BSI advises against new use of Classic McEliece
Germany’s cybersecurity agency says the code-based post-quantum candidate should not be chosen for new systems after recent cryptanalysis.
By nonceGermany’s cybersecurity agency says the code-based post-quantum candidate should not be chosen for new systems after recent cryptanalysis.
By nonceThe post-quantum zero-knowledge draft already ships in Google Wallet and India’s UIDAI, with multiple independent implementations backing group change control.
By ttlAn open test suite targets ACID guarantees for hash-based signature state as NIST revises SP 800-208 to allow private key export.
By tarpitMarkku-Juhani O. Saarinen solved a public challenge instance in roughly one hour on 24 GH200 GPUs, with fresh HQC security estimates expected from the same work.
By nonceNGCC's first round of post-quantum submissions is collapsing under human and machine cryptanalysis, and the fastest breaks came from an AI running on its own.
By staffThe agency will specify a single KAT-matchable signing procedure and keep more aggressive Falcon optimizations for later special publications.
By tarpitAn AI-assisted lattice break and quasipolynomial claims against Classic McEliece reopening the fight over whether standardized post-quantum choices outran the cryptanalysis.
By tarpitTLS chairs and the Security AD decline to hear a complaint alleging a flawed rough-consensus call, citing violations of IETF conduct rules.
By ttlML-KEM, ML-DSA, ChaCha20-Poly1305, and the X-Wing hybrid KEM will become available through the browser Web Cryptography API once the change lands.
By ampersandDaniel Borkmann's v2 patches give operators a BPF-scoped trust root for signed program loads and teach bpftool post-quantum signatures.
By oopsBorkmann's bpf-next series adds a BPF-scoped trust anchor for signed program loads and proves the path works with post-quantum keys.
By oopsPreliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.
By tarpitIn a four-part Last Call filing the last-call moderators appear to have blocked, Bernstein compiled 75 sourced objections, a Kyber co-designer's own warning against solo use, and a five-orders-of-magnitude cost gap. The IESG should not publish draft-ietf-tls-mlkem.
By staffIETF makes hybrid ML-KEM key agreement a Proposed Standard just as an AI-found attack kills HAWK and pure-ML-KEM last call draws public process and security objections.
By nonceAn AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.
By nonceAn IETF-wide last call asks the steering group to publish pure ML-KEM key agreement for TLS 1.3 as an RFC, the latest stage of a months-long fight over a rough-consensus call the chairs will not show their math on. A solo post-quantum handshake fails completely the day ML-KEM does, hybrids do not, and the code points already exist. The IESG should reject it. Comments close 13 August.
By staffThe SSHM chairs met an unanswered objection to solo post-quantum signatures with moderation threats instead of discussion. D. J. Bernstein's RFC 2026 complaint reads IETF's own rules back to them: address objections and measure consensus, do not gavel them away. The call for adoption closes 17 August.
By staffAnthropic says its Claude Mythos Preview model found the key-recovery attack largely on its own, in about 60 hours for roughly $100,000 in compute. Steve Weis posted it to pqc-forum, Daniel Apon confirmed the math independently, and the HAWK team helped verify it. HAWK is a NIST candidate, not deployed, so no software has to change.
By nonceA three-week adoption call pits NIST and FIPS-driven demand for standalone ML-DSA against warnings that new PQ code will ship with exploitable bugs.
By ttlAs the SSHM working group runs a call for adoption ending 17 August, the record makes a strong case against blessing solo ML-DSA for host and user authentication when a cheap ECC hedge removes an entire class of failure.
By staffA new draft pairs ML-DSA with elliptic-curve operations for smaller hybrid signatures, drawing scrutiny over strong unforgeability, code size, and hedging.
By ttlA challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.
By tarpitBernstein objects to multiple combiners as needless complexity; MLS implementers plan immediate use of the concrete hybrids.
By ttl