ELSEIF
Your brief EB
472 stories from 182 feeds 1114 clusters Refreshed 25 minutes ago next pull 20:40

INFRA Signal 480

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

Cloudflare's 1.1.1.1 public resolver now validates DNSSEC signatures using NIST's post-quantum ML-DSA-44 algorithm, exposing operational challenges from 2,420-byte signatures that exceed common DNS-over-UDP limits.

WHY IT MATTERS

This is early large-scale testing of post-quantum signatures in DNS infrastructure, where signature sizes 38 times larger than ECDSA P-256 threaten to break assumptions in network software. The migration requires coordination across authoritative servers, registries, registrars, and resolvers, and zones must maintain conventional signatures for years, creating downgrade risks. Only one feed carried this, and it is a first-party announcement from Cloudflare about its own product.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

ML-DSA-44 signatures are 2,420 bytes, nearly 38 times larger than ECDSA P-256's 64-byte signatures, exceeding DNS-over-UDP limits before accounting for other record data.

02

Zones must publish both post-quantum and conventional signatures during migration, creating a potential downgrade path if validation does not prevent fallback to older algorithms.

03

Cloudflare targets full post-quantum security by 2029, with post-quantum TLS already enabled for all customers since 2022 but DNSSEC signatures previously untested at scale.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Cloudflare 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it Open ↗