Cloudflare's 1.1.1.1 DNS resolver now validates post-quantum DNSSEC signatures using ML-DSA-44, a NIST-standardized algorithm, to prepare DNS infrastructure for potential quantum computing threats. The implementation addresses the challenge of handling much larger signatures (2,420 bytes) while maintaining backward compatibility with conventional algorithms.
Cloudflare's 1.1.1.1 resolver now validates DNSSEC signatures using ML-DSA-44, a post-quantum algorithm standardized by NIST, to prepare DNS security for potential future threats from quantum computers. The main challenge is that ML-DSA-44 signatures are 2,420 bytes—nearly 38 times larger than current algorithms—requiring larger DNS responses while maintaining backward compatibility with older resolvers.
Cloudflare's 1.1.1.1 DNS resolver now validates post-quantum DNSSEC signatures using ML-DSA-44, a NIST-standardized algorithm, to prepare DNS infrastructure for potential quantum computer threats. The transition presents challenges due to the large size of post-quantum signatures (2,420 bytes) and the need to maintain backward compatibility with older resolvers during the migration.