PlanckScale

Einstein, 1926 — “God does not play dice”

Quantum machines, classical panic.

A working notebook on quantum mechanics, the machines being built out of it, and the cryptography that has to survive them. For people who want the physics and the engineering in one place — and who have something real to migrate, on a deadline.

Behind this text: a module lattice — the hard problem underneath ML-KEM. Move your cursor and it finds the nearest lattice point. In two dimensions that takes microseconds. In 256, nobody knows how to do it, and that assumption is what your traffic will rest on.

Signatures  · 

Your certificate chain is about to get heavy

An ML-DSA signature is not a drop-in for an ECDSA one — it is roughly an order of magnitude larger, and a chain carries several. Here is what that does to TLS handshake latency on a lossy mobile link, what it does to firmware images with a fixed signature slot, and the three places I have seen it break before anyone had a chance to plan for it.

14 min read

fig. 1 — signature size, bytes

The migration clock

Read the guidance →

Dates that already exist in published guidance. The gap between them is your entire migration window.

2024

Standards final

FIPS 203, 204, and 205 published. ML-KEM, ML-DSA, and SLH-DSA stop being drafts.

2026

You are here

Hybrid key exchange is default in the major browsers and CDNs. Signatures are the unfinished half.

2030

Deprecated

112-bit classical algorithms — RSA-2048, ECDSA P-256 — deprecated for federal use.

2035

Disallowed

Disallowed outright. Anything with a secret still worth reading in 2035 is already late.

Subscribe

Two posts a month, sent when they’re finished

No digest, no tracking pixels, no course upsell. Long pieces on lattices, migration, and the hardware, sent as plain text with the diagrams attached.

Unsubscribe link in every email.