Sign in

Bas Westerbaan

@bwesterb.bsky.social
42 followers 5 following 9 posts

post quantum @cloudflare

PostsRepliesMedia
Bas Westerbaan @bwesterb.bsky.social · 10/09/2026
I still haven't found the perfect GIF to express my feelings shoving ML-DSA-44 into DNSSEC. blog.cloudflare.com/post-quantum...
blog.cloudflare.com
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.
041
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 12/08/2026
Don't like what I'm posting? Become my boss and tell me to cut it out! Or just become my boss and be cool, that's also possible and encouraged. www.linkedin.com/jobs/view/44530271…
linkedin.com
Google hiring Engineering Director, Product Security, Core in Zurich, Zurich, Switzerland | LinkedIn
Posted 1:35:05 AM. Note: By applying to this position you will have an opportunity to share your preferred working…See this and similar jobs on LinkedIn.
174
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 10/08/2026
Woohoo, the TLS key exchange algorithm Chrome, Firefox, and friends have been using for the last two years is now an actual standard! datatracker.ietf.org/doc/html/rfc10…
datatracker.ietf.org
RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3
This document defines three hybrid key agreement mechanisms for TLS 1.3 -- X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 -- that combine the post-quantum ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) with an ECDHE (Ephemeral Elliptic Curve Diffie-Hellman) exchange.
14017
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 10/08/2026
New blog post about cryptanalysis and AI bughunters.google.com/blog/more-cry…
22811
Bas Westerbaan @bwesterb.bsky.social · 29/07/2026
We support post-quantum authentication now to your origin. First place we deploy PQ certs: many more to come. blog.cloudflare.com/post-quantum...
blog.cloudflare.com
Post-quantum authentication to origins is now supported
Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providi...
084
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 28/07/2026
On the HAWK break: setting aside the LLM part of the narrative, this fits very well into my priors. I only had started looking at HAWK fairly recently and have not devoted much time to it, but when then I was not really convinced by the security argument. My main concern is that HAWK's public […]
infosec.exchange
Original post on infosec.exchange
0112
Reposted by Bas Westerbaan
Filippo Valsorda @filippo.abyssdomain.expert · 29/07/2026
I'm seeing folks draw the wrong conclusion (in good faith or not) from the HAWK attack. HAWK is a scheme that 1. cryptographers were suspicious of and 2. was still in the assessment process. A break is GOOD. It means the process is useful, and it INCREASES confidence in the selected algorithms.
111620
Bas Westerbaan @bwesterb.bsky.social · 28/07/2026
I updated PQSpy, a @firefox.com extension that shows you in a little icon whether the page you're visiting is post-quantum encrypted ⚛️, or not ❌, or partially in a kinda pie chart. Click the icon to get more the deets as shown in the screenshot. Get it here addons.mozilla.org/en-GB/firefo...
010
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 23/07/2026
You can now download the spec for ML-KEM over a connection secured with ML-KEM. An honor it shares with I guess SP 800 38D, and, if you change ClientHello, P256. And also RFC 7748, if you want to extend it further. csrc.nist.gov/pubs/fips/203/final
NIST's page for ML-KEM, showing that Chrome used X25519MLKEM768 to access the website
061
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 23/07/2026
How to interpret a base64 encoded ML-DSA signature: first kilobyte: the exhausting part Second to last bytes: AAAAAAAAAAAA the eternal scream after being done with the exhausting part The last few bytes: the death rattle
161
Bas Westerbaan @bwesterb.bsky.social · 09/07/2026
Every year we write about the exciting developments in post-quantum signatures. Last year didn't disappoint. But it's too late. As ekr wrote in 2024 "You go to war with the algorithms you have, not the ones you wish you had." ML-DSA will have to do for now. blog.cloudflare.com/ml-dsa-will-...
blog.cloudflare.com
Why we cannot wait for better post-quantum signature algorithms
NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and sh...
0116
Reposted by Bas Westerbaan
Software Engineering Daily @softwaredaily.bsky.social · 16/06/2026
Bas Westerbaan is a cryptography engineer at @cloudflare.social. He joins @kball.llc to discuss preparing for Q Day, post quantum cryptography, quantum threats, migration timelines, and readiness. @bwesterb.bsky.social softwareengineeringdaily.com/2026/06/16/p...
softwareengineeringdaily.com
Preparing for Q-Day - Software Engineering Daily
Most of the cryptography securing the internet today rests on mathematical problems that classical computers cannot solve in any reasonable timeframe. That assumption is now being tested. Recent advan...
011
Reposted by Bas Westerbaan
Sam Jaques @sejaques.bsky.social · 09/04/2026
Overdue quantum landscape update: sam-jaques.appspot.com/quantum_land... A 2d chart can only say so much. tl;dr new results are still overhyped, but definitely worth taking seriously. This chart is based on surface codes and a big question now is whether new codes can be practical (=>useless chart)
A cluttered and complicated chart relating qubit counts to qubit error rates, comparing today's devices to cryptographic attacks.
15122
Reposted by Bas Westerbaan
Filippo Valsorda @filippo.abyssdomain.expert · 20/04/2026
There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
312135
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 07/04/2026
I post links about the quantum thing. That is my life now, I guess. Anyways, here is Cloudflare following suit and setting 2029 as target date, and Scott slowing losing his mind over people being dumb on the internet. blog.cloudflare.com/post-quantum-ro… […]
infosec.exchange
Original post on infosec.exchange
075
Bas Westerbaan @bwesterb.bsky.social · 07/04/2026
No one likes it if deadlines are pulled forward. I thought I had a decade at least for PQC. But when things change, you gotta adapt. blog.cloudflare.com/post-quantum...
blog.cloudflare.com
Cloudflare targets 2029 for full post-quantum security
Recent advances in quantum hardware and software have accelerated the timeline on which quantum attack might happen. Cloudflare is responding by moving our target for full post-quantum security to 202...
011
Reposted by Bas Westerbaan
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 02/04/2026
A very nice explainer why "if you're so worried about quantum computers, why haven't they factored 21 yet?" isn't a very convincing argument. Look at the labels of the graph, and how extremely close the various lines are for factoring 21 and 2048 bit numbers. Polynomial scaling remains […]
infosec.exchange
Original post on infosec.exchange
02417
Reposted by Bas Westerbaan
Deirdre Connolly¹ ² @durumcrustulum.com · 02/04/2026
from @bwesterb.bsky.social: bas.westerbaan.name/notes/2026/0...
bas.westerbaan.name
Factoring is not a good benchmark to track Q-day
Homepage of dr. Bas Westerbaan, principal research engineer at Cloudflare, working on making the Internet post-quantum secure
084
Reposted by Bas Westerbaan
Filippo Valsorda @filippo.abyssdomain.expert · 26/03/2026
Last year, I thought we still had time to design PQ auth systems. Now, based on the pace of progress and on statements like Google's, I believe 1. we need to finish rolling out PQ kex yesterday 2. we need to start rolling out PQ auth now 3. it's too late to ship any new non-PQ design or system
blog.google
Quantum frontiers may be closer than they appear
An overview of how Google is accelerating its timeline for post-quantum cryptography migration.
08328
Reposted by Bas Westerbaan
Craig Gidney @craiggidney.bsky.social · 28/03/2026
While I was attending APS March Meeting, I appeared in the 632nm podcast. The recording is available on youtube: www.youtube.com/watch?v=lnHg... Never been on a podcast before, and no doubt that shows, but it was fun.
youtube.com
How To Make Quantum Algorithms Cheaper | Craig Gidney on Magic-State Factories, Resource Estimates
YouTube video by 632nm
0152
Reposted by Bas Westerbaan
Craig Gidney @craiggidney.bsky.social · 25/03/2026
I would bet against Q day by 2030, but I wouldn't bet against it at 10:1 odds. ~10% risk is unacceptably high here, so I'm very in favor of transitioning to quantum-safe cryptography by 2029: blog.google/innovation-a... Yes this means I 90% expect to be made fun of in 2030. Oh well.
blog.google
Quantum frontiers may be closer than they appear
An overview of how Google is accelerating its timeline for post-quantum cryptography migration.
1227
Reposted by Bas Westerbaan
Filippo Valsorda @filippo.abyssdomain.expert · 19/09/2025
"Lack of scalability is enough for us to disqualify QKD outright: if a technology can’t bring security to the whole Internet, we’re not going to spend much time on it." Quantum Key Distribution (as opposed to post-quantum cryptography) has many problems, but this succinctly captures the core issue.
blog.cloudflare.com
You don’t need quantum hardware for post-quantum security
Post-quantum cryptography protects against quantum threats using today’s hardware. Quantum tech like QKD may sound appealing, but it isn’t necessary or sufficient to secure organizations.
2304