Post-quantum cryptography and security
New encryption standards built to survive quantum computers, and the frontier of cybersecurity.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.Updated
- WikiDARPA AI Cyber Challenge (AIxCC)DARPA's two-year competition for AI systems that find and patch software vulnerabilities, won by Team Atlanta in August 2025. Results and significance.Updated
- WikiHQC (Hamming Quasi-Cyclic)HQC is the code-based encryption algorithm NIST picked in 2025 as a backup to ML-KEM. Why it was chosen, its trade-offs and its standards status.Updated
- WikiHybrid post-quantum TLS (X25519MLKEM768)How browsers and servers combine X25519 with ML-KEM to protect web traffic from future quantum decryption, and how far deployment had got by 2026.Updated
- WikiML-DSA (FIPS 204)ML-DSA, formerly CRYSTALS-Dilithium, is NIST's main post-quantum digital signature standard. How it works, its sizes and where it is deployed.Updated
- WikiML-KEM (FIPS 203)ML-KEM, formerly CRYSTALS-Kyber, is NIST's main post-quantum key-establishment standard and the algorithm behind hybrid post-quantum TLS.Updated
- WikiNIST Post-Quantum Cryptography projectNIST's open, multi-year competition that produced the ML-KEM, ML-DSA and SLH-DSA standards, plus HQC, FN-DSA and the work still in progress.Updated
- WikiSignal's post-quantum protocol (PQXDH and SPQR)How Signal added post-quantum protection in two steps, PQXDH in 2023 and the SPQR "Triple Ratchet" in 2025, and how Apple's iMessage PQ3 compares.Updated
- WikiSLH-DSA (FIPS 205)SLH-DSA, formerly SPHINCS+, is NIST's hash-based post-quantum signature standard: a conservative backup to ML-DSA with large signatures.Updated
- AnalysisDoes AI help cyber attackers or defenders more?AI now finds and exploits software flaws. Evidence from DARPA's AIxCC, Google's Big Sleep, Anthropic's Mythos and a reported AI-run espionage campaign.Updated
- AnalysisHow fast must we move to post-quantum cryptography?Q-Day timing, 2029 corporate targets versus 2030-2035 government deadlines, and whether to rush new algorithms: the post-quantum migration debate.Updated
- ExplainerHarvest now, decrypt later: why the quantum threat is already hereHow attackers can store encrypted data today to decrypt with a future quantum computer, which data is at risk, and why it drives migration deadlines.Updated
- ExplainerHow post-quantum cryptography worksLattices, hashes and codes: the math behind post-quantum algorithms, how key encapsulation and signatures work, and the trade-offs in size and safety.Updated
- ExplainerHow quantum computers break encryptionWhy Shor's algorithm threatens RSA and elliptic-curve cryptography, why AES survives, and how fast attack estimates fell in 2025-2026.Updated