Schreibt mir eine post-quantum Nachricht!
Und steigt auf Post-Quantum um!

#gnupg #sequoia #openpgp #aes #kyber #postquantum #cryptography #quantum

-----BEGIN PGP PUBLIC KEY BLOCK-----

mEkFagceSxYAAAA/AytlcQHI0TWUyLDWm/9brPLIjkBVEb9mu922wsirsFkfTiSj
NH/Dytz45QGF8GmXb5gOqNzL44eHOqR6bRwAtBhTY2hudXIgPHNjaG51ckBtYWls
LmkycD6I6QUTFgoAaSIhBUscQadL0Gfr51DPNfPs7eXIRGo3CAqKRSeG+VL49VKE
BQJqBx5LGxSAAAAAAAQADm1hbnUyLDIuNSsxLjEyLDIsMgIbAwUJCpfdgAULCQgH
AgIiAgYVCgkICwIEFgIDAQIeBwIXgAAA6RwBxA6kGXIK9eW+fxfbP61nqTcoucrd
bYZ2GaA3xWb8aKuewghWZR5UiLMs/mg2BD84pwSmHuFjcpVVAAHIxU6LUwSj+O79
mrA9L9pFSTYgIhANDVC0pcCTSfEToMeiNfMXnN7OuVqX6HLgc3miXutr3yuZTzoA
tBtTY2hudXIgPHNjaG51ckBpMnBtYWlsLm9yZz6I6QUTFgoAaSIhBUscQadL0Gfr
51DPNfPs7eXIRGo3CAqKRSeG+VL49VKEBQJqBx7/GxSAAAAAAAQADm1hbnUyLDIu
NSsxLjEyLDIsMgIbAwUJCpfdgAULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAA
g4kByOrTzFtDjQTQvJnTcp76u9ylX2b/RSYQRud5AMyF3Py3aKqbLK1/aMiBqR73
6KPSFgbZ6CpooqpoAAHI55swsGUlNrkHHUQagWnklEWF30DtybTigM2t1di2fXYs
8KIOFo4zZY8wee6m+HlWyawm5ZgvnzUAtB9TY2hudXIgPHNjaG51ckBob3JzZWZ1
Y2tlci5vcmc+iOkFExYKAGkiIQVLHEGnS9Bn6+dQzzXz7O3lyERqNwgKikUnhvlS
+PVShAUCagcfMxsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiwyLDICGwMFCQqX3YAF
CwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AAAIS8Aci/4qM4a3eIozLg7Zr+wnT8
LP3Zj4Lexe92uyQF4pvB0NrA89MlVagPsyntdcvUYmiuS+ch/SZWugABxREs7rSN
zii3nWftV5C6/SBcPGPulP+uY/0sOhqSs+8UvHhmjj8/dfhFGBIcFjEy3CxKKlPG
m1UAALQiU2NobnVyIDxhbm9uc2NobnVyQHBhcmFub2lkLmVtYWlsPojpBRMWCgBp
IiEFSxxBp0vQZ+vnUM818+zt5chEajcICopFJ4b5Uvj1UoQFAmoHH6cbFIAAAAAA
BAAObWFudTIsMi41KzEuMTIsMiwyAhsDBQkKl92ABQsJCAcCAiICBhUKCQgLAgQW
AgMBAh4HAheAAAB7/AHFEBSwAtD1T5bOW8YkHvcExBvzAGljd96L4Ww/Xjqr33Jv
upx+JjFd+Dhy9r4azOMRbZlQ69OEjQWAAcd5lDUUeMYd3aQiFR885kJv70SgQUxi
NOi9RRUmyAcchhSFRw3y021Iq94HbBRlDpCgW4w6xtUAGAC5BmwFagceSwgAAAZi
AytlbwHAgGFSx/MUSL3W1Vwe14zyB6qODVlbqrkBeDy2yYVRdKrjCeNZZ7cCfBg6
DJo3oUJCPfZwZbmPul0AAAYgqUYrC3WodTVkr5xXcgaQ8oGfQcNyPZWVVHcMUDF5
0vd7ujh5idh+mMxkz8QEztWD1BCxB3UzcyKoVnhI+Tiu3veYdAVGhCs+UZGY7gOC
K1WYM0CG2jNJu8V5aDS8WbjDoqPELPLMTMPOUhUKL2G1TghjjVBKKAxymViqA/rL
sPFUJKXCV3gif6ZsnfwR8XGcxbJh8tl7HxB20iUxYKtpQljA/EFjOVQeVYJ6+5Wh
tOYycbC906mHqZrIVYy6ojdju4KVyCzLnmGNcVkY58e7ChC3dMNpaFgARGFZ4YPB
xOENmYFQr+sqjvAwrweMRza94XJ6wmoZ9aW/QdNhUgpNouxgkFgWPRkUAkVp7pV6
URd/O5PAOhm141RnALRtdWOvHfKVlqcEPcxuCloQppeinGZhN+ALzeEPT2ucRrej
o8Ei4BxDfmWkiHmtj5VM9nu54UhJNCdS8WtPJeRu68VmxNXHFmzGoGMuSjd9z8d5
CeieimOYPxvJ9BunQ9toYVUHAKxIIzAN2ySQwQVlVnupdLQHXpIIxHInM9e7bWcU
KUY4LJlXqeJZkzDFaNlvepDMu3iR+LpwCGs1ppFxu3h9pFOZx8BmOYGQS1WU65qf
Phu08oVsmWVoBFZua4c762tzyQuNBLOYtMxPN+g/keE4xRbI5OFeQfh5TtmlEGV0
pfGITMl2YZIQpAorxuAHutu/kad+lJEiHLGen9McD+TO0mfOI9iELOmfXJgOFbiG
LHByj2ORozZzkTGqEmZYxLoO1bE4oMVKBJgGDTh66IJoVAeLSZed0ac39PILmnQi
e9Bkwoe26Je49EVfVfgjovwImUuPFwG99phBfGQO8jIywcKNQCfOiwO82LOok/mT
zTOcT3SASsWU6uypSTIRJiYdMAVdfXdIUeZ0i4h1JbcJCHgU/Qt+7RK+YCFPCPAE
LyOuzoNjBMy9xXkELZyUHmRd0AuTpNA2VFsueeCeqqqFc3MTJ5lVbYSZVMrAZIA2
LjEXflp9Hrk5KIC8uJMlQXJ8+fQTPodBibKts2iBkCsBlKKVHACm1jojKYd7oBAh
RJawGRykj6mYPsHAWpa2BrBoWAmKz8rAjyoTaBwSOwTOMCEIGKiRygYTYpBRpHmU
ZksP6UqNhDsx5zYeZlW853YXmXY5DIPDpmQFGYqUSRdqHlWHlkiGxpWFtWRMb4Ml
uOhrjshueXUyy5yeFxOZnpVCA8nNe7t1nWtfIEh7JMelBkIGcFo3SDRWKFa/8pAg
rGNvdhw5gzCNn2k/KQmZtyiBl1QqJ2DFZWoYeLtrwBBMiqcyuYbMp0EBnBB5aroM
7FsRw+EKpaKzACmvuqeULze8gzUg8Zqjzyof9BZW8YiLUuw9QbKl9dfGzVwPOgW/
IEIl+vZJScA60nOO/XFJ+TjJtYq2flLA98EUCAwtPCJYBqk8c4ghd6ItiXq8EoAk
Sgo9bCEQI4ZFdCM5GZkT6EZBCxrP1IFFUVebOnUiQ9wh95VL+5Zk0pMu+4GYVSma
z9oSY4tAYaiOH6poTKwhYbWf3tInA6AZhHagZpcEA9XOzpgTKBQjNKOspPpYwom7
E6GHTEyI3EzF+oYF/ncqzdtP9kYXxxGIfxkzNrjAfDtwrowXLuRT8WWj7xogTVOe
bDC71lamIaW+RuxqVgZndryctRqsZthfG1xswASboxof+Yu3gOFJh3BEy2Ipbchy
rgSBLckIq7atMnnINayaq3miFrZby6V1iSueolS/IBx0N5VYm9x2IKXEohkjFOFH
jqR3DKOS14erICCaIOjIoJPPuOodkMSXahComsqxamiJWho6qDEQQLlBS1k6bTyy
bCeESqxU/whiSLJsh9doYvQA5DoG2Cat2fOwZGs2SwEjJtVDN9l1OmuzwUcoUZUd
OdmffsKxDvuVQvzMtnc3myS23nRDYHK5g+xpx6F3jAKvp1aFzCW4BBN8UqsDWtWu
nNGGHdlSj+pUg0nNjkANlrplVecqdPAhm5i8cINe+aJZyfgEOcp5/6m5drINylNq
pMNOEdy+ImkvFmc11iKKmmcZuziOFUHu6cGDNTEV/y7kmPdXmJh3gV8LnwihNWD8
ytKIzgUYFgoATiIhBUscQadL0Gfr51DPNfPs7eXIRGo3CAqKRSeG+VL49VKEBQJq
Bx5LGxSAAAAAAAQADm1hbnUyLDIuNSsxLjEyLDIsMgIbDAUJCpfdgAAAsQgByOwk
vYE/vYDHeXRWG7UPBUxCxAykZwOz2jqFBSD8e/riTzTx85nVkUIRXb4mmBhp73DT
HLbhgOOwgAHI5TS2rCxCNqr/4u8wmf2ppt5mf68E/hwFODvRQKdIawFyu9hS8rGa
ZInzyeVq1UkMl+EIy/jXEC4A
=JLo6
-----END PGP PUBLIC KEY BLOCK-----

So you want to deploy Falcon / FN-DSA for small post-quantum signatures

FN-DSA(구 Falcon)는 포스트 양자 서명 표준으로, 현재 NIST의 초기 공개 초안(IPD)이 지연 중이며 실제 표준화까지 최소 1년 이상 소요될 전망입니다. FN-DSA는 해시 함수 사용과 관련해 안전한 사전 해싱(prehashing)이 불가능하며, 부적절한 구현 시 개인키 유출 위험이 있습니다. 또한 알고리즘에 필수적인 부동소수점 연산은 상수 시간 구현이 매우 어렵고, 서명 속도 저하 및 보안 문제를 야기할 수 있습니다. 따라서 FN-DSA 도입 시 신중한 검토와 구현 주의가 필요합니다.

https://keymaterial.net/2026/05/13/so-you-want-to-deploy-fn-dsa/

#postquantum #cryptography #fndsa #signature #security

So you want to deploy FN-DSA

FN-DSA (née Falcon) is a proposed post-quantum signature standard that keeps polarizing engineers. Cryptography engineers on the one hand, tasked with potentially implementing this monstrosity, hat…

Key Material
That feeling when your personal infrastructure is #postquantum Feels… cozy…
Tezos experiments with post-quantum privacy while its founder pushes back on what he calls 'half-baked' quantum theories around Bitcoin. Whether you agree or not, the conversation is happening — and that's exactly where it should be. Quantum readiness isn't panic, it's preparation. 🧮 #infosec #PostQuantum #Cryptography
https://decrypt.co/367795/tezos-post-quantum-privacy-founder-slams-half-baked-bitcoin-theories
Tezos Tests Post-Quantum Privacy as Founder Slams 'Half-Baked' Bitcoin Quantum Theories

Arthur Breitman's comments come as Tezos tests a post-quantum privacy system designed to protect encrypted blockchain data from future attacks.

Decrypt

I read OpenSSL for fun and found a nonce leak

OpenSSL 4.0.0의 SLH-DSA 서명 구현에서 랜덤 nonce(주소 랜덤값)를 스택에 남겨두는 치명적이지는 않지만 보안상 취약한 버그가 발견되었다. nonce를 지워야 하는데 조건문 오류로 인해 정상 경로에서는 스택 버퍼를 지우지 않아, 프로세스 크래시 시 코어 덤프, 스왑 파일, 정보 노출 취약점과 연계될 수 있다. ML-DSA 구현과 비교해보면 SLH-DSA 코드가 변수 혼동으로 인해 클렌징 로직이 잘못 작성된 것이 원인이다. 간단한 코드 수정으로 문제를 해결할 수 있으며, FIPS 140-3 준수에도 영향을 미친다.

https://blog.himanshuanand.com/2026/05/i-read-openssl-for-fun-and-found-a-nonce-leak/

#openssl #cryptography #security #postquantum #bug

I Read OpenSSL for Fun and Found a Nonce Leak

I was poking around the OpenSSL source code recently. Not really hunting for anything specific (one of the most heavily audited codebases), just curious about how the new post-quantum crypto stuff was wired up in version 4.0.0. I went in expecting to find nothing interesting. Instead I tripped over a single-character logic bug that leaks cryptographic randomness onto the stack on every signing call. Quick disclaimer: I am not a crypto person.

Himanshu Anand :: Threat Notes

3/14 · Post-Quantum Audit for Critical National Infrastructure

An operator-side playbook for the NCSC 2031 and 2035 migration deadlines. 22 pages.

https://mickai.co.uk/ebooks/post-quantum-audit-for-critical-national-infrastructure

#NCSC #PostQuantum #CNI

Post-Quantum Audit for Critical National Infrastructure

The NCSC has published the post-quantum migration roadmap. The dates are 2031 and 2035. The substrate question is what an operator at National Grid, SSE, BT, Openreach, Thames Water, the major banks, or the NDA portfolio actually does on Monday morning to land on those dates without a vendor-key dependency.

Mickai

2/14 · The Audit Substrate Under Every AI Agent

The OAR primitive. Hash-linked CBOR, FIPS 204 ML-DSA-65 signed, browser-resident verifier. 24 pages.

https://mickai.co.uk/ebooks/the-audit-substrate-under-every-ai-agent

#OAR #PostQuantum

The Audit Substrate Under Every AI Agent

Every AI agent in 2026 is producing decisions that affect humans, regulators, and balance sheets. The audit trail of those decisions is, today, held under the AI vendor's key in the AI vendor's format. The substrate question is upstream of the policy question. This ebook is the engineering walk-through of the substrate that closes the gap: hash-linked CBOR, FIPS 204 ML-DSA-65 signing, SHA-3-512 chaining, browser-resident verification, deterministic verdicts.

Mickai

Fourteen free engineering ebooks on sovereign AI shipped today.

The corpus underneath the Mickai patent family. Every committed AI action serialised in CBOR, hashed under SHA-3-512, signed under FIPS 204 ML-DSA-65, replayable offline.

302 pages. 14 PDFs. Open canonical schema.

UK IPO patent family GB2607309.8 to GB2610422.4. Trade mark UK00004373277.

https://mickai.co.uk/ebooks

#SovereignAI #PostQuantum #Mickai

Mickai Ebooks · Sovereign AI Playbooks

Downloadable PDF playbooks from Mickai on sovereign AI.

Mickai

NCSC Post-Quantum Cryptography pilot opens. Late spring 2026 to 31 March 2027 delivery window. UK PQC migration timeline: 2028 discovery, 2031 high-priority migration, 2035 full migration.

The Mickai SIOS audit ledger is FIPS 204 ML-DSA-65 from inception. Not retrofitted. ML-DSA-87 migration is a parameter change, not a redesign.

https://mickai.co.uk/articles/ncsc-pqc-pilot-opens-mickai-is-the-substrate-that-already-ships-under-fips-204

#PostQuantum #NCSC #FIPS204 #Mickai

NCSC's Post-Quantum Cryptography pilot opens. Mickai is the substrate that already ships under FIPS 204.

The NCSC's Post-Quantum Cryptography pilot opens in late spring 2026 and runs to 31 March 2027. The pilot exists because most UK organisations are not yet ready for the 2028 cryptographic-discovery milestone, never mind the 2031 high-priority migration. The Mickai SIOS audit ledger is FIPS 204 ML-DSA-65 from inception, not retrofitted. This piece maps the pilot's stated intent to the substrate that is already shipping, and opens an invitation to brief.

NCSC named the AI patch wave on 1 May 2026. The operators that hold ground through the forced correction will be the ones with a cryptographic position on what they patched, in what order, under whose key.

The Mickai audit substrate is that position at the primitive layer: FIPS 204 ML-DSA-65, SHA-3-512 hash chain, browser-resident offline verifier.

https://mickai.co.uk/articles/ncsc-named-the-ai-patch-wave-the-audit-substrate-is-what-survives-it

#NCSC #AICyber #PostQuantum #Mickai

NCSC named the AI patch wave. The audit substrate is what survives it.

The NCSC's 1 May 2026 patch wave warning is a structural read of where vulnerability disclosure is going, not a tactical alert. The operators that survive the correction will be the ones that can prove, cryptographically, what they patched and when. The Mickai audit substrate is that proof at the primitive layer: FIPS 204 ML-DSA-65 per action, SHA-3-512 hash chain, CBOR canonical serialisation, browser-resident offline verifier. The pitch is not faster patching; the pitch is verifiable patching.