1.1.1.1 now supports post-quantum DNSSEC

3 pointsposted 5 hours ago
by MehrdadKhnzd

1 Comments

sybercecurity

4 hours ago

Note that 1.1.1.1 is a validating resolver. Some zone still needs to sign using the algorithm. That number is basically zero once you remove test zones.

Still, there will be a migration to PQC as in other protocols. DNS doesn't have the same "store and decrypt later" threat, so it could be a lower priority over other protocols in use.