INFRA Signal 203
Why we cannot wait for better post-quantum signature algorithms
ML-DSA has significant downsides compared to classical algorithms—much larger on-wire sizes and incompatibility with many RSA/ECC techniques—but the threat of harvest-now-decrypt-later attacks makes waiting unviable. Organizations planning their post-quantum migration need to design around ML-DSA's constraints for their first pass.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
NIST is advancing nine post-quantum signature algorithms to the third round of standardization, but these candidates will not be ready in time for the current post-quantum transition.
ML-DSA, the only standardized post-quantum signature scheme available today, produces signatures and public keys that are significantly larger than classical alternatives like Ed25519 or RSA 2048.
Cloudflare already uses ML-KEM encryption for the majority of its traffic and is targeting 2029 to be fully post-quantum secure, including authentication via post-quantum signatures.
THE CLUSTER
↗