CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
Podcast

Digital Identity Security: Stolen Faces Crack Open by 2035

Digital Identity Security: Stolen Faces Crack Open by 2035

Digital Identity Security: Stolen Faces Crack Open by 2035

0:00-0:00

This episode is based on our article:

Read the full article →

Digital Identity Security: Stolen Faces Crack Open by 2035

Full Episode Transcript


Somewhere right now, someone is copying encrypted files they can't open. They're not frustrated. They're patient. Because according to warnings from the N.S.A. and N.I.S.T., attackers are collecting scrambled data today with a plan to unlock it years from now — when the technology catches up.


If you've ever scanned your fingerprint at a

If you've ever scanned your fingerprint at a border, or uploaded a photo of your passport to open a bank account, this touches you. And I want to be honest — this one stopped me cold when I first understood it. You can change a stolen password in about thirty seconds. You cannot change your fingerprint. Not ever. So today we're going to walk through why "your data is encrypted" is a promise with an expiration date nobody prints on the label. Why does encryption stop protecting you long after it was applied?

The attack has a name. Security researchers call it harvest now, decrypt later. Three steps. Someone intercepts or copies your encrypted data today. They store it. They wait. When a powerful enough quantum computer arrives, they open everything they've been sitting on.

The article uses an analogy I keep thinking about. Picture mailing a sealed letter, locked with a lock whose design will be publicly cracked ten years from now. Someone steals that letter and drops it in a drawer. They can't read it. They don't care. They just have to outlive the lock.

So why do so many of us assume encryption is permanent? Because it feels like a vault. A vault either holds or it doesn't. Nobody pictures a thief photocopying the contents and walking out to wait for a better crowbar. But that's the actual threat model. The word to focus on is "yet." Your attacker can't read the file yet.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why biometrics specifically

Now, why biometrics specifically? Your fingerprint, your iris pattern, the mathematical map of your face — those are static. They're you, permanently. A bank can issue you a new card number. Nobody can issue you a new iris. So a biometric file copied in 6/1/2026 and cracked in twenty-thirty-five is still a working key to your identity for the rest of your life.

And this isn't a niche problem. According to a research analysis drawing on more than a hundred primary sources, somewhere between ninety-five and one hundred percent of government-classified data encrypted today could be readable later. For healthcare records, it's essentially all of them. That's your medical history. That's your immigration file.

There is a response, and it's real. In twenty-twenty-four, N.I.S.T. finalized new encryption standards built to survive quantum computers. One handles secret keys. Two handle digital signatures — the math that proves a document actually came from who it says. Translation for the rest of us: new locks exist. The question is how fast anybody installs them.

And that's slower than you'd hope, for an unglamorous reason. Size. One of the old digital signatures is about sixty-four bytes — smaller than this sentence. One of the new quantum-resistant ones runs around four thousand bytes. Roughly sixty times bigger. Stack those into a full certificate chain and you're pushing eight to ten kilobytes through systems designed for a fraction of that. That's why airport gates, payment networks, and phone apps can't just flip a switch overnight.


The Bottom Line

So the real deadline isn't when quantum computers arrive. The deadline is now — because the data being stolen in this decade is the data that gets opened in the next one. Encryption was never a purchase. It's a lease, and nobody tells you when it expires.

Three things to remember. Attackers are copying encrypted data today, planning to unlock it in the twenty-thirties. Your biometrics can't be reset, so that delay doesn't protect you — it just postpones the harm. And new standards exist, but only data protected before the copying happens is actually safe. So the next time an app or an agency tells you your information is encrypted, you now know the better question. Encrypted for how long? That question isn't paranoia. It's literacy — and asking it is how you stop feeling powerless. The written version goes deeper — link's below.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search