Skip to content
Tag

harvest now, decrypt later

Every article tagged harvest now, decrypt later, newest first.

6 articles

Research

Obelisk: the first Nostr client with post-quantum DMs

Nine days ago we published a proposal for giving a Nostr identity post-quantum keys, derived from its seed phrase where it has one. It is now running in a chat client anyone can open. Obelisk sends gift-wrapped direct messages carrying an ML-KEM-1024 payload, against public relays, with no relay changes and no changes required of clients that do not opt in. The four specification drafts are public. So is the bug we shipped and caught, which was in the routing rather than the cryptography.

10 min read
Research

A post-quantum transition for Nostr identities

Every encrypted Nostr message published today is a future plaintext. We are proposing a NIP, jointly with nostr-wot, that lets an identity derive post-quantum keys from its seed phrase where it has a 24-word one - so those words still restore the identity after the transition. Accounts without one, which is most of them, generate an independent key that needs its own backup. It is implemented and running against public relays, not a design document: you can send a post-quantum encrypted message and take it apart layer by layer.

10 min read
News

How much of the web already uses post-quantum TLS

By late 2025, around 43% of human web connections to Cloudflare were already using hybrid post-quantum key agreement, and X25519MLKEM768 is on by default in every major browser. The browser-to-edge hop is largely migrated. The unfinished half is origins, authentication, and your own stack. Here is where the line actually is.

3 min read
Research

Mosca's theorem: the equation that decides when to start post-quantum migration

You cannot predict when a quantum computer will break RSA, and Mosca's inequality (X + Y > Z) says you do not need to. Here is the arithmetic that decides whether you should already be migrating.

4 min read
Research

The clock is already running

Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.

2 min read
Research

Post-quantum migration is a risk-asymmetry problem, not a timeline bet

You do not need to predict when a cryptographically relevant quantum computer arrives. You need to weigh the cost of migrating too early against the cost of migrating too late, and those costs are not symmetric.

2 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.