A quarter of them are already post-quantum
One week of SSH key exchange negotiations, grouped by the algorithm each attacking client asked for first. Second place goes to a hybrid of a classical elliptic curve and a lattice scheme standardised in 2024, chosen first by 6,751 clients, with a second post-quantum option further down at 43. Nobody picked these deliberately - they are attacking from whatever their distribution ships, and their distribution already ships post-quantum key exchange.
More than a quarter of the machines attacking this server are already post-quantum.
Post-quantum key exchange sounds like a problem for later. Something to plan for, once the standards settle and the tools catch up.
This is one week of key exchange negotiations, grouped by what each client asked for first.
Top of the list is the ordinary elliptic curve everybody uses. Second is a hybrid: that same curve combined with a lattice scheme standardised in twenty twenty-four. Six thousand seven hundred and fifty-one clients put that one first.
There is a second post-quantum option further down, with forty-three.
None of them chose this deliberately. They are attacking from whatever their distribution ships, and their distribution already ships it.
Which makes the direction the interesting part. The tooling pointed at your server is more current than the server it is pointed at.
Check what your own client negotiates first.
#linux#security#selfhosted#infosec#cryptography
❯ Check what your own client negotiates first.