Research
Original post-quantum research and measurement, including the protocol work we publish as drafts and proposals.
14 articles
TLS 1.2 made servers refuse a resumption whose name had changed. TLS 1.3 removed that rule.
We have submitted a position paper to the IAB workshop on post-quantum authentication, and published the whole evidence base behind it: eleven CVE identifiers across eight pieces of software since 2014, reproductions against current OpenSSL, Go and nginx, a fourteen-host measurement of public endpoints, and what conforming would save a deployment that cannot safely resume today. It is a proposal, not a standard, and the page says so at the top.
Post-quantum makes session resumption essential. We are now measuring who offers it.
The PQC Observatory now records three things it never did: whether a host issues a TLS session ticket, whether it volunteers one without being asked, and whether it honours its own ticket when the ticket comes back. On the web panel today, 69 of 70 hosts issue a ticket, 40 of 70 send it without being asked for anything, and 61 of 69 resume. The gap between those first two numbers is the reason the measurement had to change.
Obelisk: the first Nostr client with post-quantum DMs
Nine days ago we published a proposal for giving a Nostr identity post-quantum keys, derived from its seed phrase where it has one. It is now running in a chat client anyone can open. Obelisk sends gift-wrapped direct messages carrying an ML-KEM-1024 payload, against public relays, with no relay changes and no changes required of clients that do not opt in. The four specification drafts are public. So is the bug we shipped and caught, which was in the routing rather than the cryptography.
Bitcoin self-custody: make your own randomness
In 2026, thieves emptied thousands of hardware wallets without breaking any of Bitcoin's cryptography. They just guessed the keys. Here is how that is possible, explained plainly, and the one simple thing that saved the people who did it.
A post-quantum transition for Nostr identities
Every encrypted Nostr message published today is a future plaintext. We are proposing a NIP, jointly with nostr-wot, that lets an identity derive post-quantum keys from its seed phrase where it has a 24-word one - so those words still restore the identity after the transition. Accounts without one, which is most of them, generate an independent key that needs its own backup. It is implemented and running against public relays, not a design document: you can send a post-quantum encrypted message and take it apart layer by layer.
Governments set the post-quantum deadlines. Their own sites are behind.
We added 201 government and public-sector sites to the PQC Observatory and measured them as their own panel. Just under a third negotiate post-quantum key exchange today. The pattern is not the one you would guess: several of the governments writing the migration mandates have not enabled it on their own front doors, while smaller states are already there.
From a snapshot to a signal: continuous post-quantum posture
A one-time scan tells you where you stand today. Migration is a moving target, so we now track posture over time: an append-only snapshot per scan, a drift alert when a commit reintroduces quantum-vulnerable crypto, and migration projects that group findings by an identity that survives a line shift.
Not all RSA is equal: quantifying harvest-now-decrypt-later exposure
Every scanner treats RSA on a marketing microsite and RSA on 25-year health records as the same finding. Real risk is a property of the data behind the crypto. We now compute an exposure score per finding, vulnerability times data sensitivity times a Mosca margin, and rank the migration backlog by risk instead of by count.
The PQC Observatory: measuring post-quantum readiness across the web
Every month we probe a fixed panel of public hosts for hybrid key exchange and certificate posture, then publish the trend. Here is what the observatory measures, how, and why a vendor-neutral series is worth keeping.
Mosca's theorem: the equation that decides when to start post-quantum migration
You cannot predict when a quantum computer will break RSA, and Mosca's inequality (X + Y > Z) says you do not need to. Here is the arithmetic that decides whether you should already be migrating.
We scanned 43 open-source projects for quantum risk. The bigger problem was classical.
We built a scanner to inventory quantum-vulnerable cryptography and ran it across 43 popular open-source projects. It flagged the RSA and elliptic-curve keys we expected and, more often than we'd like, TLS certificate verification switched off in production.
The clock is already running
Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.
Post-quantum migration is a risk-asymmetry problem, not a timeline bet
You do not need to predict when a cryptographically relevant quantum computer arrives. You need to weigh the cost of migrating too early against the cost of migrating too late, and those costs are not symmetric.
X-Wing and the TLS group: choosing a hybrid KEM combiner
Hybrid KEMs and hybrid signatures are not the same problem. For key exchange, the industry has largely converged on X25519MLKEM768, and there are good reasons to follow rather than invent.
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.