Loading…
Loading…
Original post-quantum research and measurement, including the protocol work we publish as drafts and proposals.
12 articles
Nine days ago we published a proposal for giving a Nostr identity post-quantum keys, derived from its seed phrase where it has one. It is now running in a chat client anyone can open. Obelisk sends gift-wrapped direct messages carrying an ML-KEM-1024 payload, against public relays, with no relay changes and no changes required of clients that do not opt in. The four specification drafts are public. So is the bug we shipped and caught, which was in the routing rather than the cryptography.
In 2026, thieves emptied thousands of hardware wallets without breaking any of Bitcoin's cryptography. They just guessed the keys. Here is how that is possible, explained plainly, and the one simple thing that saved the people who did it.
Every encrypted Nostr message published today is a future plaintext. We are proposing a NIP, jointly with nostr-wot, that lets an identity derive post-quantum keys from its seed phrase where it has a 24-word one - so those words still restore the identity after the transition. Accounts without one, which is most of them, generate an independent key that needs its own backup. It is implemented and running against public relays, not a design document: you can send a post-quantum encrypted message and take it apart layer by layer.
We added 201 government and public-sector sites to the PQC Observatory and measured them as their own panel. Just under a third negotiate post-quantum key exchange today. The pattern is not the one you would guess: several of the governments writing the migration mandates have not enabled it on their own front doors, while smaller states are already there.
A one-time scan tells you where you stand today. Migration is a moving target, so we now track posture over time: an append-only snapshot per scan, a drift alert when a commit reintroduces quantum-vulnerable crypto, and migration projects that group findings by an identity that survives a line shift.
Every scanner treats RSA on a marketing microsite and RSA on 25-year health records as the same finding. Real risk is a property of the data behind the crypto. We now compute an exposure score per finding, vulnerability times data sensitivity times a Mosca margin, and rank the migration backlog by risk instead of by count.
Every month we probe a fixed panel of public hosts for hybrid key exchange and certificate posture, then publish the trend. Here is what the observatory measures, how, and why a vendor-neutral series is worth keeping.
You cannot predict when a quantum computer will break RSA, and Mosca's inequality (X + Y > Z) says you do not need to. Here is the arithmetic that decides whether you should already be migrating.
We built a scanner to inventory quantum-vulnerable cryptography and ran it across 43 popular open-source projects. It flagged the RSA and elliptic-curve keys we expected and, more often than we'd like, TLS certificate verification switched off in production.
Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.
You do not need to predict when a cryptographically relevant quantum computer arrives. You need to weigh the cost of migrating too early against the cost of migrating too late, and those costs are not symmetric.
Hybrid KEMs and hybrid signatures are not the same problem. For key exchange, the industry has largely converged on X25519MLKEM768, and there are good reasons to follow rather than invent.
Book a discovery call and get an indicative scope and pricing for your organisation.