PQ-TLS mainly means swapping key exchange first; cert signatures stay the real bloat in the handshake.
trending8
01 02 An overview of QKD, its variants, standards, and deployment status, plus the usual “is this actually useful?” subtext.03 The Most Efficient Protocol for PAKE: What Exact Stuff Do You Need to Hash at the End? eprint.iacr.orgWhich bytes do you actually hash at the end of PAKE? A UC proof for all 16 OEKE-2F variants and their KEM assumptions.04 Small botnet, industrial-grade crypto: RustDuck swaps C for Rust and adds anti-analysis, encrypted C2, and DDoS plumbing.05 IETF's practical PQC migration guide, with KEMs, signatures, hybrids, and the usual deployment pain.06 New AKE freshness for staged hybrids, tracking pseudorandomness after branch reveals, stage-key leaks, and corruptions.07 How do you stop first-packet replays in PSK Shadowsocks without a clock or server nonce? You probably can't.08 The Best of Both Worlds: Hybrid Authenticated Key Exchange for QKD(N) without Signatures eprint.iacr.orgHybrid AKE for QKD without signatures, swapping the usual PQ signature glue for KEMs and a CK01 proof.