INFRA Signal 480
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
Cloudflare's 1.1.1.1 public resolver now validates DNSSEC signatures using NIST's post-quantum ML-DSA-44 algorithm, exposing operational challenges from 2,420-byte signatures that exceed common DNS-over-UDP limits.
This is early large-scale testing of post-quantum signatures in DNS infrastructure, where signature sizes 38 times larger than ECDSA P-256 threaten to break assumptions in network software. The migration requires coordination across authoritative servers, registries, registrars, and resolvers, and zones must maintain conventional signatures for years, creating downgrade risks. Only one feed carried this, and it is a first-party announcement from Cloudflare about its own product.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ML-DSA-44 signatures are 2,420 bytes, nearly 38 times larger than ECDSA P-256's 64-byte signatures, exceeding DNS-over-UDP limits before accounting for other record data.
Zones must publish both post-quantum and conventional signatures during migration, creating a potential downgrade path if validation does not prevent fallback to older algorithms.
Cloudflare targets full post-quantum security by 2029, with post-quantum TLS already enabled for all customers since 2022 but DNSSEC signatures previously untested at scale.
THE CLUSTER
↗