Skip to content
Tag

post-quantum

Every article tagged post-quantum, newest first.

12 articles

Research

TLS 1.2 made servers refuse a resumption whose name had changed. TLS 1.3 removed that rule.

We have submitted a position paper to the IAB workshop on post-quantum authentication, and published the whole evidence base behind it: eleven CVE identifiers across eight pieces of software since 2014, reproductions against current OpenSSL, Go and nginx, a fourteen-host measurement of public endpoints, and what conforming would save a deployment that cannot safely resume today. It is a proposal, not a standard, and the page says so at the top.

6 min read
Research

Post-quantum makes session resumption essential. We are now measuring who offers it.

The PQC Observatory now records three things it never did: whether a host issues a TLS session ticket, whether it volunteers one without being asked, and whether it honours its own ticket when the ticket comes back. On the web panel today, 69 of 70 hosts issue a ticket, 40 of 70 send it without being asked for anything, and 61 of 69 resume. The gap between those first two numbers is the reason the measurement had to change.

7 min read
Methodology

A field guide to post-quantum readiness, free and in the open

Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.

3 min read
Methodology

You cannot migrate what you cannot see: build a CBOM with qScan

Every post-quantum migration plan starts with the same step, and almost everyone underestimates it: know exactly what cryptography you have. A cryptographic bill of materials (CBOM) is that inventory in a standard, machine-readable form. Here is how to produce one across your code and your infrastructure in about a minute, with qScan, and what to do with it once you have it.

3 min read
Research

Governments set the post-quantum deadlines. Their own sites are behind.

We added 201 government and public-sector sites to the PQC Observatory and measured them as their own panel. Just under a third negotiate post-quantum key exchange today. The pattern is not the one you would guess: several of the governments writing the migration mandates have not enabled it on their own front doors, while smaller states are already there.

4 min read
Research

The PQC Observatory: measuring post-quantum readiness across the web

Every month we probe a fixed panel of public hosts for hybrid key exchange and certificate posture, then publish the trend. Here is what the observatory measures, how, and why a vendor-neutral series is worth keeping.

2 min read
Methodology

A post-quantum workflow for AI coding agents

AI coding agents are fluent in cryptography and blind to its expiry date. The quantakrypto MCP gives them the missing sense. Here is the workflow we actually use: what to delegate to the agent, and where a human still decides.

3 min read
Conformance

You migrated to post-quantum crypto. Is the implementation actually conformant?

Audits catch exploitable bugs; conformance is a different axis. Here is how to test any ML-KEM / ML-DSA / SLH-DSA implementation against FIPS 203/204/205 in a few minutes, plus a real (since-fixed) FIPS 203 deviation it surfaced in a widely-used library.

5 min read
Research

Mosca's theorem: the equation that decides when to start post-quantum migration

You cannot predict when a quantum computer will break RSA, and Mosca's inequality (X + Y > Z) says you do not need to. Here is the arithmetic that decides whether you should already be migrating.

4 min read
Company

Introducing quantakrypto

We exist for one reason: to get your systems quantum-ready before Q-day. Here's who we are, what the lattice in our mark means, and what you'll find on this blog.

2 min read
Company

Why we built quantakrypto

Quantum computing just hit its transistor moment: real systems, real early uses, and a cryptographic reckoning that's a planning problem today and a break-glass problem in the 2030s. The gap between a finished standard and an unstarted migration is why this firm exists.

3 min read
Research

The clock is already running

Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.

2 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.