Is it possible to defend against this attack in a classical way? Some sort of time limit on decryption? Or an argument that it's impossible?
Is it possible to defend against this attack in a classical way? Some sort of time limit on decryption? Or an argument that it's impossible?
Wireguard, for example, provides the ability to add a pre-shared key for endpoints, which it mixes in during key exchange. Wireguard sessions collected under such a configuration should remain safe when attacked by a future quantum computer, assuming that the shared keys remain secret.
Pre-shared keys are just inconvenient to handle safely.
You can transfer PSKs safely and easily with OpenSSH 9.0 (released 2022-04-08) or later, which uses sntrup761x25519-sha512@openssh.com as the default key exchange method.
The only way you can do any "not after X time" decryption even for honest-ish users is if the decryption involves getting extra key material from some server that erases it or shuts down at some point. But even that doesn't help if someone can break the crypto.
There are a number of things you can do today, more than I listed. I suggest you discuss with an appsec person who is familiar with your threat model.