>

NIST’s PQC Standards: FIPS 203-205 and the Migration Clock

On August 13, 2024, NIST published the final versions of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — the first formal post-quantum cryptography standards, capping an eight-year open competition and starting the migration clock for RSA and elliptic-curve infrastructure. With harvest-now-decrypt-later collection already threatening long-lived secrets and federal migration timelines targeting the 2030s, enterprises face a decade-scale cryptographic inventory and replacement program. This guide walks the standards, the threat math, and the migration playbook from inventory to hybrid deployment.

Continue ReadingNIST’s PQC Standards: FIPS 203-205 and the Migration Clock

PuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PuTTY's April 2024 advisory for CVE-2024-31497 read like a physics problem: the terminal's ECDSA implementation biased nonces on NIST P-521, so roughly 71 captured SSH signatures suffice for a lattice attack that recovers the private key. This piece explains the Hidden Number Problem math, why archived PCAP and DLP session capture retroactively weaponized years of traffic, the 0.81 deterministic-nonce fix, and the brutal rotation drill that made every P-521 key used through Pageant presumptively burned.

Continue ReadingPuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key
>