JALURI 17,534 SUMMARIES / 50 SOURCES
SEARCH LAST PASS 16:16 ATOM

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

1.1.1.1 has added DNSSEC signature validation with NIST’s post-quantum ML-DSA-44 algorithm, and the content explains how it handles large 2,420-byte signatures while mitigating downgrade risks at scale.

MAIN POINTS
  1. Cloudflare’s 1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44.
  2. The algorithm introduces very large 2,420-byte signatures.
  3. The system must process these signatures efficiently at scale.
  4. Downgrade risks are a key concern in deploying the new validation method.
TAKEAWAYS
  1. Post-quantum cryptography is moving into real DNS infrastructure.
  2. Large signature sizes create practical operational challenges.
  3. Secure rollout requires careful handling of compatibility and fallback behavior.
  4. Scalable validation is essential for adopting new cryptographic standards.
READ THE ORIGINAL