







Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.

DEF CON 33 - Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it? - K Karagiannis
More on whether useful quantum computing is “imminent”
These days, the most common question I get goes something like this: A decade ago, you told people that scalable quantum computing wasn’t imminent. Now, though, you claim it plausibly is immi…

Sirraya One | Enterprise Decentralized Identity Platform
NIST-certified quantum-resistant identity with zero-knowledge proofs. Government & military-grade verifiable credentials.

Wave - Secure Messaging App
Privacy-first messaging with quantum-level encryption. No signup, fully decentralized, zero tracking.
Node.js Cryptography Overhaul: Migrating from SHA-256 to Post-Quantum Algorithms | Markaicode
Learn how to upgrade your Node.js applications from SHA-256 to quantum-resistant cryptographic algorithms with practical code examples and migration strategies.

Hybrid Constructions: The Post-Quantum Safety Blanket - Dhole Moments
The funny thing about safety blankets is they can double as stage curtains for security theater. Art: CMYKat “When will a cryptography-relevant quantum computer exist?” is a question ma…

A look at the latest post-quantum signature standardization candidates
NIST has standardized four post-quantum signature schemes so far, and they’re not done yet: there are fourteen new candidates in the running for standardization. In this blog post we take measure of them and discover why we ended up with so many PQ signatures.

Soatok’s Informal Guide to Threat Models - Dhole Moments
After a long day of exhausting conversations about Hybrid Post-Quantum Cryptography, random jackasses trying to play gotcha with endpoint attacks against end-to-end encrypted messaging apps, and me…

In Search of Hardness
Protocol studies, the next crypto cycle, and the next age of the world

Meet Willow, our state-of-the-art quantum chip
Our new quantum chip demonstrates error correction and performance that paves the way to a useful, large-scale quantum computer.
Time-lock puzzle
A time-lock puzzle, or time-released cryptography, encrypts a message that cannot be decrypted until a specified amount of time has passed. The concept was first described by Timothy C. May,[1] and a solution first introduced by Ron Rivest, Adi Shamir, and David A. Wagner in 1996.[2] Time-lock puzzle are useful in cases where confidentiality of information is determined by time, such as a diarist who does not want their views released until 50 years after their death, an auction where bids are sealed until the bidding period is closed, electronic voting, and contract signing.[1][3] They can additionally be used in creating further cryptographic primitives, such as verifiable delay functions and zero knowledge proofs.[3]
Let’s talk about encrypted reasoning
This is a quick post I wanted to write about a hobby project I spent a weekend on. It has little to do with real cryptography, and mostly doesn’t expose a particularly exciting vulnerability.…

Encrypted Spaces — Research preview
An architecture for collaborative applications where data is encrypted and operations are cryptographically verifiable.

Encryption + Trust & Safety reading list (updated 2026-05-20)