Einstein, 1926 — “God does not play dice”
Quantum machines, classical panic.
A working notebook on quantum mechanics, the machines being built out of it, and the cryptography that has to survive them. For people who want the physics and the engineering in one place — and who have something real to migrate, on a deadline.
Behind this text: a module lattice — the hard problem underneath ML-KEM. Move your cursor and it finds the nearest lattice point. In two dimensions that takes microseconds. In 256, nobody knows how to do it, and that assumption is what your traffic will rest on.
Latest
All 47 posts →Your certificate chain is about to get heavy
An ML-DSA signature is not a drop-in for an ECDSA one — it is roughly an order of magnitude larger, and a chain carries several. Here is what that does to TLS handshake latency on a lossy mobile link, what it does to firmware images with a fixed signature slot, and the three places I have seen it break before anyone had a chance to plan for it.
What a cryptographically relevant quantum computer actually costs
Logical qubits are the wrong unit. Counting physical qubits, error-correction overhead, and wall-clock hours instead.
21 min
Hybrid or bust: reading X25519MLKEM768 on the wire
A packet-by-packet walk through a hybrid key exchange, and why the classical half is still doing real work.
11 min
Crypto agility is an inventory problem, not a math problem
You cannot rotate what you cannot find. Building a usable inventory of every key, cert, and hardcoded curve.
17 min
Lattices, in the order they were invented
From Ajtai's worst-case reduction to Learning With Errors to the module structure in the standards. No prerequisites past linear algebra.
26 min
SLH-DSA is slow, stateless, and probably your firmware's future
Hash-based signatures ask for almost no new assumptions. That is worth a lot when the device ships for fifteen years.
13 min
Rejection sampling is where the bugs live
Notes from reviewing four ML-KEM implementations, and the timing leak that survived all of them.
19 min
The migration clock
Read the guidance →Dates that already exist in published guidance. The gap between them is your entire migration window.
2024
Standards finalFIPS 203, 204, and 205 published. ML-KEM, ML-DSA, and SLH-DSA stop being drafts.
2026
You are hereHybrid key exchange is default in the major browsers and CDNs. Signatures are the unfinished half.
2030
Deprecated112-bit classical algorithms — RSA-2048, ECDSA P-256 — deprecated for federal use.
2035
DisallowedDisallowed outright. Anything with a secret still worth reading in 2035 is already late.
Subscribe
Two posts a month, sent when they’re finished
No digest, no tracking pixels, no course upsell. Long pieces on lattices, migration, and the hardware, sent as plain text with the diagrams attached.
Unsubscribe link in every email.