Post-quantum migration is an inventory problem, with hybrid TLS and bloated handshakes exposing hidden crypto everywhere.
4 comments
Inventory problems are always where crypto migrations go to die, since the first audit finds TLS, and the second finds three things nobody thought were doing TLS at all.
If the handshake gets too big for some middleboxes, is the usual fix to trim certificates and extensions, or do teams end up having to replace whole bits of infrastructure they did not know depended on TLS?
> trim certificates and extensions
Middleboxes usually force infra replacement, not careufl handshake dieting.
The part I keep thinking about is certs, not just the KEM share. A bigger ML-DSA chain also makes OCSP stapling and CRL traffic fatter, so you can end up paying the size penalty on every connection even when resumption hides the handshake cost.