@cthos @aud One addendum I should have added: even were a quantum computer capable of breaking practical keysizes of a candidate post-quantum cryptosystem within the forward secrecy time of a backup, it's likely that actually performing said break would be exorbitantly expensive for quite a while. If your stuff is specifically interesting to a degree that three-letters are willing to hold it encrypted for twenty years then spend millions to get into it, quantum is the least of your worries.