[PQ]files

Research, analysis, and tools for the post-quantum transition.

EN | DE
Featured

What the Dihedral Coset Claim Means for Lattice Standards

A preliminary ePrint draft claims a polynomial-time quantum algorithm for the Dihedral Coset Problem, which published reductions connect to the lattice assumptions behind ML-KEM and ML-DSA. The proof is unverified and the paper attacks no concrete parameter set. The operational question is answerable today: which assets depend on a lattice assumption as their only post-quantum mechanism.

Read more →

ISO Standardized Three Post-Quantum Algorithms

A press release called Classic McEliece the first post-quantum algorithm to reach ISO standardization. The same June 2026 amendment to ISO/IEC 18033-2 standardized three key encapsulation mechanisms, ML-KEM, FrodoKEM, and Classic McEliece, so McEliece is the first code-based algorithm ISO has standardized, not the first post-quantum one. NIST and ISO now point to different code-based algorithms, one more field the inventory has to record, while a scan still finds almost no code-based key exchange on the wire.

Read more →
Featured

[PQ]probe PQC Vendor Scorecard: Q2 2026

The second quarterly scorecard tracks what moved since February. Networking had the most vendor movement of any category, HSM and key management enters as a new category, and the FIPS 140-3 validation queue turns out to be the binding constraint rather than firmware. Databases and SaaS did not move at all.

Read more →

Your PQC Deadline Doesn't Track the Quantum Timeline

A peer-reviewed Nature critique by physicist Henry Legg reopened the debate over when a quantum computer will break RSA. The hardware timeline changes nothing about your deadline: regulators already fixed the compliance dates, and the harvest-now-decrypt-later window is already open. The only number that responds to work is your origin key exchange, measured per scan against 2030.

Read more →

The Threat Category Question

Forescout reports nearly 90% of SSH servers still lack post-quantum key exchange. The fair practitioner question is what the real threat is. Three threat categories run on three clocks, and only harvest-now-decrypt-later is already running, which is why every deadline puts key exchange first.

Read more →

The US Post-Quantum Deadline Is Now an Executive Order

Executive Order 14412 makes the US civilian post-quantum deadline binding: federal high-value and high-impact systems must adopt PQC for key establishment by the end of 2030 and for digital signatures by 2031. The year between the two dates is the part worth reading closely, because a system can be on pace for one deadline and behind on the other at the same moment.

Read more →

ML-DSA is Final. Stop Signing Classical.

With the final announcement of RFC 9964, formerly draft-ietf-cose-dilithium, ML-DSA serializations for JOSE and COSE just landed. It has raised a question whether leaf certificate in the current scan data presents any insights into classical signatures. Looking at a sample of 100K certificates with a recorded signature algorithm, none yet were ML-DSA or SLH-DSA. RSA signs roughly four out of five of them, with SHA256-RSA alone accounting for 80K, and ECDSA covers most of what remains.

Read more →

The 256-Bit Symmetric Distraction

Filippo Valsorda argued last week that AES-128 holds up against quantum computers. [PQ]probe scan data adds the empirical layer: AES-128-only hosts have deployed hybrid PQC key exchange at roughly 8 times the rate of AES-256-only hosts. They upgraded the cipher and left the key exchange alone. Audit checklists treating AES-256 as a quantum-preparedness criterion check the cipher when the quantum threat is on the key exchange.

Read more →

The Hybrid Signature Split

Filippo Valsorda has reversed his position on hybrid signatures: pure ML-DSA-44 is fine for sigs, hybrid stays for KEX, non-PQ KEX is a potential active compromise. The shift puts BSI's hybrid mandate and the new Geomys/OpenSSH posture on a collision course. Scanners will need to report against both.

Read more →

Reading Microsoft’s Cryptographic Posture Framework as a Network Team

Microsoft Security published a Cryptographic Posture Management framework that organizes PQC work across code, network, runtime, and storage. The network-domain starter steps give you inventory of where encrypted sessions live. A companion layer answers what those sessions are negotiating, and that pairing is where a migration plan comes together.

Read more →
Featured

Stop Calling Quantum Computing Magic

WSJ calls quantum computing “seemingly magical science.” CSIRO calls entanglement “the magic of quantum computers.” This framing gives CISOs permission to defer migration. That’s the damage.

Read more →

Cloudflare Can’t Fix the False Floor

Three days after we argued that edge PQC numbers create a false floor, Cloudflare launched origin-server tracking on Radar. The gap narrowed from 60% vs 1% to 60% vs some-fraction-of-10%. Still enormous. Still the most important number in PQC.

Read more →

Quantum Threat: The JVG Algorithm Does Not Break RSA

A group of engineering professors and PQC hardware executives have announced their "apocalypse" algorithm breaks RSA-2048 in 11 hours. However, it failed initial scrutiny, which reveals how commercial incentives threaten to distort PQC migration.

Read more →

PQ Guide: HAProxy

HAProxy delegates TLS to OpenSSL. If OpenSSL supports ML-KEM, HAProxy can negotiate it. The question is whether yours does.

Read more →