Cloudflare's 1.1.1.1 DNS resolver now validates post-quantum DNSSEC signatures using ML-DSA-44, a NIST-standardized algorithm, to prepare DNS infrastructure for potential quantum computing threats. The implementation addresses the challenge of handling much larger signatures (2,420 bytes) while maintaining backward compatibility with conventional algorithms.
Cloudflare's 1.1.1.1 DNS resolver now validates post-quantum DNSSEC signatures using ML-DSA-44, a NIST-standardized algorithm, to prepare DNS infrastructure for potential quantum computer threats. The transition presents challenges due to the large size of post-quantum signatures (2,420 bytes) and the need to maintain backward compatibility with older resolvers during the migration.