A Post-Quantum Future for Let's Encrypt

Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).

AI Summary

Let’s Encrypt plans to adopt Merkle Tree Certificates (MTCs) to achieve post-quantum-safe authentication for the web without sacrificing TLS performance. The urgency for post-quantum authentication has increased due to government mandates (NSA, NIST, EU) targeting 2030–2035 deadlines, and recent commitments by Google and Cloudflare to migrate their services by 2029.

Read Original → · Discuss with AI → · Share →
← Back to news