until 1980 — nearly 40 years of work. Messages sent during the war were still being read decades later. When the plaintext finally surfaced, it helped expose Soviet agents inside the Manhattan Project, including the physicist Klaus Fuchs, and a web of sources across the US government.


Every one of those messages was sent by someone who believed it was safe. They were right about the mathematics. They were wrong about the timeline. The gap between "secure today" and "secure for as long as this has to stay secret" is where all the damage lived.



TWO DIFFERENT FAILURES, ONE LESSON

It's tempting to draw a straight line from VENONA to today's quantum computing threat, but the honest version of the story has a wrinkle worth sitting with.


VENONA failed because humans violated the rules. The math behind one-time pads was never broken — the discipline around generating and using the key material was. That's an operational failure, not a mathematical one.


RSA and elliptic curve cryptography, the encryption underneath almost everything digital today, would fail for a completely different reason. Nothing about how we use them has to go wrong. A sufficiently capable, fault-tolerant quantum computer running Shor's algorithm could break the math itself, correctly implemented, no mistakes required.


That's a subtle distinction, but it matters. One failure mode is about discipline. The other is about the ground shifting underneath a system that was never misused at all.


What connects them isn't the mechanism of failure. It's the timeline. In both cases, the security assumption was true at the moment the message was sent, and false by the time anyone found out it mattered.



THE MEASURE THAT MATTERS IS TIME, NOT ONLY STRENGTH

That's the real takeaway, and it's worth sitting with directly.


Security isn't just asking "can someone break this today?" It's asking "will this still be secure for as long as the information has value?"


Nobody expects an attacker to crack RSA-2048 this afternoon. That's not the threat model. The threat model is "harvest now, decrypt later" — encrypted traffic is being collected and stored today specifically so it can be decrypted years from now, once quantum capabilities mature. You don't need to break the encryption today. You just need to be patient, and have somewhere to put the data while you wait.


That's exactly the VENONA playbook, run on a different clock. Collect what you can't read yet. File it away. Wait for the tool that makes it readable. The only thing that's changed is what kind of breakthrough you're waiting for — human error then, computational capability now.


This is why governments and large enterprises are already migrating toward post-quantum cryptography, well before any quantum computer can actually break current encryption. Migrating early isn't about solving today's threat. It's about protecting confidentiality that has to survive into a future where today's math no longer holds.



THIS ISN'T JUST ABOUT STATE SECRETS ANYMORE

VENONA's targets were diplomatic cables and intelligence traffic — the kind of thing you'd expect a government to collect and wait decades to read. But the "harvest now, decrypt later" problem has quietly expanded to cover almost everything with a long shelf life.


Medical records. Financial data. Intellectual property. Source code. Legal communications. Critical infrastructure design. AI model weights and training data.


Many of those have a useful lifetime measured in decades, not years. A patient's genetic data matters as much in 2050 as it does today. A company's proprietary model weights or training pipeline can still be a competitive asset a decade from now. Legal privilege doesn't expire on a schedule that lines up conveniently with cryptographic obsolescence.


So the real question for anyone holding data like that isn't "is my encryption safe today?" It's "will this data still matter when today's encryption no longer does?" If the answer is yes, the VENONA clock is already running on your data, whether or not you've thought about it that way.



WHY THIS ISN'T PARANOIA

VENONA is a genuinely useful case study here because it's not a hypothetical. It's proof, on the record, that "collect now, break later" works — not in theory, but as an executed 40-year intelligence operation with real consequences. It didn't require a technological miracle. It required patience and one operational mistake by the target.


Quantum computing removes the need for the mistake. The math becomes vulnerable on its own timeline, independent of how carefully anyone follows the rules. That's a harder problem to defend against than a discipline failure, because you can train people not to reuse a key. You can't train mathematics not to be breakable.


The organizations already moving to post-quantum cryptography aren't reacting to an active threat. They're reacting to a lesson that's already been proven once, in public, with declassified documents to show for it. The gap between "secure today" and "secure for as long as it needs to be" is where VENONA's damage lived for forty years. It's the same gap sitting under a huge amount of the data being encrypted today.


The math is fine right now. The question was never whether the lock works today. It's whether anyone's willing to bet the contents still matter in twenty years — and whether they're comfortable with someone else placing that bet for them, quietly, in a server somewhere, right now.


Ad: Use code: RICH99 for a discount
Ad: Use code: RICH99 for a discount

Rich Washburn is a technologist and strategist working at the intersection of AI, infrastructure, and capital. He is Managing Partner and Chief AI Officer at Eliakim Capital.

Comments


Animated coffee.gif
cup2 trans.fw.png

© 2018 Rich Washburn

bottom of page