Algorithms

What each algorithm does, and whether a quantum computer breaks it.

ECDSA P-256The most common elliptic-curve certificate signature algorithm. Why it is quantum-vulnerable, and why that is less urgent than key exchange.Quantum-vulnerableML-KEM-768The NIST-standardised post-quantum key encapsulation mechanism, formerly CRYSTALS-Kyber. What FIPS 203 specifies and where ML-KEM-768 is used.Post-quantumRSA-2048Still the most common certificate key size on the web. What NIST's transition timeline means for RSA-2048, and why key exchange matters more than signatures.Quantum-vulnerableX25519The most widely deployed classical key exchange on the web, and why it leaves TLS sessions exposed to harvest-now-decrypt-later.Quantum-vulnerableX25519MLKEM768The hybrid post-quantum key exchange used by default in Chrome, Firefox, Cloudflare and OpenSSL 3.5. What it is and how to tell if you have it.Hybrid — post-quantum protected