<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Post-Quantum, Plainly on Daniel Fedick</title>
    <link>https://blog.fedick.net/series/post-quantum-plainly/</link>
    <description>Recent content in Post-Quantum, Plainly on Daniel Fedick</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 08 Oct 2026 10:13:00 -0400</lastBuildDate>
    <atom:link href="https://blog.fedick.net/series/post-quantum-plainly/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Locks: Post-Quantum Algorithms in Plain English</title>
      <link>https://blog.fedick.net/posts/pq-plainly-1-the-locks/</link>
      <pubDate>Thu, 08 Oct 2026 10:13:00 -0400</pubDate>
      <guid>https://blog.fedick.net/posts/pq-plainly-1-the-locks/</guid>
      <description>Algorithms are lock designs. Keys fit those designs. Crypto-agility means swapping the lock without replacing the door. A plain-English tour of hashes, elliptic curves, lattices, hash-based signatures, and code-based crypto.</description>
      <content:encoded><![CDATA[<p>I think Vitalik is one of the greats in the crypto industry. My fear for Ethereum is that it sounds so complicated that the general user won&rsquo;t be able to understand what&rsquo;s going on.</p>
<aside class="plain">
<h2 id="in-plain-english">In plain English</h2>
<p>Encryption is a lock on your data (and here, your data is access to your tokens).</p>
<p>We have two main existential threats on the horizon: quantum and AI. AI is here, and quantum is quickly approaching. No AI has broken any of the related locks yet. The concern is that AI can speed up the math research that would find the weak spots in the lock design.</p>
<p>How could we defend against this threat? Use two different locks, so a thief has to pick both of them:</p>
<ul>
<li>One lock that is older and proven (like ECDSA, which Ethereum wallets use today).</li>
<li>One that is quantum-resistant (like ML-DSA or hash-based SLH-DSA).</li>
</ul>
<p>The ability to quickly swap your locks out as one of them becomes weak is very important. This ability is called <strong>crypto-agility</strong>.</p>
<p>When algorithms are being described, they are describing the lock design. It&rsquo;s the math that decides how hard it is for these threats (quantum and AI) to pick. Your key is exactly what it sounds like: the key that unlocks the lock.</p>
<p>If this interests you, I&rsquo;m putting together a breakdown of some of these algorithms, then why the problems exist, and then what we can functionally and tactically do to protect our wallets and become cryptographically agile.</p>

</aside>

<hr>
<p>This is Part 1 of three. Part 2 (coming soon) covers why this matters now. Part 3 (coming soon) is a command-line walkthrough of wallet keys.</p>
<p>Privacy is a right. Your keys are your data. Math beats promises. Don&rsquo;t trust, verify. Apply that same standard to the new post-quantum algorithms: understand what they do before you trust them with anything.</p>
<h2 id="the-analogy">The analogy</h2>
<p>Think of cryptography as locks on doors.</p>
<ul>
<li>An <strong>algorithm</strong> is a lock <em>design</em>: the shape of the pins.</li>
<li>A <strong>key</strong> is the metal that fits that design.</li>
<li><strong>Crypto-agility</strong> means you can change the lock design without tearing out the door. New algorithm, same system.</li>
<li>A <strong>hybrid</strong> means two locks on the same door. A thief has to open both.</li>
</ul>
<p>I use those words the same way through this series. For the operational version, see <a href="/posts/crypto-agility-vitalik/">Assume the Math Will Move</a>.</p>
<h2 id="two-jobs-key-exchange-and-signatures">Two jobs: key exchange and signatures</h2>
<p>Public-key crypto does two different jobs.</p>
<p><strong>Key exchange</strong> is how two strangers agree on a shared secret without meeting. That secret then locks their messages. TLS does this when you visit a website. SSH does it when you log into a server.</p>
<p><strong>Signatures</strong> prove it was you. You hold a private key. Everyone can check a matching public key. Bitcoin, Ethereum, and software updates all rely on this.</p>
<p>A <strong>hash function</strong> can help build signatures. It cannot do key exchange by itself. That limit is mathematical. Keep it in mind when someone says &ldquo;just use hashes for everything.&rdquo;</p>
<h2 id="hash-functions-a-one-way-blender">Hash functions: a one-way blender</h2>
<p>A hash function is a blender with three habits:</p>
<ol>
<li>Same input, same fingerprint.</li>
<li>One tiny change scrambles the result.</li>
<li>You cannot run it backwards.</li>
</ol>
<p>We use hashes for integrity checks, blockchain addresses, and as building blocks inside bigger schemes. SHA-256 and SHA-3 are common examples. Quantum computers do not break hashes the way they break RSA and elliptic curves; they mostly push us toward longer outputs. More on that in Part 2.</p>
<h2 id="what-we-use-today-elliptic-curves">What we use today: elliptic curves</h2>
<p>Most of the internet and most blockchains still run on elliptic-curve cryptography.</p>
<ul>
<li><strong>ECDSA</strong> and <strong>Ed25519</strong> are signature schemes. Bitcoin and Ethereum wallets use secp256k1 with ECDSA. SSH often uses Ed25519.</li>
<li><strong>X25519</strong> is key exchange. TLS 1.3 and modern SSH lean on it.</li>
</ul>
<p>These are fast and the keys are small. That is why they won. They are also on the wrong side of a future large quantum computer. Excellent locks against today&rsquo;s thieves. Not the locks we want for the next few decades alone.</p>
<h2 id="lattices-the-main-new-federal-standards">Lattices: the main new federal standards</h2>
<p>Lattice crypto hides secrets in high-dimensional grids. The honest party knows a shortcut. Everyone else sees a haystack.</p>
<p>NIST standardized two lattice schemes in August 2024:</p>
<ul>
<li><strong>ML-KEM</strong> (<a href="https://csrc.nist.gov/pubs/fips/203/final">FIPS 203</a>): key encapsulation. The workhorse for hybrid TLS and SSH (for example <code>X25519MLKEM768</code>).</li>
<li><strong>ML-DSA</strong> (<a href="https://csrc.nist.gov/pubs/fips/204/final">FIPS 204</a>): signatures.</li>
</ul>
<p>Keys and signatures are larger than elliptic curves, but still practical for most network protocols. Lattices are the default post-quantum choice for key exchange today. They are also the family getting nervous attention from people watching AI-accelerated math; that is a Part 2 story, not a known break.</p>
<h2 id="hash-based-signatures-boring-on-purpose">Hash-based signatures: boring on purpose</h2>
<p>Hash-based signatures build signing out of the blender. No lattices. No elliptic curves. Just hashes and careful bookkeeping.</p>
<p><strong>SLH-DSA</strong> (<a href="https://csrc.nist.gov/pubs/fips/205/final">FIPS 205</a>) is the federal standard, based on SPHINCS+. Related ideas include WOTS (Winternitz one-time signatures). Signatures are bigger and slower than ML-DSA. That is the trade for relying on almost nothing beyond hash security.</p>
<h3 id="a-one-time-hash-signature-lamport">A one-time hash signature (Lamport)</h3>
<p>Here is the simplest version. Too large for daily use; perfect for intuition.</p>
<ol>
<li>Alice picks a pile of random secret coins (private key).</li>
<li>She blends each coin into a fingerprint and publishes the fingerprints (public key).</li>
<li>To sign a message, she blends the message, looks at its bits, and reveals the secret coins those bits select.</li>
<li>Bob blends the revealed coins and checks that the fingerprints match Alice&rsquo;s list.</li>
</ol>
<p><img alt="Cartoon: how a hash-based signature works" loading="lazy" src="/images/hash-signature-cartoon.jpg"></p>
<p>Use those secrets once. Sign a second message and you leak overlap; a forger can stitch pieces together. SPHINCS+ (and SLH-DSA) wrap a tree of one-time keys so you can sign many times safely. The cartoon is the Lamport core; the standard is that core plus scaffolding.</p>
<p>Hashes can do this signature job. They still cannot do key exchange alone.</p>
<h2 id="code-based-classic-mceliece-and-hqc">Code-based: Classic McEliece and HQC</h2>
<p>Code-based crypto hides a message by adding noise to an error-correcting code. The secret holder can clean the noise.</p>
<ul>
<li><strong>Classic McEliece</strong> dates to 1978 roots, is conservative, and has very large public keys with small ciphertexts. A specialist tool.</li>
<li><strong>HQC</strong> is a newer code-based key encapsulation scheme. NIST selected it as an additional algorithm, which matters if you want a second family for hybrids.</li>
</ul>
<p>Different math from lattices is the point. Diversity of lock designs avoids a single failure mode.</p>
<h2 id="quick-comparison">Quick comparison</h2>
<table>
	<thead>
			<tr>
					<th>Family</th>
					<th>For</th>
					<th>Relies on</th>
					<th>Size</th>
					<th>Status</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>Elliptic curves (ECDSA, Ed25519, X25519)</td>
					<td>Signatures and key exchange today</td>
					<td>Curve discrete log</td>
					<td>Small</td>
					<td>Dominant; not quantum-safe</td>
			</tr>
			<tr>
					<td>Lattices (ML-KEM, ML-DSA)</td>
					<td>Key exchange and signatures</td>
					<td>Lattice problems</td>
					<td>Medium</td>
					<td>FIPS 203 / 204</td>
			</tr>
			<tr>
					<td>Hash-based (SLH-DSA / SPHINCS+, WOTS)</td>
					<td>Signatures only</td>
					<td>Hash security</td>
					<td>Large signatures</td>
					<td>FIPS 205</td>
			</tr>
			<tr>
					<td>Code-based (Classic McEliece, HQC)</td>
					<td>Key exchange</td>
					<td>Hard decoding</td>
					<td>McEliece: huge public keys; HQC: moderate</td>
					<td>McEliece niche; HQC additional NIST KEM</td>
			</tr>
	</tbody>
</table>
<h2 id="what-to-remember">What to remember</h2>
<p>Lock designs are algorithms. Keys fit them. Hybrids put two designs on one door. Agility lets you swap designs without rebuilding the house. Key exchange and signatures are different jobs. Hashes are a one-way blender: great for fingerprints and for certain signatures, useless alone for agreeing on a secret.</p>
<p>Next up, coming soon: the problem those locks are meant to solve. Then Part 3 puts wallet keys on the command line so you can feel what &ldquo;changing the lock&rdquo; actually breaks.</p>
<p><em>Views are my own and do not represent my employer. Nothing here is financial advice.</em></p>
]]></content:encoded>
    </item>
  </channel>
</rss>
