Cryptography, before and after Shor · Topic 10 of 10 · After Shor

Migrating without breaking everything

Where do you start, and what changes on the wire?

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06
  7. 07
  8. 08
  9. 09
  10. 10
About this section: After Shor

What Shor's algorithm takes and what it leaves, the two families of replacement (lattices and hashes) and what they weigh, and the order in which a real system moves. This is the section the tools on the post-quantum page put into practice.

See it

What the client sends: one hybrid key share X25519 ML-KEM-768 public key: 1,184 bytes 1,216 bytes What the server returns ML-KEM-768 ciphertext: 1,088 bytes 1,120 bytes For comparison: X25519 alone, both directions 64 bytes in all Client share 1,216 bytes against 32 for X25519 (38 times); whole exchange 2,336 against 64 (36.5 times). A server's first flight has room for about 14,600 bytes (10 × 1,460) before it must wait. Certificates share that room. Both shares go in; the secret is safe if EITHER the classical OR the lattice half holds.
Hybrid means both locks are on the door. The cost is bytes, not time, and most connections will absorb it. The point of doing it now is that the recording problem of topic 06 is happening already.

The intuition

Migration is three jobs in a fixed order. First, find out what you use: every certificate, every key, every protocol, and which algorithm each uses for what. This is harder than it sounds, because cryptography is spread through libraries, devices and vendors, and a certificate hides two algorithms (topic 06). Second, decide what goes first, using the clock of topic 06: whatever is being recorded and must stay secret for years, then whatever signature lives a very long time. Third, change it without a flag day, which means building the ability to swap an algorithm before you need to.

The way the field has chosen to start is the hybrid. A connection performs two key exchanges at once, one classical and one lattice-based, and mixes the two secrets so that the result is safe if either holds. A classical flaw in the new algorithm cannot hurt you, because the old one still covers you. A quantum attack on the old one cannot hurt you, because the new one covers you. The cost is bandwidth: the handshake grows, and a growing handshake can stop fitting in the first flight a server sends.

Underneath all of it is crypto-agility: algorithm names that are configuration rather than code, so that the next change, and there will be a next change, is a setting. The organisations that do best are the ones that treat this migration as the first of several.

The mathematics

The sizes. In the hybrid X25519MLKEM768 exchange the client sends an X25519 public key (32 bytes) and an ML-KEM-768 public key (1,184 bytes), and the server answers with a 32-byte X25519 share and a 1,088-byte ML-KEM ciphertext:

client: 32 + 1,184 = 1,216 bytes server: 32 + 1,088 = 1,120 bytes X25519 alone: 32 + 32 = 64 bytes

The hybrid's client share is 1,216 bytes against 32 for X25519 alone, 38 times as much, and the full exchange, 1,216 + 1,120 = 2,336 bytes, is about 36.5 times X25519's 64. A TCP sender may put an initial window of 10 segments of 1,460 bytes, 14,600 bytes, on the wire before an acknowledgement (RFC 6928), and the server's certificate chain, which may itself carry larger post-quantum signatures, has to fit in the same room. That is why the Size Cliff measures real handshakes.

Mosca's inequality as a plan. You are exposed if X + Y > Z (topic 06). The migration time Y is the one number in your control, and it is longer than people expect because the inventory step comes first. The Sequencer turns a list of systems, their dependencies and a capacity per quarter into a schedule; Q-Day Command is the same decision as a game, with the best order proven over every possible order.

The dated deadlines that governments have set for finishing the move are listed with their sources on the post-quantum page rather than repeated here, because a date copied into a course goes stale and a date with a link does not.

Where it actually runs

On the open web, now The hybrid key exchange is already offered by current browsers and by large content networks, and OpenSSL 3.5 negotiates it by default (the desk measured that in August 2026, while building a probe). A Quick Check on any endpoint tells you whether it will.

What is left Key exchange is the easier half, because it can be hybridised without changing certificates. Signatures are harder: the post-quantum ones are much larger, certificate chains grow, and the roots and the update keys of topic 06 have to move on their own schedules. That is the part of the migration that will take the longest, and it is where an early inventory pays.

The one-line summary of the course Symmetric cryptography and hashing survive with longer keys. Public-key cryptography built on factoring and discrete logarithms does not, and the replacements, lattices and hashes, cost bytes. What to do is find, rank, hybridise and stay agile.