1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
1.1.1.1 has added DNSSEC signature validation with NIST’s post-quantum ML-DSA-44 algorithm, and the content explains how it handles large 2,420-byte signatures while mitigating downgrade risks at scale.
MAIN POINTS
- Cloudflare’s 1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44.
- The algorithm introduces very large 2,420-byte signatures.
- The system must process these signatures efficiently at scale.
- Downgrade risks are a key concern in deploying the new validation method.
TAKEAWAYS
- Post-quantum cryptography is moving into real DNS infrastructure.
- Large signature sizes create practical operational challenges.
- Secure rollout requires careful handling of compatibility and fallback behavior.
- Scalable validation is essential for adopting new cryptographic standards.