Migrating protocols to PQ: the good, the bad, and the ugly

2026-05-09·
me
me
· 1 min read
Abstract
Migrating TLS to PQ seems easy. Just write in “PQ” and “KEM”, and we’re done, right? In this talk, I will show that things are unfortunately not that easy. Just using ML-DSA may lead to a melt down of the WebPKI by overloading Certificate Transparency logs and adding a very large amount of overhead. So what do we do? I will examine TLS 1.3, Signal and WireGuard, and discuss how each can be migrated to PQC, what challenges are imposed by practice rather than theory, and what is being done about that.
Date
2026-05-09 14:30 — 15:30
Event
Location

Sapienza University, Rome

Piazzale Aldo Moro 5, Rome, 00185

events

Invited talk at PQCSA workshop co-located with Eurocrypt 2026 in Rome.