Report on an attested TLS relay flaw hitting WhatsApp and Cocos AI, proof that handshakes still cosplay as security.
trending30
01 02 A10 says ACOS 7.0.3 adds hybrid PQ TLS with OpenSSL 3.5, so your ADC can do X25519+ML-KEM without new boxes.03 Attested TLS Was Supposed to Be the Last Trust Boundary. It Isn't. Formal Methods Show How. hackernoon.comProVerif finds CVE-2026-33697, a relay attack that breaks attested TLS binding, so the last trust boundary wasn't.04 FINMA Drops The Quantum Hammer: 72% Of Banks Unprepared As Post-Quantum Crypto Deadline Looms + Video undercodetesting.comFINMA's PQC warning: 72% of banks aren't ready, and the article walks through crypto-agility, hybrid TLS, and OpenSSL/liboqs tests.05 How do Windows, Azure, and SAP get to PQC by 2029 without breaking half the estate?06 Can remote attestation actually prove you’re talking to the TEE, or just to a relay that forwards the traffic?07 DJB critiques the IETF's repeated TLS last call on solo ML-KEM, arguing the process and security story are both wobbly, as usual.08 Post Quantum Cryptography: Federal Mandates, Market Drivers and What IT Companies Should Do Now dlt.comBlog on U.S. federal PQC migration, NIST/NSA deadlines, and what vendors should do now, because paperwork loves quantum too.09 Federal PQC deadlines are now 2030 for key establishment and 2031 for signatures, because crypto agility got a date.10 PQ-TLS mainly means swapping key exchange first; cert signatures stay the real bloat in the handshake.11 Energy-Aware System-Level Evaluation of Post-Quantum TLS on Embedded User Equipment over a Disaggregated 5G Network arxiv.orgArXiv paper measures PQ-TLS on Raspberry Pi 5s in disaggregated 5G, and latency, not crypto, eats the power budget.12 Energy-Aware System-Level Evaluation of Post-Quantum TLS on Embedded User Equipment over a Disaggregated 5G Network arxiv.orgHow much battery do PQC TLS handshakes burn on embedded gear? This paper measures it on Raspberry Pi 5s over 5G.13 Microsoft's PQC migration plan to 2029, covering TLS 1.3 and trust chains, because entropy doesn't care about schedules.14 TLS WG mail backs publishing draft-ietf-tls-mlkem-08, the standalone ML-KEM spec.15 IETF TLS last-call thread on ML-KEM in TLS, with the usual calls for actual attacks and less hand-waving.16 DJB says “informational” RFCs still act like standards, and the solo ML-KEM TLS 1.3 doc is the latest naming game.17 So the question is, will Microsoft get code signing and TLS 1.3 onto post-quantum crypto before 2029?18 Microsoft moved its PQC deadline up to 2029 for critical products and services, because quantum panic has a calendar.19 ePrint paper on RiskService, a modular risk scorer for TLS 1.3, PQ, or hybrid paths, because crypto agility needed another knob.20 Microsoft says its PQC migration now targets 2029, with crypto-agility, TLS 1.3, and trust-chain inventorying in tow.21 What broke in curl's crypto path? This audit walks protocol handlers, TLS backends, reuse, HSTS, SSH keys, and dead ends.22 June 2026 crawl of the Tranco Top 1M, with the usual TLS hygiene stats plus the first broad post-quantum hybrid key exchange sightings.23 Microsoft says critical products and services should be on post-quantum crypto by 2029, plus the usual TLS 1.3 cleanup.24 Microsoft moves PQC rollout up to 2029, highlighting crypto-agility and trust-chain work instead of just inventory theater.25 Microsoft says it's aiming to move critical products to post-quantum crypto by 2029, so the real question is how much breaks?26 Infosecurity writeup on Microsoft's PQC rollout to critical products by 2029, because key rotation was too easy already.27 Tor relay scans now show X25519MLKEM768 on some relays, assuming your TLS library isn't a museum piece.28 How does Claude's sandboxed memory actually work, and where do the creds and plaintext leak out?29 OpenVPN 2.7+ with OpenSSL 3.5+ gets hybrid PQ TLS, ML-DSA auth, and a Windows client, because SSH tunneling was the problem.30 Post on PQ TLS cert bloat and MTC tradeoffs, because certificates apparently needed more engineering.