I'm writing a near-future sci-fi novel where general quantum computing has been developed and SSL has been replaced with a security protocol based on quantum key distribution (QKD). Tor would still be able to establish circuits based on QKD. What sort of attacks would be effective, given the speed of quantum computing? Could NSA perform statistical attacks fast enough to expose the whole network? Would there be a different class of attacks available to someone with fewer resources than the NSA?
If this is too off-topic or beyond your knowledge-base, where would be the appropriate place to ask this?