Entropy Or Cascading Failure: The Birth Of A New Field For AI And Post-Quantum Security
The day a quantum computer comes online, RSA and ECC fall together. The day after, AI starts reading everything that was ever encrypted.
Sometimes it takes a hacker to see things differently. If you ever see a hacker politely nodding after you just called your new system “unhackable,” just know that we know. We know that every wall has a crack if you look long enough. Right now, we are going to look at a crack in the very floor of our global infrastructure.
Problem 1: The Invisible Clock
Quantum computers are computers that can guess every possible answer at one moment within a possibility space. A possibility space is a given range, say q through z, where the answer is hidden. A classical computer, which includes every computer you use now and even the world’s most powerful supercomputers, tries to figure out the answer sequentially. It goes in order: q, r, s, t, u, v.
A quantum computer drops every possible answer in at the same moment and spits out the right one. It does not go in order because it happens at the same time. Boom. Answer.
This is not just “faster.” That is the sleight of hand. It is different. Our computers, our internet, and our cybersecurity are not ready for “different.” These machines leverage superposition and entanglement to use qubits instead of the binary code of 1s and 0s we traditionally use. We are in a race with an invisible clock. We do not know where the players are or the time.
Problem 2: The Retroactive Breach
The day a fully realized quantum computer comes online is the day both RSA and ECC, the only two encryption standards we have in play, can both be busted through like the Kool-Aid Man through a wall. This failure begins on Day One. Every single piece of data, every secret, and every photo that has ever been transmitted on a computer, phone, or over the internet will be able to be broken.
The day a fully realized quantum computer comes online is the day both RSA and ECC, the only two encryption standards we have in play, can both be busted through like the Kool-Aid Man through a wall.
As hackers, we know this. The term is “harvest now, decrypt later.” With classical systems, decrypting that much stolen data would take quite a long time. For quantum, it happens at the blink of an eye. The secrets will be decrypted and disseminated before you can finish a breath.
Problem 3: The Proof Gap
Cryptographers and NIST are working on Post-Quantum Cryptography (PQC). Hopefully, we will wind up with at least one PQC algorithm that can be categorized as “quantum resilient” and deployed prior to our invisible clock winding down to Q-Day. The estimated arrival of that day keeps getting moved up. Current estimates just jumped from 2030 to 2029.
There is no such thing as “quantum proof.” Any marketing you see using that misnomer is a fallacy. Their ego trumped their honesty. In most cyber discussions, even at the highest levels, the conversation stops at PQC. This leads to a massive gap. We have no data to know if whichever algorithm is selected will actually survive an encounter in the wild with a true quantum computer. The best we can claim is quantum resilience. This is why we need entropy to act as a second lock.
Problem 4: The Figureoutable Floor
Every interaction you have online generates a “random key” that keeps that action secure. That key sits right underneath the cryptography. We require this key to be random enough that it cannot be guessed. Randomness remains an unsolved problem in computer science.
The best we ever did was make something that looks random to a human. We build pseudorandom number algorithms, and computers speak fluent algorithm. Of course it can unravel that thread if it pulls at it. This renders these keys not random, but pseudorandom. If the foundation is able to be figured out, the system is defenseless.
Problem 5: The Endless Observer
Humans are no longer alone in hacking or understanding these patterns. We have AI. AI does not get tired, hungry, or bored. It does not need sleep and it does not quit. It can learn forever into perpetuity. These models are entering training today, consuming every pseudorandom string we generate. How do we stop an endless learning machine?
AI does not get tired, hungry, or bored. It does not need sleep and it does not quit. It can learn forever into perpetuity.
We blind it. We give it something unlearnable. We give it something truly unpredictable. Not “kind of sort of” random, but truly random. This is considered not just entropy, but true entropy.
Problem 6: The Limiting Factor
Why have we not figured this out so far? There is a limiting factor. Humans are that limiting factor. We build tools using our own Earth-bound logic. To solve this, we should be looking outside of our own logic to seed the system with true entropy from the universe itself.
There are cosmic phenomena happening right now, such as quantum vacuum fluctuations, cosmic radiation, and black holes, that we are only now being able to explore. Entropy in most fields has always been seen as system waste. In the quantum era, it is the thing that could save our lives.
Problem 7: The Dual Threat
If AI can learn anything given enough time, output, and context, and quantum can solve the most complex problems in a single moment, what happens when we have AI powered by quantum speed? Global security falls straight off a cliff. Every terrestrial and space system becomes vulnerable at the exact same time.
Problem 8: The Compliance Illusion
No current compliance certification can detect, accurately measure, or validate against entropy. All of the controls organizations have in place and are certified to are effectively null and void if we do not get entropy and the foundation correct. These frameworks assume threats are static. Modern adversaries are not. AI systems analyze cryptographic keys over time, learning structure and exploiting weaknesses. They learn, iterate, guess, adapt, build, model, and duplicate. An organization can remain fully compliant while operating without awareness of exposed entropy in its systems.
Problem 9: The Measurement Crisis And The Hardware Trap
We cannot accurately measure entropy because existing standards, like NIST SP 800-90B, do not assume AI observation. They do not assume an AI is watching, tracking, and pattern matching. The dominant industry response is hardware-based migration. This introduces structural constraints: high capital expenditure and supply chain dependencies. Security that cannot adapt at software speed and scale will not keep pace with AI-driven threats. The answer must be software-based resilience.
Problem 10: A New Field For The Quantum Era
A new architecture is required to hold this wave of technological change. Entropy as Infrastructure for Security and Defense (EISD) is positioned at the intersection of cryptography, cybersecurity, and physics. The field provides the central language and measurement framework these problems require: entropy scoring, unlearnability metrics, and entropy amortization.
Entropy turns out to be both sword and shield. It is a tool for resilience and a potential weapon. Growing this field is how we prevent the nightmare scenario of entropic warfare. Physics, computer science, and cybersecurity are merging in ways that will never be undone.
I ask that anyone who interacts with this material does so free of malice. We have a world to save. We are just getting started.
The Ten Problems Behind The New Field
1. The Invisible Clock. Quantum is not faster. It is different. We are in a race we cannot see.
2. The Retroactive Breach. Every encrypted thing ever transmitted breaks on Day One.
3. The Proof Gap. No algorithm is “quantum proof.” Quantum resilience is the most we can claim.
4. The Figureoutable Floor. Pseudorandom keys are guessable. Randomness is unsolved in computer science.
5. The Endless Observer. AI is the unsleeping pattern recognizer pseudorandomness was never built to defeat.
6. The Limiting Factor. Humans build tools using Earth-bound logic. The universe offers true entropy if we look.
7. The Dual Threat. AI plus quantum collapses every terrestrial and space system at the same time.
8. The Compliance Illusion. No certification can measure entropy. Compliance and security are no longer the same thing.
9. The Measurement Crisis. NIST SP 800-90B does not assume AI observation. Hardware migration is too slow. Software resilience is the answer.
10. The New Field. Entropy as Infrastructure for Security and Defense (EISD) is the architecture this era requires.
About The Author
Samantha Lowrimore is a cybersecurity researcher, ethical hacker, entropy advocate, GRC Lead Auditor, and an approved member of the IEEE SA P1947 Working Group, where she contributes to the development of a Quantum Cybersecurity Framework for the global internet. She is the founder of PostQuantSec.io and the founder of the field of Entropy as Infrastructure for Security and Defense (EISD), a field that explores entropy, unlearnability, and software-defined resilience in post-quantum environments.