ℏPlanckScale

Feynman, 1988 — “What I cannot create, I do not understand”

Writing

Signatures

Your certificate chain is about to get heavy

An ML-DSA signature is not a drop-in for an ECDSA one — it is roughly an order of magnitude larger, and a chain carries several. Here is what that does to TLS handshake latency on a lossy mobile link, what it does to firmware images with a fixed signature slot, and the three places I have seen it break before anyone had a chance to plan for it.

14 min read

Hardware

What a cryptographically relevant quantum computer actually costs

Logical qubits are the wrong unit. Counting physical qubits, error-correction overhead, and wall-clock hours instead.

21 min

TLS

Hybrid or bust: reading X25519MLKEM768 on the wire

A packet-by-packet walk through a hybrid key exchange, and why the classical half is still doing real work.

11 min

Migration

Crypto agility is an inventory problem, not a math problem

You cannot rotate what you cannot find. Building a usable inventory of every key, cert, and hardcoded curve.

17 min

Foundations

Lattices, in the order they were invented

From Ajtai's worst-case reduction to Learning With Errors to the module structure in the standards. No prerequisites past linear algebra.

26 min

Standards

SLH-DSA is slow, stateless, and probably your firmware's future

Hash-based signatures ask for almost no new assumptions. That is worth a lot when the device ships for fifteen years.

13 min

Implementation

Rejection sampling is where the bugs live

Notes from reviewing four ML-KEM implementations, and the timing leak that survived all of them.

19 min

Subscribe

Two posts a month, sent when they’re finished

No digest, no tracking pixels, no course upsell. Long pieces on lattices, migration, and the hardware, sent as plain text with the diagrams attached.

Unsubscribe link in every email.