DEV Community

Nguyen Dong
Nguyen Dong

Posted on

Hybrid post-quantum key exchange at the front door went from 50% to 86%. It says nothing about your VPN.

We run a small public index of post-quantum adoption: one TLS 1.3 handshake per host, against the same list of 350 public front doors, repeated over time. Three runs so far, April, May and September 2026.

On the 293 hosts that answered in every run:

April May September
hybrid post-quantum key exchange 50.2% 51.2% 86.0%

105 hosts moved from classical to hybrid (X25519MLKEM768). Across all three runs, zero moved back. Banking moved the furthest of any sector, 28.0% to 94.0% on 50 hosts. A re-run on 14 September reproduced the cohort (293) and the headline (252 of 293) exactly.

That is real movement. It is also a much narrower fact than it sounds.

What the number measures

One handshake, from outside, to one public hostname. It tells you what the internet-facing TLS terminator of that host negotiates today with a client that offers a hybrid group.

What it cannot see

Everything behind that terminator:

  • VPN. IPsec, OpenVPN and WireGuard tunnels negotiate their own keys. A hybrid front door says nothing about them.
  • Internal TLS. Service-to-service traffic, load balancer to backend, database connections. Often older libraries, often pinned versions.
  • SSH. Its key exchange is configured separately on every server.
  • Signatures and certificates. In a 40-host run on 1 September (16 banks plus internet infrastructure and a control group), 0 of 40 carried a post-quantum signature. That is expected: no public CA can issue one yet. Key exchange is migrating; authentication is not, in any sample we have run.
  • Code. Hard-coded RSA or ECDH in your own applications doesn't change when a vendor updates a default.
  • Traffic already recorded. A front door that went hybrid in August protects sessions from August on, not the ones before.

The index says this about itself, and it is worth repeating: a front door isn't an estate, and a vendor default isn't a migration programme. We also do not know what changed over the northern summer, and we don't guess.

What to do with it

If your public front door already negotiates hybrid, good, and that is probably not where your exposure is. The questions that matter are the ones the index cannot answer from outside:

  1. Which of your tunnels, internal links and SSH servers still negotiate classical-only key exchange?
  2. Which data crossing them has to stay confidential for longer than your migration plan takes?
  3. Where is classical crypto hard-coded, so a library update won't fix it?

Those need a look inside the estate: TLS and server configs, SSH, VPN configs, certificates, code, and, if you can share one, a packet capture, which shows exposure per flow rather than per host.

Limits of the numbers above

  • 57 of the 350 hosts did not answer in every run; they are the weakest part of the dataset, and every percentage above is on the 293 that did.
  • Public front doors only, one handshake per host, no retries. It measures what a host negotiates, not what it could negotiate with a different client.

Two ways we can help. **PQ Front Door Check, free: send one hostname you own and we send back one page on what it negotiates. **PQC Readiness Audit, USD 4,900: the inside view above, across seven surfaces (TLS, server config, SSH, VPN, certificates, code, packet capture), with no agent on your systems. Message Dong Nguyen on LinkedIn.

Dong Nguyen, ATK New Technology

Top comments (0)