-
RSA-896 Was Factored on Spare CyclesFeatured
The largest RSA key ever publicly broken was broken on idle GPUs between other jobs: ten days, a peak of 2,048 accelerators, about 30 GPU-years, and no hardware bought or rented. The sieve got no faster; what got cheaper is the labor of porting it, and that scarcity was a security control nobody wrote down. Two days later NIST moves every FIPS 140-2 certificate to the Historical list. Defenders work from a published calendar and attackers work from capacity, and a key does not know it has been deprecated.
-
At Least 64.5% of Measured Post-Quantum Adoption Belongs to a CDN
At least 64.5% of the post-quantum results in our European cohort belong to a CDN edge rather than to the organization measured. The figure rose from 42.4% to 55.7% to 64.5% as detection improved, and nothing in the method can push it down. Finance sits at 85.9%, government at 55.0%, and the vendors that were missed longest are the ones an edge metric built on the largest vendor's own telemetry would never see.
-
The Dihedral Coset Claim Has Been Refuted
Gupte, Ragavan and Zhandry prove in ePrint 2026/1693 that the claimed dihedral coset algorithm cannot recover the secret it targets. The result closes the approach rather than correcting its analysis, and it ships with a Lean 4 formalization. The operational conclusion from the original assessment is unchanged: inventory first, then the ability to swap algorithms at reasonable cost.
-
What the Dihedral Coset Claim Means for Lattice Standards
A preliminary ePrint draft claims a polynomial-time quantum algorithm for the Dihedral Coset Problem, which published reductions connect to the lattice assumptions behind ML-KEM and ML-DSA. The proof is unverified and the paper attacks no concrete parameter set. The operational question is answerable today: which assets depend on a lattice assumption as their only post-quantum mechanism.
-
What the HAWK Withdrawal Means for PQC Migration
An AI-found attack ended a third-round NIST signature candidate in a day. Migration planning holds up when you can swap an algorithm quickly, and that starts with knowing which ones run where.
-
ISO Standardized Three Post-Quantum Algorithms
A press release called Classic McEliece the first post-quantum algorithm to reach ISO standardization. The same June 2026 amendment to ISO/IEC 18033-2 standardized three key encapsulation mechanisms, ML-KEM, FrodoKEM, and Classic McEliece, so McEliece is the first code-based algorithm ISO has standardized, not the first post-quantum one. NIST and ISO now point to different code-based algorithms, one more field the inventory has to record, while a scan still finds almost no code-based key exchange on the wire.
-
[PQ]probe PQC Vendor Scorecard: Q2 2026
The second quarterly scorecard tracks what moved since February. Networking had the most vendor movement of any category, HSM and key management enters as a new category, and the FIPS 140-3 validation queue turns out to be the binding constraint rather than firmware. Databases and SaaS did not move at all.
-
Your PQC Deadline Doesn't Track the Quantum Timeline
A peer-reviewed Nature critique by physicist Henry Legg reopened the debate over when a quantum computer will break RSA. The hardware timeline changes nothing about your deadline: regulators already fixed the compliance dates, and the harvest-now-decrypt-later window is already open. The only number that responds to work is your origin key exchange, measured per scan against 2030.
-
The Threat Category Question
Forescout reports nearly 90% of SSH servers still lack post-quantum key exchange. The fair practitioner question is what the real threat is. Three threat categories run on three clocks, and only harvest-now-decrypt-later is already running, which is why every deadline puts key exchange first.
-
The US Post-Quantum Deadline Is Now an Executive Order
Executive Order 14412 makes the US civilian post-quantum deadline binding: federal high-value and high-impact systems must adopt PQC for key establishment by the end of 2030 and for digital signatures by 2031. The year between the two dates is the part worth reading closely, because a system can be on pace for one deadline and behind on the other at the same moment.
-
Certified Is Not Deployed: France's 2027 PQC Gate
ANSSI stops certifying security products without PQC in 2027. Certification tests the product. It does not show what deployed servers negotiate, and almost none negotiate PQC today.
-
Let's Encrypt's Post-Quantum Plan: Merkle Tree Certificates and the Priority of Key Exchange
Let's Encrypt has committed to Merkle Tree Certificates for post-quantum authentication while identifying hybrid key exchange as the near-term priority for server operators. A review of the two functions, their timelines, and what each implies for measurement.
-
ML-DSA is Final. Stop Signing Classical.
With the final announcement of RFC 9964, formerly draft-ietf-cose-dilithium, ML-DSA serializations for JOSE and COSE just landed. It has raised a question whether leaf certificate in the current scan data presents any insights into classical signatures. Looking at a sample of 100K certificates with a recorded signature algorithm, none yet were ML-DSA or SLH-DSA. RSA signs roughly four out of five of them, with SHA256-RSA alone accounting for 80K, and ECDSA covers most of what remains.
-
The 256-Bit Symmetric Distraction
Filippo Valsorda argued last week that AES-128 holds up against quantum computers. [PQ]probe scan data adds the empirical layer: AES-128-only hosts have deployed hybrid PQC key exchange at roughly 8 times the rate of AES-256-only hosts. They upgraded the cipher and left the key exchange alone. Audit checklists treating AES-256 as a quantum-preparedness criterion check the cipher when the quantum threat is on the key exchange.
-
The Hybrid Signature Split
Filippo Valsorda has reversed his position on hybrid signatures: pure ML-DSA-44 is fine for sigs, hybrid stays for KEX, non-PQ KEX is a potential active compromise. The shift puts BSI's hybrid mandate and the new Geomys/OpenSSH posture on a collision course. Scanners will need to report against both.
-
X25519MLKEM768 and X-Wing: Two Hybrids, Two Constructions
Both combine X25519 and ML-KEM-768 with identical wire sizes. The combiners differ. Vendor documentation routinely treats them as synonyms. Treating them that way in a migration plan is a defect.
-
Handshake Bytes on the Wire: A PQC Size Reference
Classical TLS 1.3 is 4 to 6 KB. Hybrid key exchange plus ML-DSA certificates is 15 to 20 KB. That gap crosses IW10, QUIC 3x amplification, and DNSSEC boundaries. Reference tables plus a calculator for your specific stack.
-
Reading Microsoft’s Cryptographic Posture Framework as a Network Team
Microsoft Security published a Cryptographic Posture Management framework that organizes PQC work across code, network, runtime, and storage. The network-domain starter steps give you inventory of where encrypted sessions live. A companion layer answers what those sessions are negotiating, and that pairing is where a migration plan comes together.
-
What Sectigo’s Private PQC Covers in Your Threat Model, and What Still Needs ML-KEM
Sectigo announced Private PQC on April 14, issuing ML-DSA-signed certificates from a private CA. ML-DSA defends signature authentication. Harvest-now-decrypt-later is addressed by ML-KEM in the handshake. Both belong on the migration plan; knowing which layer each covers keeps the scoping honest.
-
Quantum Threat: Germany Funds the Hardware That Breaks ECC First
Germany’s Quantum Computing Competition funds neutral-atom consortia targeting 4,000 qubits by 2030. The Oratomic/Caltech estimates put ECC-256 at risk from approximately 26,000 neutral-atom qubits. One scaling step apart.
-
The Verification Facade in Post-Quantum Cryptography
A new paper finds structural gaps in the formal verification behind libcrux, the ML-KEM library used by Signal, Google, Firefox, and the Linux Foundation. The proofs are real. They cover less than procurement language suggests.
-
Quantum Threat: ECC-256 Falls Before RSA-2048
Two papers from Oratomic/Caltech and Google Quantum AI confirm ECC-256 breaks one to two orders of magnitude faster than RSA-2048. The most modern cryptographic deployments are the most exposed.
-
Quantum Threat: Google’s 2029 PQC Deadline Confirms What Deployment Teams Already Know
Google committed to completing PQC migration by 2029, well ahead of regulatory deadlines. Their acceleration matches what we see in deployment: the tooling works, hybrid PQC is a config change on most cloud infrastructure, and the real bottleneck is inventory, not research.
-
China Is Building a Parallel PQC Track. The Single-Standard Assumption Is Over.
China will finalize independent PQC standards by 2029 on structureless lattice math, diverging from NIST. Organizations with cross-jurisdictional exposure now face parallel migration tracks.
-
Quantum Threat: Aer Lingus on 3DES in 2026 Ain’t Gonna Fly
Aer Lingus gets a B from SSL Labs and an F from pqprobe. Both grades are correct. They answer different questions, and the gap between them is where the real risk lives.
-
Quantum Threat: Party Like It’s BB84 Tonight
A researcher confident enough to put a hard date on Shor’s algorithm doesn’t know the protocol it breaks. The gap between theoretical physics and operational security is where risk lives.
-
Stop Calling Quantum Computing Magic
WSJ calls quantum computing “seemingly magical science.” CSIRO calls entanglement “the magic of quantum computers.” This framing gives CISOs permission to defer migration. That’s the damage.
-
Quantum Threat: The Week Physics Crossed Over to Infrastructure
IBM published a quantum-centric supercomputing blueprint. Qutwo signed enterprise orchestration deals. These are not physics experiments. They are procurement decisions.
-
Hybrid or Pure PQC? You’re Not Even at Hybrid Yet
More than 90% of origin servers negotiate zero post-quantum key exchange. The IETF is debating the 2035 destination. Most organizations haven’t met the 2027 starting line.
-
Germany's PQC Deadline Is Now. We Scanned Who's Ready.
COM(2026) 13 adds the first explicit PQC requirement to EU law. BSI wrote the guidance and co-chaired the EU roadmap. We scanned bsi.bund.de. No post-quantum key exchange.
-
Cloudflare Can’t Fix the False Floor
Three days after we argued that edge PQC numbers create a false floor, Cloudflare launched origin-server tracking on Radar. The gap narrowed from 60% vs 1% to 60% vs some-fraction-of-10%. Still enormous. Still the most important number in PQC.
-
Quantum Threat: The JVG Algorithm Does Not Break RSA
A group of engineering professors and PQC hardware executives have announced their "apocalypse" algorithm breaks RSA-2048 in 11 hours. However, it failed initial scrutiny, which reveals how commercial incentives threaten to distort PQC migration.
-
Google Vaporized The Cert You Were Just About To Migrate To
Google won’t add post-quantum X.509 certificates to the Chrome Root Store. Instead, Chrome is building Merkle Tree Certificates — and the migration target just moved for everyone.
-
The Edge Is a False Floor: What PQC Adoption Numbers Actually Measure
Cloudflare reports 52% PQC adoption. Behind the edge, 1% of origin servers are post-quantum. The gap between those numbers is where the risk lives.
-
[PQ]probe PQC Vendor Scorecard: Q1 2026
Which of your vendors are actually shipping post-quantum cryptography? We mapped 28+ vendors across seven categories and checked announcements against TLS handshakes.
-
Quantum Threat: The Qubit Question Is the Wrong Question
Australia’s Signals Directorate published a quantum primer with no qubit estimates. That tells you everything about what actually matters for PQC migration.
-
The Shop Manual Problem: BSI, Pirsig, and the Practice of PQC Migration
BSI published 70 pages of post-quantum guidance. Four years later, 28 out of 150 companies responded to a survey about what they’d done. The manual was never the problem.
-
The Weak EUDI Link in German PQC-Ready Chips
Germany PQC-hardened the eID chip. Nobody's talking about the quantum-vulnerable middleware between the chip and the EUDI Wallet shipping in 2026.
-
PQ Guide: HAProxy
HAProxy delegates TLS to OpenSSL. If OpenSSL supports ML-KEM, HAProxy can negotiate it. The question is whether yours does.
-
Quantum Threat: BSI Just Set an Expiration Date on Classical Encryption
Germany's BSI now recommends classical asymmetric encryption should no longer be used alone after 2031. For high-sensitivity applications, 2030.
-
Quantum Threat: Five Ceilings—What If Quantum Computing Hits a Wall?
The industry talks about one barrier to cryptographically relevant machines. I think there are five, and they're nested.
-
Quantum Threat: Assessment Needs People Who See Threats
NSA, ASD, and the G7 are setting migration deadlines based on intelligence the open research community doesn't have.
-
Quantum Threat: The Trillion-Dollar Security Race Is Septillion Years Away
Citi says $2-3 trillion at risk. Google says 10 septillion years. Both are right, and that's the problem.
-
The Pot of Gold Mandiant Should Have Released With Their Rainbow Attack Table
Mandiant published 8TB of attack tools and 4 sentences on remediation. We built the defense tool they didn't.
-
Introducing pqprobe: Finding the Quantum Vulnerabilities Everyone Missed
We scanned Cloudflare's "post-quantum" Matrix homeserver. Zero post-quantum cryptography found in the application layer.