PQ-TLS mainly means swapping key exchange first; cert signatures stay the real bloat in the handshake.
trending13
01 02 Red Sift blog search for “ristic”, mostly email auth and PQC posts, because standards folks enjoy recurring chores.03 Deep dive on Windows revocation providers and trust validation, for when CRL/OCSP's good enough is apparently not.04 What broke in curl's crypto path? This audit walks protocol handlers, TLS backends, reuse, HSTS, SSH keys, and dead ends.05 June 2026 crawl of the Tranco Top 1M, with the usual TLS hygiene stats plus the first broad post-quantum hybrid key exchange sightings.06 Witness complexity quantifies how long short descriptions take to expand or verify, with a P=NP characterization tucked in.07 Microsoft moves PQC rollout up to 2029, highlighting crypto-agility and trust-chain work instead of just inventory theater.08 Certificates are getting shorter, because humans are the weak link; this talk covers ACME and crypto agility.09 Post on PQ TLS cert bloat and MTC tradeoffs, because certificates apparently needed more engineering.10 ArXiv measurement study of 32k domains' PQ readiness in TLS, with hybrid KEX creeping in and certs still MIA, naturally.11 Sovereign Execution Brokers: Enforcing Certificate-Bound Authority in Agentic Control Planes arxiv.orgPaper on SEB, a runtime gate for agentic control planes that only executes infra changes with valid certificates and audit trails.12 Pseudonym Scheme Based on Hybrid Certificates for Security Credential Management System in Vehicular Communications arxiv.orgArXiv paper on hybrid pseudonym certs for vehicular credential management, benchmarking ECC, RSA, and PQC. Cars needed PKI, apparently.13 The hard part isn’t the crypto, it’s certificate migration, and Google spells out the boring bits of PQC rollout.