This article provides an overview of the post-quantum cryptography (PQC) landscape, covering newer signature algorithms (FN-DSA/Falcon, SLH-DSA), composite signatures, and the IETF PLANTS working group's development of Merkle Tree Certificates to address TLS handshake bloat. It notes that while symmetric encryption remains quantum-safe, the industry is accelerating PQC adoption timelines to 2029 in response to research suggesting cryptographically relevant quantum computers may arrive sooner than expected.
tls
3 posts
Post-Quantum Cryptography: What’s Next for Edge Security UAT-7810 continues building ORB networks using new malware UAT-7810, a China-nexus APT actor, continues to build Operational Relay Box (ORB) networks by exploiting n-day vulnerabilities in Ruckus and ASUS AiCloud routers. Talos identified four new malware families — LONGLEASH (an upgraded multi-protocol proxy backdoor), DOGLEASH (a passive C-based Linux backdoor), JARLEASH (a Java-based administrative backdoor), and LEASHTEST (a MIPS test binary) — deployed across MIPS, ARM, and x64 platforms. The actor uses at least four new servers to host payloads and deploy DOGLEASH via shell scripts that modify iptables rules on compromised devices.
Post-Quantum Cryptography Beyond TLS: Remain Quantum Safe The article highlights the critical need to transition various network protocols, including SSH, IPsec, OpenPGP, and DNSSEC, to post-quantum cryptography (PQC) to mitigate the 'harvest now, decrypt later' threat. While TLS and SSH have clear upgrade paths with hybrid key exchanges, protocols like DNSSEC face complex architectural challenges due to signature sizes and UDP limitations.