post-quantum
Every article tagged post-quantum, newest first.
12 articles
TLS 1.2 made servers refuse a resumption whose name had changed. TLS 1.3 removed that rule.
We have submitted a position paper to the IAB workshop on post-quantum authentication, and published the whole evidence base behind it: eleven CVE identifiers across eight pieces of software since 2014, reproductions against current OpenSSL, Go and nginx, a fourteen-host measurement of public endpoints, and what conforming would save a deployment that cannot safely resume today. It is a proposal, not a standard, and the page says so at the top.
Post-quantum makes session resumption essential. We are now measuring who offers it.
The PQC Observatory now records three things it never did: whether a host issues a TLS session ticket, whether it volunteers one without being asked, and whether it honours its own ticket when the ticket comes back. On the web panel today, 69 of 70 hosts issue a ticket, 40 of 70 send it without being asked for anything, and 61 of 69 resume. The gap between those first two numbers is the reason the measurement had to change.
A field guide to post-quantum readiness, free and in the open
Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.
You cannot migrate what you cannot see: build a CBOM with qScan
Every post-quantum migration plan starts with the same step, and almost everyone underestimates it: know exactly what cryptography you have. A cryptographic bill of materials (CBOM) is that inventory in a standard, machine-readable form. Here is how to produce one across your code and your infrastructure in about a minute, with qScan, and what to do with it once you have it.
Governments set the post-quantum deadlines. Their own sites are behind.
We added 201 government and public-sector sites to the PQC Observatory and measured them as their own panel. Just under a third negotiate post-quantum key exchange today. The pattern is not the one you would guess: several of the governments writing the migration mandates have not enabled it on their own front doors, while smaller states are already there.
The PQC Observatory: measuring post-quantum readiness across the web
Every month we probe a fixed panel of public hosts for hybrid key exchange and certificate posture, then publish the trend. Here is what the observatory measures, how, and why a vendor-neutral series is worth keeping.
A post-quantum workflow for AI coding agents
AI coding agents are fluent in cryptography and blind to its expiry date. The quantakrypto MCP gives them the missing sense. Here is the workflow we actually use: what to delegate to the agent, and where a human still decides.
You migrated to post-quantum crypto. Is the implementation actually conformant?
Audits catch exploitable bugs; conformance is a different axis. Here is how to test any ML-KEM / ML-DSA / SLH-DSA implementation against FIPS 203/204/205 in a few minutes, plus a real (since-fixed) FIPS 203 deviation it surfaced in a widely-used library.
Mosca's theorem: the equation that decides when to start post-quantum migration
You cannot predict when a quantum computer will break RSA, and Mosca's inequality (X + Y > Z) says you do not need to. Here is the arithmetic that decides whether you should already be migrating.
Introducing quantakrypto
We exist for one reason: to get your systems quantum-ready before Q-day. Here's who we are, what the lattice in our mark means, and what you'll find on this blog.
Why we built quantakrypto
Quantum computing just hit its transistor moment: real systems, real early uses, and a cryptographic reckoning that's a planning problem today and a break-glass problem in the 2030s. The gap between a finished standard and an unstarted migration is why this firm exists.
The clock is already running
Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.